How to Configure SSO/SCIM - Okta

Last updated: September 17, 2026

This guide walks you through integrating Okta with Kula to enable Single Sign-On (SSO) and automated user provisioning via SCIM.

Who can do this: Super Admin 

Where to find it: Settings → Privacy, Compliance & Security → Security

SSO Integration with Okta

Supported Features

  • SAML 2.0-based authentication

  • IdP-Initiated and SP-Initiated SSO flows

  • Manual metadata configuration

  • No domain verification required

Steps to Configure SSO in Okta:

  1. Create a SAML Integration App in Okta:

    • Go to Okta Admin Console > Applications > Applications > Create App Integration

    • Select SAML 2.0

  2. Configure SAML Settings:

    • Single Sign-On URL (ACS): Provided by Kula (based on your account)

    • Audience URI (Entity ID): Provided by Kula

    • Name ID format: EmailAddress

    • Application username: Email

  3. Provide Metadata to Kula:

    • Download the metadata XML or use the metadata URL

    • In Kula, go to Settings → Privacy, Compliance & Security → Security, turn on SSO under Sign-in options, click Add SSO and select Okta

    • Upload metadata or paste values (Entity ID, SSO URL, Certificate)

  4. Save & Test:

    • Kula will confirm if SSO setup is successful

    • Test both IdP-Initiated and SP-Initiated flows

SCIM Provisioning with Okta

Steps to Enable SCIM in Okta:

  1. Enable SCIM in Kula:

    • Click Next: Setup SCIM at the end of the SSO setup in Kula (or edit your Okta configuration later)

    • Copy the Authorization token from the SCIM Configuration steo

  2. Configure Okta SCIM:

    • In the SAML app > Provisioning tab

    • Enable API integration

    • Set:

      • SCIM Base URL: https://api.kula.ai/api/saml/scim

      • Unique identifier field for users: email

      • Bearer Token: The SCIM token from Kula

  3. Test and Save Integration:

    • Click Test Connection

    • Configure supported operations: Create, Update, Deactivate users

Good to know

  • Kula shows the values your identity provider needs. The Set up SSO step displays Kula's Assertion Consumer Service (ACS) URL and Service Provider (SP) Entity ID — copy them from there.

  • You can give Kula your identity provider's details three ways: upload the metadata XML, enter the metadata URL, or enter the SSO URL, Entity ID and X.509 certificate by hand.

  • SCIM is set up in the same place as SSO. After Set up SSO, click Next: Setup SCIM to get the SCIM connector base URL and authorization token, and turn on automatic provisioning.

  • At least one sign-in option must stay on. Kula won't let you turn off or delete the last one.

  • Turning off Email & password locks out external users. External collaborators such as agencies sign in with an email and password, so they lose access if you switch it off.

FAQ

Where do I find the SCIM token for Okta?
In Kula, open Settings Privacy, Compliance & Security Security, edit your Okta configuration and go to the SCIM configuration step. The Authorization token is shown there.

Can people still sign in with a password once SSO is on?
Yes, as long as Email & password stays turned on under Sign-in options. Turn it off to make everyone use SSO.

Will our agencies and other external users still be able to sign in?
Only if Email & password stays on. External users sign in with an email and password, not through your identity provider.

Why can't I turn off this sign-in option?
It's the only one still on. Turn on another sign-in option first — Kula always needs at least one.

Can we connect more than one identity provider?
Yes. Each one you add has its own toggle under Sign-in options.

Need help? If you have questions or need assistance, reach out to us at support@kula.ai or use the in-app chat.