How to Configure SSO/SCIM - Okta
Last updated: September 17, 2026
This guide walks you through integrating Okta with Kula to enable Single Sign-On (SSO) and automated user provisioning via SCIM.
Who can do this: Super Admin
Where to find it: Settings → Privacy, Compliance & Security → Security
SSO Integration with Okta
Supported Features
SAML 2.0-based authentication
IdP-Initiated and SP-Initiated SSO flows
Manual metadata configuration
No domain verification required
Steps to Configure SSO in Okta:
Create a SAML Integration App in Okta:
Go to Okta Admin Console > Applications > Applications > Create App Integration
Select SAML 2.0
Configure SAML Settings:
Single Sign-On URL (ACS): Provided by Kula (based on your account)
Audience URI (Entity ID): Provided by Kula
Name ID format: EmailAddress
Application username: Email
Provide Metadata to Kula:
Download the metadata XML or use the metadata URL
In Kula, go to Settings → Privacy, Compliance & Security → Security, turn on SSO under Sign-in options, click Add SSO and select Okta
Upload metadata or paste values (Entity ID, SSO URL, Certificate)
Save & Test:
Kula will confirm if SSO setup is successful
Test both IdP-Initiated and SP-Initiated flows
SCIM Provisioning with Okta
Steps to Enable SCIM in Okta:
Enable SCIM in Kula:
Click Next: Setup SCIM at the end of the SSO setup in Kula (or edit your Okta configuration later)
Copy the Authorization token from the SCIM Configuration steo
Configure Okta SCIM:
In the SAML app > Provisioning tab
Enable API integration
Set:
SCIM Base URL:
https://api.kula.ai/api/saml/scimUnique identifier field for users: email
Bearer Token: The SCIM token from Kula
Test and Save Integration:
Click Test Connection
Configure supported operations: Create, Update, Deactivate users
Good to know
Kula shows the values your identity provider needs. The Set up SSO step displays Kula's Assertion Consumer Service (ACS) URL and Service Provider (SP) Entity ID — copy them from there.
You can give Kula your identity provider's details three ways: upload the metadata XML, enter the metadata URL, or enter the SSO URL, Entity ID and X.509 certificate by hand.
SCIM is set up in the same place as SSO. After Set up SSO, click Next: Setup SCIM to get the SCIM connector base URL and authorization token, and turn on automatic provisioning.
At least one sign-in option must stay on. Kula won't let you turn off or delete the last one.
Turning off Email & password locks out external users. External collaborators such as agencies sign in with an email and password, so they lose access if you switch it off.
FAQ
Where do I find the SCIM token for Okta?
In Kula, open Settings → Privacy, Compliance & Security → Security, edit your Okta configuration and go to the SCIM configuration step. The Authorization token is shown there.
Can people still sign in with a password once SSO is on?
Yes, as long as Email & password stays turned on under Sign-in options. Turn it off to make everyone use SSO.
Will our agencies and other external users still be able to sign in?
Only if Email & password stays on. External users sign in with an email and password, not through your identity provider.
Why can't I turn off this sign-in option?
It's the only one still on. Turn on another sign-in option first — Kula always needs at least one.
Can we connect more than one identity provider?
Yes. Each one you add has its own toggle under Sign-in options.
Need help? If you have questions or need assistance, reach out to us at support@kula.ai or use the in-app chat.