> ## Documentation Index
> Fetch the complete documentation index at: https://docs.barndoor.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect Okta through Okta Integration Network

> Configure Barndoor SSO using the official OIN app with SCIM provisioning

## Overview

The Barndoor OIN app provides the easiest setup experience with built-in SCIM provisioning for automated user lifecycle management. This method offers:

* Pre-configured OIDC settings
* Automated user provisioning and deprovisioning
* Automated group provisioning and group membership synchronization
* Official Okta Verified integration path

***

## Supported features

The Barndoor OIN integration supports the following Okta features.

### OIDC

* **SP-initiated SSO** — Single Sign-On initiated from Barndoor
* **IdP-initiated SSO** — Single Sign-On initiated from the Okta dashboard (through Third-Party Initiated Login)
* **Just-In-Time provisioning** — Accounts are created and updated in Barndoor at first sign-in

### SCIM provisioning

* **Create users** — Provision new users to Barndoor
* **Update user attributes** — Sync user attribute changes from Okta to Barndoor
* **Deactivate users** — Deprovision users in Barndoor when they are unassigned or deactivated in Okta
* **Group Push** — Push Okta groups and their memberships to Barndoor

***

<Note>
  **Prerequisites**:

  * Admin access to your Barndoor account
  * Admin access to your Okta org
  * SCIM token from Barndoor (generated during setup)
</Note>

<Info>
  For manual configuration with full control, see [Connect Okta with custom application registration](/how-tos/okta-custom-app-setup).
</Info>

***

## Step 1: Add Barndoor from OIN

<Steps>
  <Step title="Navigate to Okta Applications">
    In the Okta Admin Console, go to **Applications** → **Applications**.
  </Step>

  <Step title="Browse App Catalog">
    Click **Browse App Catalog** and search for **"Barndoor.ai"**.
  </Step>

  <Step title="Add Integration">
    Click on the Barndoor app and then click **Add Integration**.
  </Step>

  <Step title="Configure Application Settings">
    Add your Application Label and Organization alias. This can be found in the platform on your user profile information.
    In the example below, `oin-app-testing` is the organization alias.

    <Frame>
      <img src="https://mintcdn.com/barndoor/K5EAwxC6tMHpdKua/images/okta/oin-app-config.png?fit=max&auto=format&n=K5EAwxC6tMHpdKua&q=85&s=1be6b865afa0fd12a97791efded40ce6" alt="OIN App Configuration" width="1030" height="595" data-path="images/okta/oin-app-config.png" />
    </Frame>

    <br />

    <Frame>
      <img src="https://mintcdn.com/barndoor/K5EAwxC6tMHpdKua/images/okta/organization-alias-location.png?fit=max&auto=format&n=K5EAwxC6tMHpdKua&q=85&s=9486c0217637317526789aa5b302a3e3" alt="Organization Alias Location" width="484" height="129" data-path="images/okta/organization-alias-location.png" />
    </Frame>
  </Step>
</Steps>

***

## Step 2: Configure SSO Settings

<Steps>
  <Step title="Open SSO Configuration">
    In your newly added Barndoor app, go to the **Sign On** tab.
  </Step>

  <Step title="Note OIDC Settings">
    The OIN app comes pre-configured with:

    * Client ID (auto-generated)
    * Client Secret (auto-generated)
    * Issuer URL (your Okta domain)

    You'll need these values to configure the IDP connection within Barndoor. Copy the Issuer URL along with the
    Client ID and Client Secret to the Identity Provider section within Barndoor and then save the connection details.

    <Info>
      Your OIDC metadata can be found at `https://<your-okta-subdomain>.okta.com/.well-known/openid-configuration`
    </Info>

    <Frame>
      <img src="https://mintcdn.com/barndoor/K5EAwxC6tMHpdKua/images/okta/oin-signon-config.png?fit=max&auto=format&n=K5EAwxC6tMHpdKua&q=85&s=8c662491e8affdbc446cb874bfc76877" alt="OIN Sign-On Configuration" width="1038" height="859" data-path="images/okta/oin-signon-config.png" />
    </Frame>

    <br />

    <Frame>
      <img src="https://mintcdn.com/barndoor/K5EAwxC6tMHpdKua/images/okta/barndoor-oidc-config.png?fit=max&auto=format&n=K5EAwxC6tMHpdKua&q=85&s=3365471a610c6c66cd3f0debb0220bcf" alt="Barndoor OIDC Config" width="938" height="820" data-path="images/okta/barndoor-oidc-config.png" />
    </Frame>
  </Step>
</Steps>

***

## Step 3: Configure SCIM Provisioning

<Steps>
  <Step title="Enable SCIM Provisioning">
    Go to the **Provisioning** tab and click **Integration** in the sidebar.
  </Step>

  <Step title="Enable API Integration">
    Check **Enable API integration** and enter:

    * **API Token**: Generate this from Barndoor Settings → SCIM Provisioning -> API Token

    <Frame>
      <img src="https://mintcdn.com/barndoor/K5EAwxC6tMHpdKua/images/okta/barndoor-scim-api-token.png?fit=max&auto=format&n=K5EAwxC6tMHpdKua&q=85&s=ce9726c0fa312763d091d3f95afc017a" alt="Barndoor SCIM API Token" width="731" height="443" data-path="images/okta/barndoor-scim-api-token.png" />
    </Frame>
  </Step>

  <Step title="Test Connection">
    Click **Test API Credentials** to verify the connection.

    ✅ **Expected result**: "API credentials verified successfully"

    <Frame>
      <img src="https://mintcdn.com/barndoor/K5EAwxC6tMHpdKua/images/okta/oin-scim-api-token-success.png?fit=max&auto=format&n=K5EAwxC6tMHpdKua&q=85&s=574c4279af29576dd069641995f9eb47" alt="OIN SCIM API Token Success" width="991" height="636" data-path="images/okta/oin-scim-api-token-success.png" />
    </Frame>
  </Step>

  <Step title="Enable User Provisioning to App">
    Go to the **Provisioning** tab and click **To App** in the sidebar.

    * Enable the lifecycle settings you would wish to synchronize to Barndoor. It is recommended to enable all operations.

    <Frame>
      <img src="https://mintcdn.com/barndoor/K5EAwxC6tMHpdKua/images/okta/oin-scim-to-app.png?fit=max&auto=format&n=K5EAwxC6tMHpdKua&q=85&s=3460c54f88e19d3a37609b799904a9e7" alt="OIN SCIM To App" width="1005" height="706" data-path="images/okta/oin-scim-to-app.png" />
    </Frame>
  </Step>
</Steps>

***

## Step 4: Assign Users and Groups

<Steps>
  <Step title="Go to Assignments">
    Navigate to the **Assignments** tab in your Barndoor app.
  </Step>

  <Step title="Assign Users">
    Click **Assign** and choose either:

    * **Assign to People**: Select individual users
    * **Assign to Groups**: Select entire Okta groups (recommended)
  </Step>

  <Step title="Configure User Attributes">
    Review and confirm the attribute mappings for each assigned user.
  </Step>

  <Step title="Save Assignments">
    Click **Save and Go Back** to complete assignments.

    <Info>
      Users will be automatically provisioned in Barndoor within a few minutes.
    </Info>
  </Step>

  <Frame>
    <img src="https://mintcdn.com/barndoor/K5EAwxC6tMHpdKua/images/okta/oin-scim-user-assignment.png?fit=max&auto=format&n=K5EAwxC6tMHpdKua&q=85&s=bedc92b3dc03b4b8b417032d0fa5f9eb" alt="OIN SCIM User Assignment" width="1021" height="573" data-path="images/okta/oin-scim-user-assignment.png" />
  </Frame>

  <Step title="Assign Groups">
    Navigate to the **Push Groups** tab in your Barndoor app.

    * Click **Push Groups** and search for groups by name or rule.
    * Search for the group you would like to sync and click 'Save' or 'Save and Add Another'.
    * Continue adding all groups you would like to synchronize with Barndoor.

    <Info>
      All groups added to 'Push Groups' will synchronize with Barndoor but group membership will only synchronize to
      users that have been assigned to the application.
    </Info>
  </Step>

  <Frame>
    <img src="https://mintcdn.com/barndoor/K5EAwxC6tMHpdKua/images/okta/oin-scim-group-assignment.png?fit=max&auto=format&n=K5EAwxC6tMHpdKua&q=85&s=a3f015ef5adf4c212d33dc4b0d4dfd70" alt="OIN SCIM Group Assignment" width="1047" height="690" data-path="images/okta/oin-scim-group-assignment.png" />
  </Frame>
</Steps>

***

## Map admin access (optional)

SCIM group push keeps users and group membership in sync in Barndoor. To auto-assign the **Admin** role from an Okta group at login, use the **Map groups to roles** card on the [Identity Provider](https://app.barndoor.ai/idp) page—the **Admin Role Group Name** must match the group you push in Step 4 exactly.

See [Connect your IdP — Step 3: Configure Role Mapping](/how-tos/idp-setup#step-3-configure-role-mapping-auto-provision-admins) for the full flow, including the OIDC `groups` claim if your OIN app does not already emit group names at sign-in.

***

## Testing the Integration

### Verify SSO Connection

<Steps>
  <Step title="Confirm SSO sign-in works">
    Sign out of Barndoor and sign in with an Okta-assigned test user. You should reach Barndoor after Okta authentication.

    <Frame>
      <img src="https://mintcdn.com/barndoor/K5EAwxC6tMHpdKua/images/okta/barndoor-sso-success.png?fit=max&auto=format&n=K5EAwxC6tMHpdKua&q=85&s=1f6f1f75ae5a4ea58edf8ab563d047a0" alt="Barndoor SSO Success" width="516" height="579" data-path="images/okta/barndoor-sso-success.png" />
    </Frame>
  </Step>

  <Step title="Run the enforcement preflight (recommended)">
    Before enforcing organization-wide SSO, run **Test SSO sign-in** from [Roll out SSO enforcement](#roll-out-sso-enforcement) below. Barndoor requires that pop-up test—not just a manual login—before **Enforce SSO** is enabled.
  </Step>
</Steps>

### Verify SCIM Provisioning

<Steps>
  <Step title="Assign Users">
    In Okta, assign user(s) to the Barndoor application by either individual users or groups.
  </Step>

  <Step title="Verify user provisioned in Barndoor">
    In Barndoor, go to [**Users**](https://app.barndoor.ai/users) and verify the user appears.
  </Step>

  <Step title="Push Groups">
    In Okta, assign group(s) to the Barndoor application by pushing groups by name or rule.

    * Push groups for users that are already assigned to the application.
    * In Okta, verify groups pushed have transitioned from 'Pushing' to 'Activated'
  </Step>

  <Step title="Verify user groups provisioned in Barndoor">
    In Barndoor, go to [**Users**](https://app.barndoor.ai/users) and verify the users previously provisioned now show their pushed group memberships.

    <Frame>
      <img src="https://mintcdn.com/barndoor/K5EAwxC6tMHpdKua/images/okta/barndoor-scim-provisioning-success.png?fit=max&auto=format&n=K5EAwxC6tMHpdKua&q=85&s=49291f069af010dcba60b18468297cab" alt="Barndoor SSO Success" width="1634" height="131" data-path="images/okta/barndoor-scim-provisioning-success.png" />
    </Frame>
  </Step>
</Steps>

***

## Roll out SSO enforcement

After your IdP connection is saved and SSO sign-in works, the **Roll out SSO enforcement** section on the [Identity Provider](https://app.barndoor.ai/idp) page lets you require SSO for every member of your organization. Until you enforce SSO, users can still sign in with Barndoor passwords in addition to your IdP.

<Info>
  If you don't see **Roll out SSO enforcement** controls on the Identity Provider page, organization-wide SSO enforcement may not be enabled for your workspace yet. Contact your Barndoor account team.
</Info>

<Warning>
  **Enforcing SSO is irreversible in production.** It permanently clears Barndoor passwords for all members, terminates every active session (including yours), and requires all future logins through your IdP—except the dedicated break-glass account described below.
</Warning>

### What changes when you enforce SSO

When you confirm enforcement, Barndoor:

* Requires all organization members to sign in through your IdP
* Permanently clears saved Barndoor passwords for every member
* Leaves password sign-in enabled **only** for the break-glass admin email you configure
* Terminates all active sessions, including the administrator who enabled enforcement

After enforcement succeeds, sign out and sign back in through your IdP to continue working as an administrator.

### Prerequisites

Both items in **Before you can enforce SSO** must be complete before **Enforce SSO** is enabled:

<Steps>
  <Step title="Test SSO sign-in">
    Click **Test SSO sign-in**. Barndoor opens a pop-up window and runs the full IdP login path—not just a connection preflight.

    Complete authentication in the pop-up. When the test succeeds, the row is marked complete. You can run the test again anytime to confirm sign-in still works.

    <Tip>
      If the pop-up is blocked, allow pop-ups for the Barndoor site and run the test again.
    </Tip>
  </Step>

  <Step title="Configure break-glass admin email">
    Click **Manage** on the **Break-glass admin email** row and set an emergency mailbox your security or platform team can use if your IdP is unavailable.

    * The address must use your organization's IdP email domain (shown as `@your-domain` in the dialog)
    * It must **not** already belong to an existing Barndoor user
    * You **cannot** use your own administrator email as the break-glass account

    Click **Save**. Barndoor stores the address as the configured break-glass email. The dedicated break-glass user account is created when you enforce SSO.
  </Step>
</Steps>

### Enable organization-wide SSO

<Steps>
  <Step title="Review the rollout card">
    When both prerequisites are complete, click **Enforce SSO** at the bottom of the rollout card.
  </Step>

  <Step title="Acknowledge each consequence">
    In the confirmation dialog, check every acknowledgement:

    * Future logins will be exclusively via IdP SSO
    * All Barndoor passwords will be permanently cleared
    * Only your break-glass email will be able to sign in via password going forward
    * All active sessions—including your current one—will be terminated

    The dialog also shows your IdP connection name and redirect URI for a final sanity check.
  </Step>

  <Step title="Confirm enforcement">
    Click **Confirm Enforcement**. On success, Barndoor shows **SSO enforcement is active** and prompts you to **Sign out and sign in with SSO**.

    <Note>
      If enforcement succeeds but Barndoor shows a warning that not all member passwords were cleared or sessions could not be terminated, SSO enforcement is still active. Sign out and sign in again with SSO, verify member access, and contact support if the warning persists.
    </Note>
  </Step>
</Steps>

<Check>
  SSO enforcement is active. All organization members must sign in through your Identity Provider. Password login is disabled for everyone except the break-glass account.
</Check>

### Set up the break-glass account

When enforcement completes, Barndoor provisions a dedicated **Barndoor Break Glass** administrator account at the email you configured and sends a setup email to that mailbox. The recipient must:

1. Open the setup email and follow the link to set a password
2. At first sign-in, complete the email one-time passcode (OTP) sent to that mailbox—the same second factor used during an IdP outage

Store break-glass credentials in your organization's secure emergency-access process (for example, a sealed envelope or privileged-access vault)—not in shared chat or email threads.

### Manage break-glass access after enforcement

After SSO is enforced, the rollout card shows **SSO enforcement** as active and lets you manage the break-glass email:

* **Resend invite** — If the break-glass account has not finished password setup, resend the setup email from the break-glass dialog
* **Change break-glass email** — Opens a destructive change flow. Enter the new address, check the acknowledgement that the current account will lose password sign-in, then click **Save**. The new mailbox must complete password and OTP setup before it can be used

<Warning>
  Changing the break-glass email while SSO is enforced removes the previous break-glass account's password credentials and requires the new mailbox to complete setup from scratch.
</Warning>

### Sign in with break-glass during an IdP outage

If your IdP is unavailable and you need emergency administrator access:

1. On the Barndoor sign-in page, choose password sign-in (not SSO)
2. Enter the break-glass email address and password
3. Complete the email one-time passcode sent to that mailbox

Password sign-in and email OTP at login are available **only** for the break-glass account once SSO is enforced. All other members must use IdP SSO.

### Remove the SSO connection (optional)

To disconnect IdP integration before or after enforcement, open the **actions menu** (⋯) on the rollout card and choose **Remove SSO**. Confirm when prompted.

<Warning>
  Removing the SSO connection immediately revokes IdP-based access for your organization. Only users who can still authenticate with a Barndoor password—including the break-glass account, if configured—can sign in. SSO enforcement remains on for the organization; re-connecting an IdP does not restore member password login.
</Warning>

### SSO enforcement troubleshooting

<AccordionGroup>
  <Accordion title="Test SSO sign-in pop-up blocked or closes early" icon="window-restore">
    **Common causes:**

    * Browser blocked pop-ups for the Barndoor site
    * The sign-in window was closed before authentication finished

    **Solution:** Allow pop-ups for your Barndoor portal origin, then click **Test SSO sign-in** again. If the test times out, cancel and retry.
  </Accordion>

  <Accordion title="Break-glass email rejected on Save" icon="envelope">
    **Common causes:**

    * Address is outside your organization's IdP email domain
    * Address already belongs to an existing Barndoor user
    * You entered your own administrator email

    **Solution:** Use a dedicated emergency mailbox on your IdP domain that is not yet a Barndoor user. Enter only the part before `@`—the domain is shown in the dialog.
  </Accordion>

  <Accordion title="Break-glass setup email not received" icon="paper-plane">
    **Solution:** From the break-glass **Manage** dialog after enforcement, click **Resend invite**. Check spam filters and confirm the mailbox is monitored. The recipient must complete password setup from the link before the account can sign in.
  </Accordion>

  <Accordion title="Enforcement succeeded with a warning" icon="triangle-exclamation">
    **Cause:** SSO enforcement is active, but Barndoor could not clear every member password or terminate every session.

    **Solution:** Sign out and sign back in with SSO. Verify affected members can still reach the app through your IdP. Contact Barndoor support if the warning remains or members report unexpected password login.
  </Accordion>
</AccordionGroup>

***

## Troubleshooting

<AccordionGroup>
  <Accordion title="SSO Login Fails" icon="key">
    **Common causes:**

    * Incorrect Client ID or Secret
    * Incorrect organization alias
    * User is not assigned to application

    **Solution**:

    * Verify OIDC credentials in both systems
    * Confirm organization alias is correct
    * Check user logging in is assigned to the Barndoor application
  </Accordion>

  <Accordion title="SCIM Connection Fails" icon="plug">
    **Common causes:**

    * Invalid or expired SCIM token

    **Solution**:

    * Generate a new SCIM token in Barndoor
  </Accordion>

  <Accordion title="Users Not Provisioning" icon="user-xmark">
    **Common causes:**

    * Provisioning not enabled in Okta
    * Users not assigned to the application
    * Attribute mapping conflicts

    **Solution**:

    * Verify "Create Users" is enabled in Provisioning settings
    * Check user assignments in the Assignments tab
    * Review attribute mappings for required fields
  </Accordion>

  <Accordion title="Groups Not Syncing" icon="users">
    **Common causes:**

    * Group push not configured
    * Group already exists with different ID

    **Solution**:

    * Enable "Push Groups" in Provisioning settings
    * Deactivate the group and re-add it to trigger reprovisioning
  </Accordion>
</AccordionGroup>

***

## Best Practices

<CardGroup cols={2}>
  <Card title="Use Groups for Assignment" icon="users">
    Assign Okta groups rather than individual users for easier management.
  </Card>

  <Card title="Test Before Production" icon="flask">
    Always test with a small group before rolling out to all users.
  </Card>

  <Card title="Monitor Provisioning Logs" icon="chart-line">
    Regularly check Okta's provisioning logs for any sync issues.
  </Card>

  <Card title="Secure SCIM Tokens" icon="lock">
    Rotate SCIM tokens periodically and store them securely.
  </Card>
</CardGroup>

***

## Summary

You've successfully configured the Okta integration with Barndoor using the Okta Integration Network!
This enables SSO and SCIM provisioning for your organization.

<Check>**Centralized authentication** - Users sign in with their Okta credentials</Check>
<Check>**Automated user lifecycle management** - Users are managed automatically</Check>
<Check>**Real-time group synchronization** - Membership changes take effect immediately</Check>
<Check>**Reduced manual work** - No need to manually provision users in Barndoor</Check>
<Check>**(Optional) Admin role mapping and organization-wide SSO enforcement** - See sections above</Check>

***
