Okta Single Sign-On and SCIM Provisioning

Add IssueBadge to your Okta org once. Staff sign in from the Okta dashboard, and joiners and leavers are provisioned and deactivated automatically. No passwords to manage, no orphaned accounts.

  • OpenID Connect sign-in, Okta-initiated or from the IssueBadge login page
  • SCIM 2.0 provisioning: create, update, deactivate, and reactivate users
  • Accounts created on first sign-in with the role you choose
  • Free on every plan; set up in about ten minutes
  • Listed in the Okta Integration Network: follow the Okta configuration guide

IssueBadge in Okta

OIDC web app + SCIM provisioning

Sign-inOpenID Connect
ProvisioningSCIM 2.0, bearer token
New joiner✓ Account created
Leaver✓ Deactivated

✓ Certificates and history stay intact when someone is deactivated.

Identity handled by Okta, certificates by IssueBadge

Everything a security review asks for, without a custom project.

One click sign-in

Team members open IssueBadge from their Okta dashboard. MFA and session policies come from Okta.

Joiners and leavers

Assign the app to a group in Okta and accounts appear in IssueBadge. Unassign and access ends the same minute.

Nothing lost

Deactivation never deletes. Issued certificates, verification pages and audit history stay.

Connect Okta in 4 steps

You need an Okta admin account and the owner login of your IssueBadge workspace.

1

Create the app in Okta

In Okta Admin go to Applications → Create App Integration, choose OIDC and Web Application. Name it IssueBadge.

2

Paste the IssueBadge URLs

In IssueBadge open Settings → Single sign-on, choose Okta, and copy the Redirect URI and Initiate login URI into the Okta app. Assign the app to the groups that should have access.

3

Copy the client details back

Paste the Okta Client ID, Client secret and your org URL (issuer) into IssueBadge, add your email domains, click Test sign-in, then turn single sign-on on.

4

Turn on provisioning (optional)

In IssueBadge click Generate token. In the Okta app open Provisioning → Configure API Integration, enter the SCIM base URL and the token, then enable Create Users, Update User Attributes and Deactivate Users.

IssueBadge supports SCIM 2.0 with bearer authentication, userName as email, and PATCH for activation changes.

Values you will need

Setting Value
Sign-in protocolOpenID Connect (authorization code)
Issuerhttps://<your-org>.okta.com
Redirect URIhttps://app.issuebadge.com/sso/callback
Initiate login URIhttps://app.issuebadge.com/sso/start
SCIM base URLhttps://app.issuebadge.com/scim/v2
SCIM authenticationHTTP header, Bearer token
Unique identifieruserName (email)

The exact redirect and initiate-login URLs for your workspace are shown in IssueBadge under Settings → Single sign-on.

Frequently asked questions

Is IssueBadge in the Okta Integration Network?

Yes. Search for IssueBadge in the Okta app catalog and follow the configuration guide at /h/integration/okta/configuration-guide. You can also add it as a custom OIDC app with the steps above; the result is identical.

Do existing team members need to do anything?

No. Their accounts stay as they are. The first time they sign in through Okta they are matched by email.

What role do new people get?

The role you pick in the single sign-on settings, developer by default. Owners can change roles later from Team settings.

Can Okta remove the workspace owner?

No. Deactivation requests for the owner are refused so a workspace can never lock itself out.

Does this cost extra?

No. Single sign-on and SCIM are included on every IssueBadge plan.

What about SAML?

IssueBadge uses OpenID Connect, which Okta supports for every app. SAML is not required.

Your Okta org, your certificate platform

Set it up once. Access follows your directory from then on.

Start free with IssueBadge