Okta Single Sign-On and SCIM Provisioning
Add IssueBadge to your Okta org once. Staff sign in from the Okta dashboard, and joiners and leavers are provisioned and deactivated automatically. No passwords to manage, no orphaned accounts.
- OpenID Connect sign-in, Okta-initiated or from the IssueBadge login page
- SCIM 2.0 provisioning: create, update, deactivate, and reactivate users
- Accounts created on first sign-in with the role you choose
- Free on every plan; set up in about ten minutes
- Listed in the Okta Integration Network: follow the Okta configuration guide
IssueBadge in Okta
OIDC web app + SCIM provisioning
✓ Certificates and history stay intact when someone is deactivated.
Identity handled by Okta, certificates by IssueBadge
Everything a security review asks for, without a custom project.
One click sign-in
Team members open IssueBadge from their Okta dashboard. MFA and session policies come from Okta.
Joiners and leavers
Assign the app to a group in Okta and accounts appear in IssueBadge. Unassign and access ends the same minute.
Nothing lost
Deactivation never deletes. Issued certificates, verification pages and audit history stay.
Connect Okta in 4 steps
You need an Okta admin account and the owner login of your IssueBadge workspace.
Create the app in Okta
In Okta Admin go to Applications → Create App Integration, choose OIDC and Web Application. Name it IssueBadge.
Paste the IssueBadge URLs
In IssueBadge open Settings → Single sign-on, choose Okta, and copy the Redirect URI and Initiate login URI into the Okta app. Assign the app to the groups that should have access.
Copy the client details back
Paste the Okta Client ID, Client secret and your org URL (issuer) into IssueBadge, add your email domains, click Test sign-in, then turn single sign-on on.
Turn on provisioning (optional)
In IssueBadge click Generate token. In the Okta app open Provisioning → Configure API Integration, enter the SCIM base URL and the token, then enable Create Users, Update User Attributes and Deactivate Users.
IssueBadge supports SCIM 2.0 with bearer authentication, userName as email, and PATCH for activation changes.
Values you will need
| Setting | Value |
|---|---|
| Sign-in protocol | OpenID Connect (authorization code) |
| Issuer | https://<your-org>.okta.com |
| Redirect URI | https://app.issuebadge.com/sso/callback |
| Initiate login URI | https://app.issuebadge.com/sso/start |
| SCIM base URL | https://app.issuebadge.com/scim/v2 |
| SCIM authentication | HTTP header, Bearer token |
| Unique identifier | userName (email) |
The exact redirect and initiate-login URLs for your workspace are shown in IssueBadge under Settings → Single sign-on.
Frequently asked questions
Is IssueBadge in the Okta Integration Network?
Yes. Search for IssueBadge in the Okta app catalog and follow the configuration guide at /h/integration/okta/configuration-guide. You can also add it as a custom OIDC app with the steps above; the result is identical.
Do existing team members need to do anything?
No. Their accounts stay as they are. The first time they sign in through Okta they are matched by email.
What role do new people get?
The role you pick in the single sign-on settings, developer by default. Owners can change roles later from Team settings.
Can Okta remove the workspace owner?
No. Deactivation requests for the owner are refused so a workspace can never lock itself out.
Does this cost extra?
No. Single sign-on and SCIM are included on every IssueBadge plan.
What about SAML?
IssueBadge uses OpenID Connect, which Okta supports for every app. SAML is not required.
Your Okta org, your certificate platform
Set it up once. Access follows your directory from then on.
Start free with IssueBadge