Documentation

gitHub

Integrating with Okta

On this page, you will find a step-by-step guide to integrating Okta with the Model HUB portal.

 

Pre-requisites

In order to perform the operations in this guide, you will need the following:

  • Access to the administration panel on Okta with the ability to create an app integration and authorization server
  • Be able to create groups and assign them to users

 

1. Create an app integration

IIn Okta, select Applications -> Applications, then click on Create App integration

 

In the modal, select OIDC - OpenID Connect and Single-Page Application as the Application, then click Next

 

Give a name to your app, then add the following options

 

2. Create a new group

In order to give users administrative access to the Model HUB portal, you should create a new group

 

In Okta, select Directory -> Groups, then click on Add group

 

Fill the form with the following:

  • Name: Hub.Admin
  • Description: A group that gives access to the admin UI of the Model Hub portal

 

Once the group is created, you can start assigning users to this group

 

3. Configure the authorization server

To retrieve the groups a user belongs to in the Model HUB, you will need to configure the authorization server to include them in the access token.

 

In Okta, select Security -> API, then select the authorization server you want to use (or the default one)

 

Go to Claims, then click on Add Claim

 

Fill the model with the following information:

  • Name: roles
  • Include in token type: Select Access Token
  • Value type: Groups
  • Filter: Select Starts with and fill in "Hub"
  • Include in: Select any scope

 

Make sure you have an Access Policy configured by going to the Access Policies tab

 

4. Configure the application in the admin portal

Finally, to configure the application to use Okta as an authentication server, you will need to go to the admin portal -> Authentication, click on the Authentication enabled toggle, then fill the form with the following

 

  • Identity provider: Okta
  • Domain: The domain name of your Okta deployment
  • Client ID: Go to Okta, select Applications -> Applications then click on the app you just created and copy the Client ID in the client credentials section
  • Authorization server ID (optional): Specify the authorization server configured in step 3. Uses default by default