--- title: "Enabling the Okta Integration" slug: "enabling-the-okta-integration" updated: 2026-06-06T21:25:27Z published: 2026-06-06T21:25:27Z canonical: "support.builtapp.com/enabling-the-okta-integration" stale: true --- > ## Documentation Index > Fetch the complete documentation index at: https://support.builtapp.com/llms.txt > Use this file to discover all available pages before exploring further. # Enabling the Okta Integration --- If you’re currently using Okta, you can allow individuals to access Built via Okta SSO. If your Built plan includes provisioning, you can also manage access to Built through Okta. ## Available Okta Integration Features ### Okta OIDC SSO - Assigned users can [access Built via Okta SSO](/v1/docs/accessing-built-via-okta-sso) (SP and IdP Initiated). ### Okta OIDC SSO with SCIM Provisioning ****Provisioning features are available with our upgraded integration subscription.*** - Assigned users can [access Built via Okta SSO](/v1/docs/accessing-built-via-okta-sso) (SP and IdP Initiated). - Okta users assigned to the Built application are automatically added as Built users. - When assigned Okta users are deactivated or unassigned from the app, corresponding Built users are automatically deleted. - Changes to a user's name or primary email in Okta will update the individual's name and work email in Built. *Provisioning features are built around an industry-standard protocol known as SCIM (System for Cross-domain Identity Management). To learn more about how Okta works with SCIM, refer to:* [*What is SCIM?*](https://www.okta.com/blog/2017/01/what-is-scim/) ## To set up your Okta integration, first subscribe to the Built app in Okta: 1. Log in to Okta as an admin. 2. From the main menu, click the **Applications** dropdown, then click **Applications**. 3. Click the **Browse App Catalog** button. 4. Enter “Built” in the Search field, and select the **Built** application. 5. Click the **+ Add Integration** button and follow the prompts. 6. Click **Done**. 7. Navigate to the **Sign On** tab and click **Edit**. 8. Under **Advanced Sign-on Settings**, enter your company identifier. *To obtain your company identifier, log in to Built, navigate to* ***Settings*** *>* ***Integrations****, and click* ***Okta Integration****.* ## Next, configure the integration in Built: *Only Company Admins can configure company integration settings. Learn more about* [*managing user roles and permissions*](/v1/docs/managing-user-roles-and-permissions)*.* 1. In a separate browser tab, log in to your Built account. 2. Click your company name at the top of the main navigation, then click **Company Settings**. 3. Click the **Integrations** tab. 4. In the **Integrations** table, click the **Okta** dropdown, then click **Connect**. 5. When the Okta window opens, enter the Okta URL, Client ID, and Client Secret. *You can locate your Okta URL in your Okta account by clicking the user dropdown in the upper-right corner of the page. The URL will appear below your Okta username in the dropdown. To obtain your Client ID and Client Secret, navigate to* ***Applications*** *>* ***Applications****, select the* ***Built*** *app, and then click the* ***Sign On*** *tab.* 6. If your Built plan includes provisioning*, select **Yes** to enable user provisioning from Okta to Built**.** 7. Click **Connect**. ​*If your plan includes provisioning, remain logged into Built to obtain the Built connection code when completing provisioning authorization.* ## To complete provisioning* authorization in Okta: 1. Navigate to the browser tab where you are logged into your Okta account. 2. Go to **Applications** > **Applications**, and select the Built application. 3. Click the **Provisioning** tab. 4. Click **Edit** to adjust the SCIM Connection settings. 5. Paste [https://secure.builtapp.com/{connection code}/scim/v2](https://qa3.builtforteams.com/039bbca4-57eb-4efa-bff4-445def142186/scim/v2/) in the SCIM connector base URL field, replacing {connection code} with your connection code provided by Built. In the API Token field, paste the token provided by Built**. ​***You can locate the Built connection code and token by navigating to* ***Settings*** *>* ***Integrations*** *in Built.* 6. Click the **Test Connector Configuration** button. 7. Click **Save.** 8. Click **Edit the Provisioning To App**. 9. Click the checkboxes for **Create Users**, **Update User Attributes**, and **Deactivate Users**. 10. Click **Save**. ## Assigning Users to the Built App in Okta To allow people to access Built via Okta SSO, you must [assign individuals](https://help.okta.com/oie/en-us/content/topics/users-groups-profiles/usgp-assign-apps.htm) to the Built application in Okta, including individuals you’ve already [invited to your Built account](/v1/docs/inviting-others-to-your-account). Assigned users can then [access Built via Okta SSO](/v1/docs/accessing-built-via-okta-sso). *Individuals who created a password in Built prior to being assigned to the Built app in Okta can still access Built directly using their password. By* [*enforcing SSO*](/v1/docs/enforcing-single-sign-on-sso)*, you can prevent new Built users from creating a password. If your plan includes provisioning*, Okta SSO is enforced automatically for new Built users provisioned through Okta.* ### Provisioning* New Built Users in Okta If your plan includes [provisioning*](/v1/docs/enabling-the-okta-integration#okta-oidc-sso-with-scim-provisioning), assigning an individual to the Built app will create a new user in Built if they haven’t already created a user account. If the person does not yet have a profile in Built, a profile will be created for the new user. *Changes to an individual's name or username in Okta will update the person’s name and work email in Built.* ## Deactivating, Unassigning, or Suspending Okta Users When a user is [deactivated](https://help.okta.com/en-us/content/topics/users-groups-profiles/usgp-deactivate-user-account.htm), [unassigned](https://help.okta.com/en-us/content/topics/users-groups-profiles/usgp-unassign-apps.htm), or [suspended](https://help.okta.com/en-us/content/topics/users-groups-profiles/usgp-suspend.htm) in Okta, the user will be unable to access Built via Okta SSO. If the user is later reassigned to the Built application in Okta, their SSO access will be restored. ### Notes about deactivating, unassigning, and suspending users: - *If your plan does not include provisioning, a deactivated, unassigned, or suspended individual with an existing Built password can still access the platform using their password.* - *If your plan includes* [*provisioning**](/v1/docs/enabling-the-okta-integration#okta-oidc-sso-with-scim-provisioning)*, a suspended user with an existing Built password can still access the platform using their password—we recommend deactivating or unassigning users in Okta to revoke Built access.* - *Whether or not your plan includes provisioning, a deactivated, unassigned, or suspended individual’s employee status in Built will not be impacted. A person’s data will be maintained across Built as long as their employee status is active. If necessary, you can update a person's employee status manually or via import. To update an individual's employee status manually, navigate to their profile, click the three-dot menu next to their name, and then click* ***Change Employee Status****. Select the appropriate option from the* ***Status*** *dropdown before clicking the* ***Save*** *button.* ## Disabling the Okta Integration You may disable the Okta integration at any time [through Okta](https://help.okta.com/en-us/content/topics/apps/apps-deactivate.htm) or Built. *If your plan includes* [*provisioning**](/v1/docs/enabling-the-okta-integration#okta-oidc-sso-with-scim-provisioning)*, you must* [*unassign users*](https://help.okta.com/en-us/content/topics/users-groups-profiles/usgp-unassign-apps.htm) *from the Built app in Okta before disabling the integration to ensure corresponding Built users are deleted and cannot access the platform using existing passwords.* ### To disable the Okta Integration in Built: 1. Click your company name at the top of the main navigation, then click **Company Settings**. 2. Click the **Integrations** tab. 3. Click the **Okta** dropdown, then click **Edit**. 4. When the Okta Integration window opens, click **Disable**. 5. Click **Yes, Disable the Okta Integration**. Please contact our Customer Success Team for additional assistance. ## Additional Resources [Using Single Sign-on (SSO) with Your Built Account](/v1/docs/using-single-sign-on-sso-with-your-built-account) [Enforcing Single Sign-On (SSO)](/v1/docs/enforcing-single-sign-on-sso)