Set up SSO with Keepit using the Okta Integration Network
This article explains how to add Keepit to an Okta organization from the Okta Integration Network (OIN) catalog and configure single sign-on (SSO). The integration uses SAML 2.0, with Okta as the identity provider.
Prerequisites
Before you configure the integration, make sure that:
- Your Keepit account is hosted in a supported data center: Denmark (Copenhagen), United States (Washington, DC), Canada (Toronto), Australia (Sydney), United Kingdom (London), Germany (Frankfurt), or Switzerland (Zurich).
- You have a Keepit role that can set up SSO (Master Admin, SSO Admin, Partner Parent, or MSP Full Admin role).
- You have the super administrator role in Okta, or both the app administrator and organization administrator roles.
- You created a dedicated SSO Admin user in Keepit. For instructions, see Create an SSO Admin user.
- Users who need SSO access exist in both Okta and Keepit with matching email addresses. Keepit doesn’t auto-provision users from SAML assertions.
- You know your data center identifier. See Part I below for the list.
Supported features
The Keepit integration in the OIN catalog supports:
- SP-initiated SSO (recommended)
- IdP-initiated SSO (optional, disabled by default)
- SAML 2.0 with SHA-256 signature and digest algorithms
- Force authentication (ForceAuthn), enabled by default in the OIN wizard
- A dedicated SSO Admin fallback role that signs in with Keepit credentials
The integration doesn’t support:
- Just-in-time (JIT) provisioning (users must exist in the Keepit account before they sign in with SSO)
- SCIM-based lifecycle management
- SP-initiated single logout (SLO)
- Encrypted SAML assertions
- Group claims or attribute statements beyond the SAML subject (NameID)
For more information about these terms, see the Okta Glossary.
Configuration steps
The configuration has three parts: add Keepit in Okta, get the SAML metadata from Okta, and complete the SSO setup in Keepit.
Part I: Add Keepit to the Okta organization
You enter a data center identifier in this phase. Use the identifier that matches your Keepit account.