Skip to main content
Fini supports SAML 2.0 single sign-on with Okta as the identity provider. Once it’s set up, your team signs in with their Okta credentials instead of a separate Fini login, and access is governed by your Okta assignments. Setup has two halves. You create and assign a SAML app in Okta, then send Fini your metadata URL and email domains so we can register your provider. Plan for one business day between sending us those details and SSO going live.

Service provider values

Enter these Fini values when you configure the SAML app in Okta. They’re the same for every customer.

Configure the SAML app in Okta

1

Create the app integration

In your Okta admin console, go to Applications → Create App Integration, choose SAML 2.0, and continue. Name it “Fini Dashboard”.
2

Enter the SAML settings

On the Configure SAML step, set:
3

Add the attribute statements

Still on the Configure SAML step, under Attribute Statements, add these three rows. The names on the left must match exactly, because Fini reads them by name.
4

Finish and assign users

Complete the setup wizard, then open the app’s Assignments tab and assign every user or group who should have Fini access. Only assigned users can sign in.
The Name ID format must be Persistent and the three attribute names must match the table exactly. A different Name ID format, or a renamed attribute, is the most common reason a SAML response is rejected or a user’s name renders blank in Fini.

Send Fini your details

Email [email protected] with two things: your IdP metadata URL and your email domains. Find the metadata URL on the app’s Sign On tab in Okta, under “View SAML setup instructions” or “Identity Provider metadata”. For the domains, list every domain your team signs in with, for example acme.com. We register your provider within one business day and reply to confirm. After that, your team signs in at app.usefini.com, clicks “Continue with SSO”, and enters their work email.

If your team already has Fini accounts

Teammates who already have a Fini account, created through Google login or an invite, are handled separately. On their first SSO sign-in, Okta authenticates them but Fini treats the SSO identity as a new account, so they land on the onboarding page instead of your workspace. To link them, email [email protected] with the affected users’ email addresses. We connect each existing account to its SSO identity, and their next sign-in resolves to the right workspace with their history intact.
Have affected teammates sign in through SSO once before you send us their emails. That first sign-in creates the SSO identity we link to.

Why SSO isn’t working

Your Fini account predates SSO and isn’t linked yet. Sign in through SSO once, then email [email protected] with your email address so we can connect the existing account. See If your team already has Fini accounts.
Either the domain isn’t registered yet (allow one business day after you send it), or the email you entered is on a domain you didn’t send us. Confirm the exact domain with the person who completed setup.
The Single sign-on URL or Audience URI in Okta doesn’t match the service provider values above, or the Name ID format isn’t Persistent. Re-check all three against the table.
The first_name and last_name attribute statements are missing or renamed. Open the SAML app’s Configure SAML step and confirm the three attribute rows match the table exactly.