> ## Documentation Index
> Fetch the complete documentation index at: https://docs.usefini.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Okta SSO

> Configure SAML 2.0 single sign-on so your team signs into Fini with their Okta accounts.

Fini supports SAML 2.0 single sign-on with Okta as the identity provider. Once it's set up, your team signs in with their Okta credentials instead of a separate Fini login, and access is governed by your Okta assignments.

Setup has two halves. You create and assign a SAML app in Okta, then send Fini your metadata URL and email domains so we can register your provider. Plan for one business day between sending us those details and SSO going live.

## Service provider values

Enter these Fini values when you configure the SAML app in Okta. They're the same for every customer.

| Field | Value |
| - | - |
| ACS URL (Single sign-on URL) | `https://auth.usefini.com/auth/v1/sso/saml/acs` |
| Entity ID (Audience URI) | `https://auth.usefini.com/auth/v1/sso/saml/metadata` |
| Name ID format | Persistent |
| Attributes | `email`, `first_name`, `last_name` |

## Configure the SAML app in Okta

<Steps>
  <Step title="Create the app integration">
    In your Okta admin console, go to **Applications → Create App Integration**, choose **SAML 2.0**, and continue. Name it *"Fini Dashboard"*.
  </Step>

  <Step title="Enter the SAML settings">
    On the **Configure SAML** step, set:

    | Okta field | Value |
    | - | - |
    | Single sign-on URL | `https://auth.usefini.com/auth/v1/sso/saml/acs` |
    | Audience URI (SP Entity ID) | `https://auth.usefini.com/auth/v1/sso/saml/metadata` |
    | Name ID format | `Persistent` |
    | Application username | `Email` |
  </Step>

  <Step title="Add the attribute statements">
    Still on the **Configure SAML** step, under **Attribute Statements**, add these three rows. The names on the left must match exactly, because Fini reads them by name.

    | Name | Value |
    | - | - |
    | email | user.email |
    | first\_name | user.firstName |
    | last\_name | user.lastName |
  </Step>

  <Step title="Finish and assign users">
    Complete the setup wizard, then open the app's **Assignments** tab and assign every user or group who should have Fini access. Only assigned users can sign in.
  </Step>
</Steps>

<Warning>
  The Name ID format must be **Persistent** and the three attribute names must match the table exactly. A different Name ID format, or a renamed attribute, is the most common reason a SAML response is rejected or a user's name renders blank in Fini.
</Warning>

## Send Fini your details

Email **[hello@usefini.com](mailto:hello@usefini.com)** with two things: your IdP metadata URL and your email domains.

Find the metadata URL on the app's **Sign On** tab in Okta, under *"View SAML setup instructions"* or *"Identity Provider metadata"*. For the domains, list every domain your team signs in with, for example `acme.com`.

We register your provider within one business day and reply to confirm. After that, your team signs in at [app.usefini.com](https://app.usefini.com), clicks *"Continue with SSO"*, and enters their work email.

## If your team already has Fini accounts

Teammates who already have a Fini account, created through Google login or an invite, are handled separately. On their first SSO sign-in, Okta authenticates them but Fini treats the SSO identity as a new account, so they land on the onboarding page instead of your workspace.

To link them, email **[hello@usefini.com](mailto:hello@usefini.com)** with the affected users' email addresses. We connect each existing account to its SSO identity, and their next sign-in resolves to the right workspace with their history intact.

<Note>
  Have affected teammates sign in through SSO once before you send us their emails. That first sign-in creates the SSO identity we link to.
</Note>

## Why SSO isn't working

<AccordionGroup>
  <Accordion title="After signing in, I land on an onboarding or setup page" icon="user-plus">
    Your Fini account predates SSO and isn't linked yet. Sign in through SSO once, then email **[hello@usefini.com](mailto:hello@usefini.com)** with your email address so we can connect the existing account. See [If your team already has Fini accounts](#if-your-team-already-has-fini-accounts).
  </Accordion>

  <Accordion title="Continue with SSO doesn't recognize my email" icon="at">
    Either the domain isn't registered yet (allow one business day after you send it), or the email you entered is on a domain you didn't send us. Confirm the exact domain with the person who completed setup.
  </Accordion>

  <Accordion title="Okta reports an invalid SAML response" icon="triangle-exclamation">
    The Single sign-on URL or Audience URI in Okta doesn't match the service provider values above, or the Name ID format isn't Persistent. Re-check all three against the table.
  </Accordion>

  <Accordion title="My name shows up blank in Fini" icon="user">
    The `first_name` and `last_name` attribute statements are missing or renamed. Open the SAML app's **Configure SAML** step and confirm the three attribute rows match the table exactly.
  </Accordion>
</AccordionGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.