Skip to main content
SSO is available on Enterprise plans, with your domains enabled by the Blinq team. Read How SAML SSO works first — it covers registering your domains, which has to happen before the SAML settings will open.
There’s no Blinq app in the Okta Integration Network, so you build a SAML 2.0 app integration yourself. It takes a few minutes and needs no custom attributes.

Create the app integration

1

Start a new integration

In the Okta Admin dashboard, open Applications → Applications, select Create App Integration, choose SAML 2.0, then Next.
2

Name it

Give the app a name your team will recognise, and add a logo if you like. Select Next.

Send Blinq’s details to Okta

In the Blinq dashboard, go to Settings → SAML and keep it open.
1

Single sign-on URL

Paste the ACS URL from Blinq.
2

Audience URI

Paste the Service provider entity ID from Blinq into Audience URI (SP Entity ID).
3

Leave RelayState blank

Nothing goes in Default RelayState.
4

Set the name ID and username formats

Set Name ID format to EmailAddress, and Application username to Okta username.
5

Finish

Blinq needs no attribute statements, so select Next, answer the customer question, and select Finish.

Send Okta’s details to Blinq

Open your new app, select the Sign On tab, and expand More details in the SAML 2.0 panel.
Paste the certificate exactly as Okta gives it to you, with no reformatting or added line breaks.
Use the entity ID Okta gives you. Okta issues an app-scoped identifier that looks like http://www.okta.com/exk…. That’s correct — don’t replace it with an organisation-level value.
Select Save in Blinq, then test a sign-in in a separate browser or private window before going further.

Enforce SSO

Once a test sign-in works, switch on Enforce SSO for all users at the bottom of the SAML settings and save. Everyone signing in with an address on your registered domains is now routed through Okta. See How SAML SSO works for what changes.
Don’t sign out of Blinq until a test sign-in has succeeded in another window. If enforcement is on and the configuration is wrong, only Blinq support can switch it back off.

Launching Blinq from Okta

If you want people to open Blinq from its tile in their Okta dashboard, contact support@blinq.me to have it enabled for your workspace. It currently requires enforcement to be switched on as well — see How SAML SSO works.
Provisioning accounts from Okta is a separate setup. See SCIM provisioning with Okta.

Need help?

For any questions or issues, contact Blinq support or email support@blinq.me.