Prerequisites
- An Okta admin account with permission to add and configure app integrations.
- A ClosedLoop AI workspace admin account.
- Your ClosedLoop AI workspace ID.
- Your ClosedLoop AI workspace region: US or EU.
Supported Features
ClosedLoop AI validates the Okta issuer, audience, signature, state, nonce, and email claim before creating an application session.
Configure Okta
Step 1: Add ClosedLoop AI from the Okta catalog
Step 1: Add ClosedLoop AI from the Okta catalog
- In Okta Admin, go to Applications > Applications.
- Click Browse App Catalog.
- Search for ClosedLoop AI.
- Add the ClosedLoop AI integration.
Step 2: Enter tenant settings
Step 2: Enter tenant settings
Enter the tenant settings for the ClosedLoop AI workspace you are connecting.
Use
us for https://app.closedloop.sh. Use eu for https://eu.app.closedloop.sh.Step 3: Copy Okta OIDC credentials
Step 3: Copy Okta OIDC credentials
After Okta creates the app instance, open the app’s Sign On tab and copy:
The issuer is normally your Okta org URL, such as
https://example.okta.com.Step 4: Save OIDC settings in ClosedLoop AI
Step 4: Save OIDC settings in ClosedLoop AI
- Sign in to ClosedLoop AI as a workspace admin.
- Go to Integrations > Okta.
- Enter your Okta domain or issuer.
- Paste the Okta Client ID and Client secret.
- Choose the default provisioned role. Use Member unless every new Okta user should become a workspace admin.
- Enable Okta sign-in.
- Enable Just-in-Time provisioning if users should be created when they first sign in through Okta.
- Save the configuration.
Step 5: Assign users
Step 5: Assign users
In Okta, assign the ClosedLoop AI app to the users or groups who should have access.If Just-in-Time provisioning is off, the user must already exist in ClosedLoop AI or be provisioned through SCIM before sign-in.
Okta OIN Values
These are the OIDC values used by the ClosedLoop AI Okta catalog integration.
ClosedLoop AI supports Universal Logout through Global Token Revocation. It does not use the OIDC Post Logout URI field.
Universal Logout
Configure Universal Logout with Global Token Revocation.
When Okta sends a valid Global Token Revocation request, ClosedLoop AI revokes the user’s ClosedLoop AI access tokens and MCP tokens.
Verify SSO
- Assign a test user to the ClosedLoop AI app in Okta.
- Open the ClosedLoop AI sign-in page for the workspace region.
- Enter the test user’s email address.
- Confirm ClosedLoop AI redirects the user to Okta.
- Complete Okta sign-in.
- Confirm the user returns to ClosedLoop AI.
For IdP-initiated SSO, launch ClosedLoop AI from the Okta End-User Dashboard app tile.
Troubleshooting
Support
For help configuring Okta OIDC SSO with ClosedLoop AI, contactsupport@closedloop.sh.