Loading

Configure Okta and Quip for Single Sign-On (SSO)

Udgivelsesdato: Aug 25, 2026
Beskrivelse

This article provides step-by-step instructions for configuring Okta as a SAML (Security Assertion Markup Language) identity provider (IdP) for Quip single sign-on (SSO). SSO allows your users to log in to Quip using their Okta credentials without a separate Quip password. Use this article when setting up Quip SSO for the first time with Okta or when troubleshooting an existing SSO configuration.

Løsning

Prerequisites

  • Administrator access to both Okta and the Quip Admin Console
  • A Quip site with SSO enabled (contact Quip Support if SSO is not yet enabled on your site)

Configure Okta as a SAML Identity Provider

  1. In Okta, create a new SAML 2.0 application for Quip.
  2. Set the Single Sign-On URL to your Quip SSO callback URL: https://[yoursite].quip.com/saml/login
  3. Set the Audience URI (SP Entity ID) to: https://[yoursite].quip.com
  4. Set the Name ID format to EmailAddress.
  5. Download the Okta SAML metadata XML file from the Sign On tab of your Okta application.
  6. In the Quip Admin Console, navigate to Security > Single Sign-On.
  7. Upload the Okta metadata XML file.
  8. Save the configuration.

Example: A company migrating from password-based Quip logins to SSO configures Okta as the identity provider so that employees are automatically authenticated with their corporate credentials when they open Quip, eliminating the need to manage a separate Quip password.

IdP-Initiated vs. SP-Initiated SSO

Quip supports both SSO flow types:

  • IdP-initiated: The user starts at the Okta dashboard and clicks the Quip tile to log in. Quip receives a SAML assertion and creates or matches the user account.
  • SP-initiated: The user navigates to your Quip site URL directly. Quip redirects the user to Okta for authentication, then back to Quip after successful login.

Setting Up a Test User

Before enabling SSO for all users, assign the Quip application to a single test user in Okta. Verify that the test user can log in successfully using both IdP-initiated and SP-initiated flows before rolling out to the full organization.

Single Identity Provider Limitation

Quip supports only one SAML identity provider per site. If your organization uses multiple IdPs, you must configure a single IdP that all users authenticate through, or use a federation service to aggregate multiple IdPs into one.

Certificate Renewal

SAML certificates expire and must be renewed before the expiration date to prevent SSO from breaking. When an Okta certificate is renewed, download the updated metadata XML from Okta and re-upload it in the Quip Admin Console under Security > Single Sign-On. Users will not be able to log in via SSO if the certificate is expired.

Vidensartikelnummer

000390279

 
Indlæser
Salesforce Help | Article