Skip to main content
All CollectionsCommandSAML/SSO
OIDC based SSO for Okta
OIDC based SSO for Okta
Updated over a week ago

Verkada Command supports Single Sign-On (SSO) through OpenID Connect (OIDC) with Okta. This integration allows our users to seamlessly and securely authenticate using their existing Okta credentials, streamlining access to Command and enhancing overall security.

OIDC configuration

  1. Navigate to your Okta instance to create a new application to manage your OIDC configuration. Click on Applications from the Applications sidebar option and click Create App Integration.

  2. Under Create a new app integration, select OIDC - OpenID Connect as your Sign-in method and Single-Page Application as your Application type.

  3. Under Sign-in redirect URIs give your application an identifiable name and add https://command.verkada.com/oidc/okta/callback/ to the list of permitted URIs.

  4. Under Assignments, select Skip Group Assignment for now and click Save.

  5. Under Assignments, click on the Assign dropdown to assign this application to your (and other relevant) user profiles.

  6. Under General tab, copy the Client ID displayed under Client Credentials.


Command configuration

  1. In Verkada Command, go to All Products > Admin.

  2. In the left navigation, select Privacy & Security .

  3. Under Authentication & User Configuration select Single Sign-On Configuration.

  4. Next to OIDC Configuration, click Add New.

  5. Under Select Provider, select Okta.

  6. Under Client and Tenant ID's click Add.

    1. In the Client ID field paste the Client ID you copied from Okta.

    2. In the Tenant ID field enter the first part of your Okta instance’s URL. It should look like this: https://YourInstanceName.okta.com/.

    3. Click on Done to complete the configuration.

  7. Under Login Test click Run Login Test.

  8. A successful login test should redirect to the OIDC configuration page. Once you’re logged in, add the domain that you need to whitelist.

  9. Once your domain is added, run the login test again. SSO will not be enabled until this second login test successfully completes.

  10. Once your domain is verified, you should see it successfully validated.


Need more help? Contact Verkada Support.

Did this answer your question?