Skip to main content

okta

Applies to:
OktaOIDCEnterprise SSOUniversal Directory

Overview​

This guide walks you through configuring Okta as an identity provider for DuoKey Cockpit. Once configured, your users can authenticate to Cockpit using their Okta credentials with full support for Okta's adaptive MFA and security policies.

Prerequisites

  • Admin access to Okta Admin Console
  • Admin access to DuoKey Cockpit
  • Your Cockpit domain URL (e.g., yourcompany.duokey.cloud)
  • Your Okta domain (e.g., yourcompany.okta.com)

Part 1: Okta Configuration​

Step 1: Create an OIDC Application​

Navigate to the Okta Admin Console and create a new OIDC application.

Access Applications

In Okta Admin Console, go to Applications > Applications

Create App Integration

Click Create App Integration

Select OIDC

Choose OIDC - OpenID Connect as the sign-in method

Select Web Application

Choose Web Application as the application type

Create OIDC Application

Step 2: Configure Application Settings​

Configure the OIDC application with the following settings:

SettingValue
App integration nameDuoKey Cockpit (or your preferred name)
Grant typeAuthorization Code
Sign-in redirect URIshttps://{yourCockpitDomain}/account/login
Sign-out redirect URIsOptional
Controlled accessBased on your organization policy

Sign-in Redirect URIs​

Configure the redirect URI to point to your Cockpit login endpoint:

https://{yourCockpitDomain}/account/login
Note
Replace {yourCockpitDomain} with your actual Cockpit domain, for example: https://mycompany.duokey.cloud/account/login

If you have multiple Cockpit environments, add all redirect URIs:

https://{yourCockpitDomain}/account/login
https://{yourCockpitApiDomain}.duokey.cloud/account/login

Application Configuration

Step 3: Get the Client ID​

After creating the application, note the Client ID from the General tab. You'll need this for Cockpit configuration.

Navigate to General

Go to Applications > Applications > Select your app > General

Copy Client ID

Copy the Client ID (alphanumerical token)

Client ID Location

Step 4: Note the Well-Known Configuration URL​

The OpenID Connect well-known configuration URL for Okta follows this pattern:

https://{yourOktaDomain}.okta.com/.well-known/openid-configuration
Tip
Replace {yourOktaDomain} with your Okta subdomain. For example, if your Okta URL is https://mycompany.okta.com, your well-known URL is https://mycompany.okta.com/.well-known/openid-configuration

Part 2: DuoKey Cockpit Configuration​

Step 1: Access Identity Provider Settings​

Login to Cockpit

Login to DuoKey Cockpit with an administrator account

Navigate to Administration

Go to Administration > Identity Providers

Create New IDP

Click Create Identity Provider

Step 2: Select Okta​

Select Okta from the available identity provider options and click Install Now.

Step 3: Configure Okta Connection​

Fill in the configuration form with the values from your Okta setup:

FieldValueDescription
Integration NameYour preferred nameThis name will be displayed on the login screen
Well-known Configurationhttps://{yourOktaDomain}.okta.com/.well-known/openid-configurationOther fields will be auto-populated
Client IDYour Okta Client IDFrom Okta application General tab

Enter Integration Name

Enter a descriptive name that will appear on the login screen (e.g., "Corporate Okta")

Enter Well-known URL

Paste your Okta well-known configuration URL. Other endpoint fields will auto-populate.

Enter Client ID

Paste the Client ID from your Okta application

Step 4: Test the Connection​

Click the Test Connection button to verify your configuration.

Click Test Connection

The system will attempt to connect to Okta

Verify Status

If successful, the status will change from "Offline" to "Online"

Troubleshoot if Needed

If the test fails, verify your Client ID and Well-known URL

Step 5: Save and Enable​

Submit Configuration

Click SUBMIT to save the identity provider configuration

Enable the IDP

From the Identity Providers list, click Actions > Enable

Step 6: Verify on Login Screen​

Once enabled, the Okta login option will appear on the Cockpit login screen. Users can click the Okta button to authenticate with their Okta credentials.

Configuration Summary​

ComponentValue
Okta App TypeOIDC Web Application
Grant TypeAuthorization Code
Sign-in Redirect URIhttps://{yourCockpitDomain}/account/login
Well-known Configurationhttps://{yourOktaDomain}.okta.com/.well-known/openid-configuration
ProtocolOpenID Connect (OIDC)

User Assignment in Okta​

Important

By default, Okta applications require explicit user or group assignment. Configure user access in Okta:

Go to Assignments

In your Okta app, navigate to the Assignments tab

Assign Users/Groups

Click Assign and select users or groups who should have access

Save Assignments

Confirm the assignments

Alternatively, you can enable self-service access or assign the app to everyone in your organization through Okta's assignment settings.

Troubleshooting​

Tip

Okta provides detailed logs in System Log. If you encounter issues, check Admin > Reports > System Log for authentication events related to your DuoKey Cockpit application.

Security Best Practices​

Enable MFA

Configure multi-factor authentication in your Okta Sign-On policies for enhanced security

Use Group Assignment

Assign the app to groups rather than individual users for easier management

Monitor Access

Review Okta System Log regularly for unusual authentication patterns

Session Policies

Configure appropriate session timeouts in Okta for your security requirements