Requirements
Admin access to an Okta tenant
That’s it for requirements! All Ben instances are configured for SAML by default, so you just need to follow the rest of the guide to get up and running
Supported Features
IdP-initiated SSO
SP-initiated SSO
For more information on the listed features, visit the Okta Glossary.
Configuration Steps
⚠️ Enabling SAML will affect all users who use the Ben app.
Ben doesn't provide a backup sign-in URL where users can sign in using their regular username and password. If necessary, contact Ben Support to turn off SAML for your instance.
In the Okta dashboard, navigate to
Applications
and then select theApplications sub-menu
.Click on
Browse App Catalog
, search forBen
and add the application.Navigate to the Ben application. Go to the
Sign On
tab on, copy theMetadata URL
and send it to the Ben team working on your implementationThe Ben team will provide you will provide you with your unique Customer ID value.
In Okta, select the Sign On tab for the Ben app, then click Edit.
Scroll down to Advanced Sign-on Settings.
Enter your Customer ID (step 4) into the corresponding field.
Click Save.
Congrats! You’ve set up Ben for Okta SSO.
SAML attributes
The required SAML claims are preconfigured in the marketplace app, but just in case you need them, we’ve compiled them in the table below:
Name | Value |
user.email | |
given_name | user.firstName |
family_name | user.lastName |
SP-initiated SSO
Navigate to ben.thanksben.com
Enter your email address and click Continue
Thanks Ben Icon
This is an icon you can use for the Thanks Ben app.