Service Center

OKTA - SAML2.0

eSignGlobal supports federated authentication based on SAML 2.0. You can integrate OKTA with eSignGlobal through SAML 2.0 federated authentication to achieve single sign-on for OKTA accounts to eSignGlobal without having to create separate accounts for each user in the enterprise or organization.

Creating an OKTA Application

  1. Log in to the OKTA developer backend.

  2. After successful login, click on [Application - Create App Integration] to create an application and select [SAML 2.0]

image.png

image1.png

  1. Fill in the App name and upload the App logo as needed.

image2.png

Setting Up Single Sign-On

  1. Return to the eSignGlobal portal, log in and install the [Single Sign-On SAML2.0 Protocol] plugin, then click on [Settings] in the top menu bar.

image3.png

  1. Click on [Single Sign-On] under the [Security] directory on the left.

image4.png

  1. Click on [Add Configuration], enter the [Service Provider Identity Identifier], and select [Single Sign-On Protocol] as SAML2.0.

image5.png

  1. After entering the information, the [Audience URL] (Service Provider Entity ID) and [ACS URL] will be automatically generated below. Click on the right side to copy them to the OKTA page.

image6.png

  1. Return to the OKTA page.

image7.png

Note:

The [Audience URL] (Service Provider Entity ID) in eSignGlobal corresponds to the [Audience URL(SP Entity ID)] in OKTA;

The [ACS URL] in eSignGlobal corresponds to the [Single sign-on URL] in OKTA.

  1. Next, check [This is an internal app that we have created] and click [Finish].

image8.png

  1. Download the XML file.

image9.png

  1. Open it with a browser and save it as an XML file.

image10.png

  1. Return to the eSignGlobal [Add Configuration] page, click on Upload the downloaded XML file.

image11.png

  1. After successful upload, the [Single Sign-On URL] and [Signature Certificate] will be automatically filled in. Click [Confirm] at this point.

image12.png

  1. The status will display [Enabled] when the SSO configuration is successful.

image13.png

Configuring User Access Permissions

  1. Click on [Assign Users to App].

image14.png

  1. Select the application and users, and click [Next].

image15.png

  1. Click on [Confirm Assignments] to confirm again.

image16.png

Verifying SSO

  1. On the eSignGlobal login page, select SSO login.

image17.png

  1. Enter the identifier of the workspace you belong to and click Login.

image18.png

  1. The page will redirect to the OKTA login.

  2. On the redirected page, enter your email and the verification code sent to your email, click [Submit] to log in to the eSignGlobal homepage.

image19.png

Note:

The email address used for SSO login cannot be used as the login account for the eSignGlobal platform.