Connect Okta to Cargo Marshal over SAML, verify your email domain, and let your team sign in with their Okta accounts.
Single sign-on (SSO) lets people with an email on your company domain sign in to Cargo Marshal through Okta. Their first sign-in adds them to your organization as members, as long as a seat is free.
Before you start
You need the Enterprise plan, the owner or admin role in your Cargo Marshal
organization, an Okta admin account, and access to your domain's DNS
settings.
In the Okta Admin Console, go to Applications → Applications → Create App Integration, choose SAML 2.0, and name the app "Cargo Marshal". On Configure SAML:
Single sign-on URL: the ACS URL from Cargo Marshal.
Audience URI (SP Entity ID): the Entity ID from Cargo Marshal.
Name ID format: EmailAddress.
Application username: Email.
Okta signs the assertion by default; keep it that way. Cargo Marshal rejects unsigned assertions.
Open the app's Sign On tab and view the SAML setup instructions. Copy the Identity Provider Single Sign-On URL, the Identity Provider Issuer, and the X.509 Certificate.
Back in Settings → Single sign-on, enter your email domain (for example acme.com), paste the three Okta values into IdP single sign-on URL, IdP entity ID (issuer), and IdP signing certificate, and click Connect.
Cargo Marshal shows a TXT record. Add it at your DNS provider, then click Verify domain. DNS changes can take a while to appear. Sign-in through SSO starts working once the domain is verified.
In Okta, assign the app to the people or groups who use Cargo Marshal. They sign in at the Cargo Marshal login page with Sign in with SSO and their work email.
Okta also supports OpenID Connect. To use it instead, select OpenID Connect in Cargo Marshal, create an OIDC web app in Okta with the Redirect URI as its sign-in redirect URI, and enter your Okta URL as the issuer with the app's client ID and client secret.
Once the domain is verified and you have signed in through SSO yourself, you can turn on Require SSO. Everyone on the domain is signed out, except you, and can then only sign in through Okta. If Okta is ever unavailable, see SSO break-glass access.
"Single sign-on isn't set up for this email domain": the domain is not verified yet, or the email is on a different domain.
"Your organization has no free seat": the plan's member limit is reached. Free a seat or invite the person, then sign in again. An invited person can always join.
"…an email outside your organization's verified domain": Okta sent a different email than the one on your domain. Check Application username and the Name ID format.