---
title: "How to set up Okta SAML SSO for Chili Piper"
source_url: https://help.chilipiper.com/hc/en-us/articles/34533166129299-How-to-set-up-Okta-SAML-SSO-for-Chili-Piper
article_id: 34533166129299
updated_at: 2026-07-24T18:55:57Z
content_hash: b0152ab8
---

## Who can use this feature?

Available on All Products

Available to Only Admins

[Billing Center](https://fire.chilipiper.com/fire/admin/billing/overview) [Get a Demo](https://www.chilipiper.com/request-demo?utm_source=zendesk&utm_medium=help-center&utm_campaign=chili-hub)

In this article, we will walk through the required steps to integrate Okta SAML SSO with Chili Piper.

- You must be a Chili Piper admin to enable Single Sign-On (SSO).

- You must use the same email address for both Chili Piper and Okta.

- This feature is currently in the Beta version.

- This article is dedicated to Chili Piper users who have already been upgraded to the Demand Conversion Platform. If you are still a Legacy user, [check this article](https://help.chilipiper.com/hc/en-us/articles/5330428625171-How-to-set-up-SSO-for-Chili-Piper) instead.

- You can find Chili Piper on Okta's Integrations page for more details [here](https://www.okta.com/integrations/chili-piper/).

⚠️ **Changing an SSO user's email? Read this first.**

If your organization signs in to Chili Piper with SSO/SAML, do not change a user's email by simply signing in with the new address. Chili Piper currently matches SSO users by their email address, so renaming a user in your identity provider can create a new, empty Chili Piper account and leave the original account's meetings, calendar connection, and routing behind.

Before renaming a user in your identity provider, contact your Customer Success Manager or [support@chilipiper.com](mailto:support@chilipiper.com), so we can help you with the process.

## How to configure Okta SAML SSO

Before configuring Okta in Chili Piper itself, you must add Chili Piper as an app in Okta:

- Select **Add Application**.

- Select **Browse App Catalog**.

- Search for the Chili Piper application.

- Select the **Add button** for the Chili Piper application.

- In **General Settings** select the appropriate values for:

**Application Visibility**: If you want to temporarily hide the app while configuring, select the check box next to _**Do not display application**_****icon to users. (You will need to change this after configuration to make the app visible to your users.)

- Browser plugin auto-submit

- In **SAML Settings**, ensure the **Attribute Statements** include the following entries:

_Name: firstName_| _Value: user.firstName_

- _Name: lastName_|_Value: user.lastName_

- _Name: email_|_Value: user.email_![](/attachments/token/VW5QGfJWnHnOZ777BJBaRHQc5/?name=image.png)

- Select **Next**.

- Under **Sign On Methods**, select **SAML 2.0**.

- Select **View Setup Instructions**

- Leave this tab open and proceed to the Chili Piper app to complete setup.

## Integrating Okta SAML SSO in Chili Piper

- Access Okta SAML Configuration by clicking Integrations in the right-side menu and click the Security tab. Then, click Connect on the Okta card.![](https://help.chilipiper.com/hc/article_attachments/34961917672979)

- Copy and Paste the **Default ACS URL** and the Entity ID from Chili Piper into Okta. **These URLS cannot be edited in anyway or they will not work.**Once done, click **Confirm Posting on Identity Provider**
****

- Copy and Paste **Metadata URL** (located under the Sign-On tab) from Okta into **Chili Piper & Test Connection**![](https://help.chilipiper.com/hc/article_attachments/34961913055123)

- Paste it to the **Metadata URL field** in Chili Piper in Step 2 section of the Okta setup.![](https://help.chilipiper.com/hc/article_attachments/34962976498707)

- Click **Test Connection** and you will be directed to the Okta login screen. You **must** log into Okta using the **same credentials** that you are logged into Chili Piper.![](https://help.chilipiper.com/hc/article_attachments/34961917682963)If the Connection is successful, you will be redirected back to Chili Piper to enforce SSO for all users.

- Optionally, if you’d like to enforce your users only logging in via Okta, you can opt to do this now. **This option will only be available if testing the connection in Step 2 was successful**.![](https://help.chilipiper.com/hc/article_attachments/34961917687955)

## Okta SAML SSO Features

- SP login flow (Service-provider Initiated)Users can log in via fire.chiliipiper.com, and your Identity provider will authenticate the user.

- Identity Provider Initiated SSO (IdP-initiated)
Users can log in to their identity provider and select the Chili Piper app.

- Only available if your identity provider supports a Default Relay State.

- JIT provisioning is **not** supported.

## Things to Know

- **Renaming a user / changing a user's email:** Chili Piper currently matches users by email address, so renaming a user's email in your identity provider will create a new Chili Piper account and orphan the old one (along with its meetings, calendar connection, and routing). Contact your Customer Success Manager or [support@chilipiper.com](mailto:support@chilipiper.com) before renaming an SSO user.

- SAML Attributes include:

**firstName**: user.firstName

- **lastName**: user.lastName

- **email**: user.email
