Skip to main content

Okta Single Sign-On (SSO) Setup Guide

The Okta SSO integration allows you to use Okta as your Single Sign-On (SSO) and Multi-Factor Authentication (MFA) provider for Kadence, adding an extra layer of security for your organisation.

Liza avatar
Written by Liza
Updated yesterday

Once configured, users can sign in to Kadence using their Okta credentials—without needing a separate password.


🛠️ Prerequisites

Before setting up Okta SSO, make sure that:

  • You have an active Okta licence

  • You are a Global Admin in Kadence

  • You have access to an Okta Admin account, or support from your Okta administrator

To log in via Okta SSO, users must have a Kadence account with the same email address as their Okta user account.


⚙️ Supported Features

The Kadence–Okta integration supports:

  • IdP-initiated SSO (users start in Okta)

  • SP-initiated SSO (users start on the Kadence login page)


🔧 Step 1: Add Kadence to Okta

  1. Log in to your Okta Admin Console

  2. Navigate to Applications → Applications

  3. Click Browse App Catalog

  4. Search for Kadence and select it

  5. Click Add integration

Configure the application

  • Enter a Kadence SSO Alias

    • Use lowercase letters and numbers only

    • Example: Company name “Bellyard Coffee”bellyard or bellyardcoffee

  • Optionally edit the application label

  • Click Done

📌 Keep a note of your SSO alias — you’ll need it later.


🔑 Step 2: Find Your Okta Client ID, Secret & Base URL

You’ll now collect the details required to complete setup in Kadence.

  1. While logged in to Okta, copy your Okta base URL

    • Example:

      • From: https://kadence-sso.okta.com/app/UserHome?fromAdmin=true

      • Use: https://kadence-sso.okta.com

  2. Go to Applications → Applications

  3. Select your Kadence application

  4. Open the Sign On tab

  5. Under Sign-on Methods → OpenID Connect, copy:

    • Client ID

    • Client Secret

💡 Store these values temporarily in a plain-text editor (e.g. Notepad).


🔒 Step 3: Enforce Single Sign-On (Optional)

To fully enforce SSO and prevent users from bypassing Okta by setting or resetting passwords, we strongly recommend blocking specific automated Kadence emails before or during rollout.

If you do not wish to enforce SSO and want your users to be able to login without SSO, skip to Step 4.


🛑 Block “Welcome to Kadence” Emails

When users are provisioned, Kadence may send a welcome email prompting them to set a password. Blocking this ensures users only access Kadence via SSO.

Block or filter emails from: [email protected]

Filter by subject line: Welcome to Kadence

Do not block all emails from this address. Other critical notifications (such as check-in reminders and booking confirmations) are also sent from this domain.


🔐 Block Password Reset Emails (SSO Recommended)

If your organisation uses Single Sign-On, blocking password reset emails prevents users from bypassing SSO authentication.

Block or filter emails from: [email protected]

Filter by subject line: Reset your password

Do not block all emails from this address. Blocking only this subject ensures SSO remains enforced while preserving essential notifications.


🔄 When should I apply these blocks?

We recommend applying these email filters:

  • Before enabling SSO, or

  • Before syncing users into Kadence, especially via Directory Sync

This ensures users only authenticate using Okta from day one.


🔗 Step 4: Enable Okta SSO in Kadence

Now connect Okta and Kadence.

  1. Log in to Kadence

  2. Navigate to Settings → Integrations

  3. Under Single Sign-On (SSO), select Okta

  4. Click Set up single sign-on

  5. Enter the following:

    • Client ID

    • Client Secret

    • Base URL (Okta sign-in URL)

    • Kadence SSO Alias

  6. Click Add

If successful, you’ll see a confirmation message at the top of the screen.


🔐 Step 5: Logging in with Okta SSO

Once Okta is integrated, users can log in by:

  1. Navigating to Kadence

  2. Clicking the Okta icon under the login form

  3. Entering their email address

  4. Authenticating via Okta

  5. Being redirected back to Kadence


🧯 Troubleshooting & Tips

  • User email addresses in Okta and Kadence must match exactly

  • You cannot enable Okta SSO if another SSO provider (e.g. OneLogin) is already configured

  • The Kadence SSO alias must be globally unique

    • If your first choice is taken, update it in Okta and re-enter it in Kadence


❓ FAQs

Can users still log in without Okta?

Once SSO is enforced, users must authenticate via Okta unless alternative login methods are allowed by your admin.

Can I manage or remove the Okta integration later?

Yes, Global Admins can update or remove the SSO integration from Settings → Integrations at any time.

Does Kadence support both IdP and SP initiated login?

Yes, users can start from either Okta or the Kadence login page.


💬 Need Help?

For support, reach out to:
📩 [email protected]

For more helpful articles see:
📚 Kadence Help Center

Did this answer your question?