How to set up Okta SAML with Role Mapping setup (with pictures)

:warning: Disclaimer:
This guide is not official documentation from Retool or Okta. It is a general reference based on what has worked with the current version of Okta's developer tools, and has been found helpful for many users. If you encounter issues or have specific questions related to Okta, we recommend contacting Okta Support for official assistance.

:scroll: General: The images below are meant to help supplement and visualize the setup process of what's already written in our Retool docs for setting up Okta SAML SSO: Configure Okta SAML SSO | Retool Docs

1. Create a SAML 2.0 app in Okta


2. Name your SAML app

3. Enter details for your:

  • Single sign-on URL
  • Audience URI
  • Attribute Statements

4. Click 'Finish'

Connecting Okta to Retool:

5. Grab your IdP metadata

6. Your IdP metadata should look something like this:

7. Insert this into Retool: Settings > SSO > SAML

Setting up Role Mapping:
1. Create a Group:

2. Assign your Okta Application to your User

3. Confirm the Assignment to the User

4. Assign your Okta Application to your Group

5. Set your Okta Application's Group Attribute with your Group Name

6. Set the Group mapping in Retool to match your Groups in Retool