Manage secure access with Okta

Databases
Identity and access management
Overview

The Jet Admin Okta integration lets your app authenticate users against your organization's Okta directory, driven by the same roles and permissions you already manage in Jet. Whether an employee opens the app for the first time, a group membership changes, or an account needs to be cut off, the whole sign-in flow runs through Okta, and access stays in sync with your directory.

That covers what teams build with Okta first: internal tools that inherit single sign-on rather than a separate password, and access reviews that stay accurate because they run off the same directory IT already maintains. Because Jet maps Okta groups to app roles, a person's permissions update automatically as their group membership changes, and removing them from Okta removes their access everywhere at once.

What you can do
Configure SSO sign-in
Let users sign in to your Jet app with their existing Okta account instead of a separate password.
Map roles from Okta groups
Assign a user's role and permissions in your app automatically based on the Okta groups they belong to.
Sync user profile on login
Pull name, email and other profile fields from Okta into your app's user record the moment someone signs in.
Restrict access by domain
Limit sign-in to accounts from your organization's Okta directory, so no outside account can reach the app.
Use Cases
Scenario
What it looks like
Enterprise SSO rollout
Give employees one-click access to an internal tool through the same Okta login they use for everything else.
Automatic role provisioning
Grant the right permissions the moment someone signs in, based on their Okta group, with no manual account setup.
Centralized access control
Let IT revoke a person's access to every internal app at once by removing them from Okta, instead of app by app.

Key benefits

  • One login for everything. Employees use the same Okta account for your Jet app as for every other company tool.
  • Automatic role sync. Permissions update the moment someone's Okta group changes, with no manual account edits.
  • Centralized offboarding. Removing someone from Okta removes their access to the app immediately.
  • Fewer passwords, less risk. No separate password to phish, forget or reuse.
  • Audit-ready access. Who has access is always exactly who your directory says should.

How to connect Jet Admin with Okta

  1. In Okta, create a new application integration and choose OIDC or SAML.
  2. In Jet Admin, open your app's authentication settings and choose Okta as the sign-in method.
  3. Enter the client ID, client secret and Okta domain from your Okta application.
  4. Map the Okta groups you want to use to roles inside your Jet app.
  5. Test sign-in with a user in each group to confirm roles apply correctly.
  6. Roll out the login link to your team, and turn off the built-in password login if you want Okta as the only path in.