+++
title = "Okta Single Sign-On"
weight = 39
updated = 2023-06-15
aliases = ["/docs/okta-single-sign-on.html", "/docs/okta-single-sign-on", "/docs/account-and-organization-management/organization-account/enterprise/account-security/okta-single-sign-on/"]

[extra]
nav_title = "Okta Single Sign-On"
weight = 50
+++

You must have an Enterprise account to enable Okta Single Sign-On. Once enabled for your account, all users must login via Okta. This can be done from the login form with any password, or from the Okta End-User Dashboard.

To enable Okta you must:

1. Reach out to [support@bonsai.io](mailto:support@bonsai.io) and request Okta for your Bonsai account.
2. Navigate to your [account security page](https://app.bonsai.io/account/security) to find a form to enter your metadata from Okta. You will see a screen similar to this:

{{ image(src="646528ef3472e76e8c1e2820_6410dfbbb470a.png", alt="Bonsai account security page showing Okta metadata form", automatically_determine_ratio=true) }}

3. In Okta, select the Sign On tab for the Bonsai app:

{{ image(src="646528ef72e059f5fe1303c9_6410dfbc9cd2e.png", alt="Okta Bonsai application Sign On tab", automatically_determine_ratio=true) }}

4. Click on **View Setup Instructions** which will open a new page. Scroll to the bottom of the page to find and copy your IDP metadata.

{{ image(src="646528ef3c600b943ab21eac_6410dfbdaaea6.png", alt="Okta setup instructions page showing IDP metadata section", automatically_determine_ratio=true) }}

5. Paste the metadata into the form on the Bonsai [account security page](https://app.bonsai.io/account/security) and submit by clicking **Add Metadata**.
6. Now Log into Bonsai via the Okta End-User Dashboard and Bonsai will activate and require Okta for all users associated with your account.