Okta: Set Up FileCloud Integration for SSO Group/User Import
To configure FileCloud/Okta integration in Okta for SSO group/user import:
- Log in to the Okta admin portal, and navigate to Applications > Applications.
- Click Create App Integration.

A list of sign-in methods opens. - Choose API Services, and click Next.

- Enter a name for the app integration and click Save.

- Your new app opens to the General tab. Click Edit.

- For Client authentication, select Public key / Private key.
- For Configuration, choose Save keys in Okta.
- Click Add key.

The Add a public key window opens. - Paste in your own key or click Generate new key.
- If you click Generate new key, under Private key - Copy this! click PEM, and then click Copy to clipboard, and save the copied key to a text file with a .pem extension so you can upload it to FileCloud.
If you do not save as a .pem file, you will not be able to upload the private key to FileCloud.
- Click Done.
- Click Save, or your public key will not be saved.

Once you click Save, your key should show a Status of Active and a Created date.
- Remain on the General tab. Scroll down to General Settings, and click Edit.

- Uncheck Proof of possession, and click Save.

Click the Okta API Scopes tab.
- Scroll down to okta.groups.read and click Grant to enable FileCloud to read Okta groups.

You are prompted to grant okta.groups.read scope to the app. - Click Grant Access.

Now the row for okta.groups.read should appear as:
- Scroll down to okta.users.read and click Grant Access to enable FileCloud to read Okta users.
The Grant Okta API Scope notification does not appear again.
- Click the Admin roles tab.
- Click Edit assignments.

- In Role, choose a role that should have access to Okta groups and users, or choose Read-only Administrator.
- Click Save Changes.

You have finished setting up integration on the Okta side.
Now you have the values you need to set up integration on the FileCloud side: the domain in the user drop-down box, the Client ID on the General tab, and the .pem keyfile that you saved.
To enter the values into the FileCloud side, see SSO API: Configure Import of SSO Groups and Users.