Applies to:
- Plan -
- Deployment -
- SAML: Okta Workforce, Microsoft Entra ID, Google Workspace, or a custom SAML provider.
- OpenID Connect (OIDC): A custom OIDC provider.
Information to include
Include the IdP and protocol you will use, the email domain or domains to configure, and the protocol-specific details below.SAML connections
For a SAML connection, include whether you want to enable IdP-initiated login, such as launching Braintrust from an Okta tile. Braintrust support will provide connection-specific values for your SAML service provider (SP) configuration:- Single sign-on URL.
- Audience URI (SP Entity ID).
mail: The user’s primary email address.public_metadata_groups(optional): The SAML group value or values configured in your Braintrust domain mappings. Send each group as a separate attribute value, not a comma-separated string. Include this attribute only if a domain mapping also matches a SAML group value.
Okta Workforce
Provide the metadata URL. If it is unavailable, provide:- Identity Provider Single Sign-On URL.
- Identity Provider Issuer.
- The SSL/TLS certificate to use.
Microsoft Entra ID
Provide the metadata URL. If it is unavailable, provide:- Login URL.
- Microsoft Entra Identifier.
- The SSL/TLS certificate to use.
Google Workspace
Provide the metadata URL. If it is unavailable, provide:- SSO URL.
- Entity ID.
- The SSL/TLS certificate to use.
Custom SAML provider
Provide the metadata URL. If it is unavailable, provide:- SSO URL.
- Entity ID.
- The SSL/TLS certificate to use.
OIDC connections
For a custom OIDC provider, provide the discovery endpoint. If it is unavailable, provide:- Authorization URL.
- Token URL.
- User Info URL.
- The client ID.
- The client secret.
- Any scopes.