SSO Setup Guide
Codd AI supports Single Sign-On (SSO) for enterprise customers, allowing your team to log in using their existing corporate credentials through identity providers like Okta. Once SSO is enabled, users on your email domain are automatically routed to your identity provider — no separate passwords needed.
Available on Enterprise plans. If you're interested in enabling SSO for your organization, contact the Codd AI team to get started.
How SSO Works
When SSO is enabled for your organization, the login experience changes as follows:
- 1
Enter Your Email
On the Codd AI login page, enter your corporate email address and click Continue.
- 2
Redirect to Your Identity Provider
Codd AI detects your email domain and redirects you to your organization's identity provider (e.g., Okta).
- 3
Authenticate
Log in with your corporate credentials (including MFA if your organization requires it). For security, Codd AI requires fresh authentication each time — you'll always see your identity provider's login page.
- 4
Access Codd AI
After successful authentication, you're redirected back to Codd AI and signed in automatically. First-time users are provisioned with a default role.
Prerequisites
Before setting up SSO, ensure you have the following:
- An active Codd AI Enterprise plan
- Administrator access to your identity provider (e.g., Okta Admin Console)
- Knowledge of your organization's email domain(s) that should use SSO
Step 1: Request SSO Enablement
Contact the Codd AI team to request SSO for your organization. You can reach us through:
- The Contact Support page
- Your account manager
- Email at support@codd.ai
Provide the following information:
| Information | Example |
|---|---|
| Organization name | Acme Corporation |
| Email domain(s) for SSO | acme.com, acme.co.uk |
| Identity provider | Okta, Azure AD, OneLogin, etc. |
| IT admin contact email | it-admin@acme.com |
The Codd AI team will provide you with the SAML configuration details needed to set up the connection on your side (see Step 2).
Step 2: Configure Your Identity Provider
After the Codd AI team processes your request, you'll receive SAML configuration details. Use these to create a SAML application in your identity provider.
Okta Configuration
Follow these steps in your Okta Admin Console:
2.1 Create a SAML Application
- Log in to your Okta Admin Console
- Navigate to Applications → Applications
- Click Create App Integration
- Select SAML 2.0 and click Next
- Enter Codd AI as the app name and click Next
2.2 Enter SAML Settings
Use the values provided by the Codd AI team:
| Field | Value |
|---|---|
| Single sign-on URL | Provided by Codd AI team |
| Audience URI (SP Entity ID) | Provided by Codd AI team |
| Name ID format | EmailAddress |
| Application username |
2.3 Enable Single Logout (Recommended)
Single Logout ensures that when a user logs out of Codd AI, their identity provider session is also terminated. This prevents session reuse across different users.
- In the SAML settings page, expand Show Advanced Settings
- Check Enable Single Logout
- Fill in the following fields (values provided by the Codd AI team):
Field Value Single Logout URL Provided by Codd AI team SP Issuer Provided by Codd AI team Signature Certificate Upload the certificate file provided by the Codd AI team
Note: The Codd AI team will provide the Single Logout URL, SP Issuer, and a signing certificate file during the setup process. If you don't have these values yet, contact the Codd AI team.
2.4 Configure Attribute Statements
Attribute statements ensure Codd AI receives user profile information correctly. The configuration differs slightly depending on your Okta version:
Okta Identity Engine (newer accounts)
After creating the app, go to the Sign On tab → Attributes Statements (SAML) section → click Add expression:
| Name | Expression |
|---|---|
| user.profile.email | |
| firstName | user.profile.firstName |
| lastName | user.profile.lastName |
Okta Classic Engine
In the SAML Settings step during app creation, scroll to Attribute Statements:
| Name | Name format | Value |
|---|---|---|
| Basic | user.email | |
| firstName | Basic | user.firstName |
| lastName | Basic | user.lastName |
2.5 Assign Users
- Go to the Assignments tab of the Codd AI app
- Click Assign → Assign to People or Assign to Groups
- Select the users or groups that should have access to Codd AI
- Click Save and Go Back, then Done
Note: Only users assigned to the Codd AI app in Okta will be able to log in via SSO. Users not assigned will see an error when attempting to authenticate.
2.6 Complete the Setup
- Click Next on the SAML settings page
- Select "I'm an Okta customer adding an internal app"
- Click Finish
Step 4: Test the Connection
Once the Codd AI team confirms the setup is complete, test the SSO connection:
- 1
Open Codd AI (https://trial.codd.ai) in a browser where you are not already logged in (or use an incognito window).
- 2
Enter your corporate email address on the login page and click Continue.
- 3
You should be redirected to your Okta login page. Sign in with your Okta credentials.
- 4
After successful authentication, you should land in Codd AI, signed in and ready to use.
Troubleshooting
If the connection doesn't work, verify:
- The Single sign-on URL and Audience URI in Okta match the values provided by the Codd AI team exactly
- Your user account is assigned to the Codd AI app in Okta
- The X.509 certificate has not expired
- Attribute statements are configured correctly
If issues persist, contact Codd AI support.
Step 5: Go Live
After successful testing, confirm with the Codd AI team that you're ready to go live. Once SSO is activated for your domain:
- All users with your email domain will be routed through your identity provider
- New users are automatically provisioned on first login with a default role
- Your IT admin manages user access through Okta — no separate invitation needed
Tip: To control who can access Codd AI, use Okta's group assignments. Only users (or groups) assigned to the Codd AI app in your Okta will be able to authenticate.
User Experience After SSO
For SSO Users
- Enter corporate email on login page
- Authenticate via your identity provider
- No separate password to remember
- MFA enforced by your organization's policies
For Non-SSO Users
- Enter email on login page
- Redirected to standard login (email + password)
- No change to existing login experience
Other Identity Providers
While this guide focuses on Okta, Codd AI supports SSO with any SAML 2.0 compatible identity provider, including:
Microsoft Entra ID (Azure AD)
Create an Enterprise Application with SAML SSO.
OneLogin
Add a SAML Custom Connector application.
Google Workspace
Configure a custom SAML app in the Admin Console.
Other SAML 2.0 Providers
Any provider that supports SAML 2.0 can be configured. Contact us for details.
The setup process is similar across all providers — create a SAML application, enter the configuration details provided by Codd AI, and share your metadata back with us.
Frequently Asked Questions
What happens when a new employee joins and needs access?
Simply assign them to the Codd AI app in your Okta Admin Console. When they log in to Codd AI for the first time, their account is automatically created.
What happens when an employee leaves?
Remove or deactivate the user in your Okta. They will no longer be able to authenticate to Codd AI. For immediate access revocation, also ask the Codd AI team or your organization admin to deactivate their Codd AI account.
Can some users use SSO while others use password login?
SSO is enabled per email domain. All users on an SSO-enabled domain are routed through the identity provider. Users on other domains continue to use standard email/password login.
What if our Okta is temporarily down?
If your identity provider is unavailable, users on your SSO domain will not be able to log in until it's restored. Users on non-SSO domains are unaffected. Okta uptime is managed by your IT team.
Can we have multiple email domains for SSO?
Yes. You can configure multiple email domains (e.g., acme.com and acme.co.uk) to route through the same identity provider. Let the Codd AI team know all applicable domains during setup.
Does logging out of Codd AI also log me out of Okta?
If Single Logout is configured (see Step 2.3), logging out of Codd AI will also end your identity provider session. This ensures the next person logging in on the same browser will need to enter their own credentials.
What role do new SSO users get?
New users provisioned through SSO are assigned a default "member" role. Organization admins in Codd AI can change user roles through the Organization Settings page.
Need Help?
If you have questions about SSO setup or run into any issues, our team is here to help.
Contact Support