SSO Setup Guide

Codd AI supports Single Sign-On (SSO) for enterprise customers, allowing your team to log in using their existing corporate credentials through identity providers like Okta. Once SSO is enabled, users on your email domain are automatically routed to your identity provider — no separate passwords needed.

Available on Enterprise plans. If you're interested in enabling SSO for your organization, contact the Codd AI team to get started.

How SSO Works

When SSO is enabled for your organization, the login experience changes as follows:

  1. 1

    Enter Your Email

    On the Codd AI login page, enter your corporate email address and click Continue.

  2. 2

    Redirect to Your Identity Provider

    Codd AI detects your email domain and redirects you to your organization's identity provider (e.g., Okta).

  3. 3

    Authenticate

    Log in with your corporate credentials (including MFA if your organization requires it). For security, Codd AI requires fresh authentication each time — you'll always see your identity provider's login page.

  4. 4

    Access Codd AI

    After successful authentication, you're redirected back to Codd AI and signed in automatically. First-time users are provisioned with a default role.

Prerequisites

Before setting up SSO, ensure you have the following:

  • An active Codd AI Enterprise plan
  • Administrator access to your identity provider (e.g., Okta Admin Console)
  • Knowledge of your organization's email domain(s) that should use SSO

Step 1: Request SSO Enablement

Contact the Codd AI team to request SSO for your organization. You can reach us through:

Provide the following information:

InformationExample
Organization nameAcme Corporation
Email domain(s) for SSOacme.com, acme.co.uk
Identity providerOkta, Azure AD, OneLogin, etc.
IT admin contact emailit-admin@acme.com

The Codd AI team will provide you with the SAML configuration details needed to set up the connection on your side (see Step 2).

Step 2: Configure Your Identity Provider

After the Codd AI team processes your request, you'll receive SAML configuration details. Use these to create a SAML application in your identity provider.

Okta Configuration

Follow these steps in your Okta Admin Console:

2.1 Create a SAML Application

  1. Log in to your Okta Admin Console
  2. Navigate to ApplicationsApplications
  3. Click Create App Integration
  4. Select SAML 2.0 and click Next
  5. Enter Codd AI as the app name and click Next

2.2 Enter SAML Settings

Use the values provided by the Codd AI team:

FieldValue
Single sign-on URLProvided by Codd AI team
Audience URI (SP Entity ID)Provided by Codd AI team
Name ID formatEmailAddress
Application usernameEmail

2.3 Enable Single Logout (Recommended)

Single Logout ensures that when a user logs out of Codd AI, their identity provider session is also terminated. This prevents session reuse across different users.

  1. In the SAML settings page, expand Show Advanced Settings
  2. Check Enable Single Logout
  3. Fill in the following fields (values provided by the Codd AI team):
    FieldValue
    Single Logout URLProvided by Codd AI team
    SP IssuerProvided by Codd AI team
    Signature CertificateUpload the certificate file provided by the Codd AI team

Note: The Codd AI team will provide the Single Logout URL, SP Issuer, and a signing certificate file during the setup process. If you don't have these values yet, contact the Codd AI team.

2.4 Configure Attribute Statements

Attribute statements ensure Codd AI receives user profile information correctly. The configuration differs slightly depending on your Okta version:

Okta Identity Engine (newer accounts)

After creating the app, go to the Sign On tab → Attributes Statements (SAML) section → click Add expression:

NameExpression
emailuser.profile.email
firstNameuser.profile.firstName
lastNameuser.profile.lastName
Okta Classic Engine

In the SAML Settings step during app creation, scroll to Attribute Statements:

NameName formatValue
emailBasicuser.email
firstNameBasicuser.firstName
lastNameBasicuser.lastName

2.5 Assign Users

  1. Go to the Assignments tab of the Codd AI app
  2. Click AssignAssign to People or Assign to Groups
  3. Select the users or groups that should have access to Codd AI
  4. Click Save and Go Back, then Done

Note: Only users assigned to the Codd AI app in Okta will be able to log in via SSO. Users not assigned will see an error when attempting to authenticate.

2.6 Complete the Setup

  1. Click Next on the SAML settings page
  2. Select "I'm an Okta customer adding an internal app"
  3. Click Finish

Step 3: Share Your Metadata with Codd AI

After creating the SAML app, share the following information with the Codd AI team:

ItemWhere to Find It
IdP Metadata URLSign On tab → SAML Signing Certificates → Actions → View IdP metadata
Sign-On URL (SSO URL)Sign On tab → under SAML settings
X.509 CertificateSign On tab → SAML Signing Certificates → Actions → Download certificate
Single Logout URLSign On tab → View SAML setup instructions → Identity Provider Single Logout URL

Send these details to the Codd AI team via email or your support channel. The team will finalize the connection on our side.

Step 4: Test the Connection

Once the Codd AI team confirms the setup is complete, test the SSO connection:

  1. 1

    Open Codd AI (https://trial.codd.ai) in a browser where you are not already logged in (or use an incognito window).

  2. 2

    Enter your corporate email address on the login page and click Continue.

  3. 3

    You should be redirected to your Okta login page. Sign in with your Okta credentials.

  4. 4

    After successful authentication, you should land in Codd AI, signed in and ready to use.

Troubleshooting

If the connection doesn't work, verify:

  • The Single sign-on URL and Audience URI in Okta match the values provided by the Codd AI team exactly
  • Your user account is assigned to the Codd AI app in Okta
  • The X.509 certificate has not expired
  • Attribute statements are configured correctly

If issues persist, contact Codd AI support.

Step 5: Go Live

After successful testing, confirm with the Codd AI team that you're ready to go live. Once SSO is activated for your domain:

  • All users with your email domain will be routed through your identity provider
  • New users are automatically provisioned on first login with a default role
  • Your IT admin manages user access through Okta — no separate invitation needed

Tip: To control who can access Codd AI, use Okta's group assignments. Only users (or groups) assigned to the Codd AI app in your Okta will be able to authenticate.

User Experience After SSO

For SSO Users

  • Enter corporate email on login page
  • Authenticate via your identity provider
  • No separate password to remember
  • MFA enforced by your organization's policies

For Non-SSO Users

  • Enter email on login page
  • Redirected to standard login (email + password)
  • No change to existing login experience

Other Identity Providers

While this guide focuses on Okta, Codd AI supports SSO with any SAML 2.0 compatible identity provider, including:

Microsoft Entra ID (Azure AD)

Create an Enterprise Application with SAML SSO.

OneLogin

Add a SAML Custom Connector application.

Google Workspace

Configure a custom SAML app in the Admin Console.

Other SAML 2.0 Providers

Any provider that supports SAML 2.0 can be configured. Contact us for details.

The setup process is similar across all providers — create a SAML application, enter the configuration details provided by Codd AI, and share your metadata back with us.

Frequently Asked Questions

What happens when a new employee joins and needs access?

Simply assign them to the Codd AI app in your Okta Admin Console. When they log in to Codd AI for the first time, their account is automatically created.

What happens when an employee leaves?

Remove or deactivate the user in your Okta. They will no longer be able to authenticate to Codd AI. For immediate access revocation, also ask the Codd AI team or your organization admin to deactivate their Codd AI account.

Can some users use SSO while others use password login?

SSO is enabled per email domain. All users on an SSO-enabled domain are routed through the identity provider. Users on other domains continue to use standard email/password login.

What if our Okta is temporarily down?

If your identity provider is unavailable, users on your SSO domain will not be able to log in until it's restored. Users on non-SSO domains are unaffected. Okta uptime is managed by your IT team.

Can we have multiple email domains for SSO?

Yes. You can configure multiple email domains (e.g., acme.com and acme.co.uk) to route through the same identity provider. Let the Codd AI team know all applicable domains during setup.

Does logging out of Codd AI also log me out of Okta?

If Single Logout is configured (see Step 2.3), logging out of Codd AI will also end your identity provider session. This ensures the next person logging in on the same browser will need to enter their own credentials.

What role do new SSO users get?

New users provisioned through SSO are assigned a default "member" role. Organization admins in Codd AI can change user roles through the Organization Settings page.

Need Help?

If you have questions about SSO setup or run into any issues, our team is here to help.

Contact Support