LASSO supports Single Sign-On (SSO) using SAML. Okta is a popular Identity Provider among our customers. This article describes how to integrate LASSO as a SAML application in Okta.
Before you start
SSO is available for admins in your LASSO account only. It is not available for crew who use the LASSO mobile application.
Setup happens in two passes: you first create the app in Okta with placeholder URLs and send LASSO your metadata; LASSO then returns the real URLs, which you enter to finish. You'll follow the steps below in order.
Part 1: Create the LASSO application in Okta
Step 1: Open the Applications page and create an app integration
In Okta, open the Applications page.
Click Create App Integration.
Step 2: Choose SAML 2.0
Select SAML 2.0, then click Next. 
Step 3: General settings
Name the application (for example, YOUR_COMPANY SSO). Optionally, give the application a logo using the upload button.
Use the upload icon to add your logo 
Click Next. 
Step 4: Configure the initial SAML settings (URLs)
The Okta app needs placeholder values for Single sign on URL and Audience URI (SP Entity ID). LASSO will provide the correct URLs later — your LASSO URL is acceptable as a placeholder for now.
Pictured are example values for the SmokeTest LASSO Account
Step 5: Set Name ID and Username
LASSO recognizes users by email address. In the same section:
Name ID format:
EmailAddressApplication username:
Email
Step 6: Add SAML attribute statements
LASSO requires three attribute statements:
Name | Value |
|
|
|
|
|
|
Scroll to the bottom of the page and click Next.
Step 7: Finalize the app (Feedback settings)
On the feedback screen, choose:
I'm an Okta customer adding an internal app
It's required to contact the vendor to enable SAML
Scroll to the bottom of the page and click Finish.
Part 2: Send your Okta SAML information to LASSO
From the new Okta app, open the Sign On tab.
Scroll down to the SAML Signing Certificates section.
Click the Actions dropdown for the SHA-2 certificate and select View IdP metadata.
Copy the URL from the newly opened browser tab and email it to [email protected].
Part 3: Receive your LASSO SAML links
LASSO will enable SAML for your account and provide you with two URLs:
SAML Single Sign on URL
SAML Metadata URL (Audience URL)
Part 4: Update the LASSO application in Okta
Now replace the placeholder URLs with the real ones LASSO provided.
Open the Okta app and click the General tab.
In the SAML Settings section, click Edit.
Click Next to advance to the SAML configuration.
Enter the newly provided URLs:
Single sign on URL → the SAML Single Sign on URL from LASSO
Audience URI (SP Entity ID) → the SAML Metadata URL (Audience URL) from LASSO
Click Next, then click Finish.
Note: SSO can only be set up for admins in your LASSO account — it is not available for crew who use the LASSO mobile application. For each user who needs SSO access, notify LASSO support and we will configure that user on your account.
Need help?
If you have any questions during setup, contact [email protected].













