Setting up Okta SSO | businesscards.io

Setting up Okta SSO

Okta SSO is available on the Pro plan and above. Once configured, your team members sign in to businesscards.io with their Okta account (the same account they use for everything else at work). No separate password to manage.

This setup uses SAML 2.0. You'll be moving between Okta's admin console and your businesscards.io team settings, so have both open in different tabs.

What you need

  • Okta admin rights at your company.
  • You're a team owner on businesscards.io.
  • The team is on a Pro plan (or Enterprise).

Step 1: Add the SAML app in Okta

  1. Sign in to the Okta admin console.
  2. Go to Applications → Applications.
  3. Click Create App Integration.
  4. Pick SAML 2.0 and click Next.
  5. Name the app (e.g. "businesscards.io") and pick a logo if you want. Click Next.
  6. You're now on the SAML settings page. Fill in:
    • Single sign-on URL: the ACS URL we provide on the businesscards.io SSO config page.
    • Audience URI (SP Entity ID): the entity ID we provide.
    • Name ID format: EmailAddress.
    • Application username: Email.
  7. Click Next and finish the wizard.

Step 2: Grab the Okta metadata

On the app's page in Okta, open the Sign On tab. Find the link to view the SAML metadata (or the IdP metadata XML). Either copy the XML or note the metadata URL.

Step 3: Plug Okta into businesscards.io

  1. Sign in to businesscards.io and open Settings → SSO on your team.
  2. Paste the Okta metadata XML (or paste the metadata URL).
  3. Save.
  4. Test by signing out and signing in via the SSO option. Use a test user first, not your owner account, in case anything is misconfigured.

Step 4: Assign users in Okta

In Okta, open the businesscards.io app's Assignments tab and assign the users or groups who should have access. Anyone you don't assign in Okta can't sign in via SSO.

Troubleshooting

  • "User not found" on first sign-in: the user's Okta email doesn't match a businesscards.io account. Either invite them first to the team or enable just-in-time provisioning (if you've configured it).
  • SAML response errors: double-check the ACS URL and Entity ID are exactly what businesscards.io shows. Trailing slashes and case matter.
  • Account locked out: keep one team owner with a password login enabled so you can always get in even if SSO breaks.

Need help? Email support@businesscards.io with the team name and a screenshot of any error.

Want to learn more about this feature? SSO →