SSO Setup Process (Keen Platform)
SSO Setup Process (Keen Platform)
Overview
This document outlines the step-by-step process followed to configure Single Sign-On (SSO) for a client using Okta and WorkOS, including internal coordination, client requirements, setup steps, troubleshooting, and validation.
1. Initial Request & Communication
Client submits a request for SSO Setup.
Account Director (AD) creates a KPS ticket.
Communication is primarily handled within the KPS ticket unless escalation is needed.
Keen Product Support team manages communication and updates.
Optional: Client can be added directly to the KPS ticket for transparency.
2. Required Information from Client
The support ticket must include:
Client Domain(s): (e.g., @keends.com, @company.com)
Timing Requirement: Minimum one-week notice before desired go-live date
Client IT Contact Info:
Must be an admin of the client’s Identity Provider (IdP)
3. Internal Setup Responsibilities
Product Support Manager + Infrastructure Lead
The Infra Lead will add client domain(s) to WorkOS
The Infra Lead will Generate and send SSO setup link to client IT admin
AD will then create a client admin user within the Keen Platform
4. SSO Configuration Details (Provided to Client)
WorkOS SAML Configuration
Single Sign-On (ACS) URL:
https://auth.workos.com/sso/saml/acs/kS937HMjrBAhDG8CFDm31ji8qAudience URI (SP Entity ID):
kS937HMjrBAhDG8CFDm31ji8qMetadata URL (Optional):
https://auth.workos.com/sso/saml/kS937HMjrBAhDG8CFDm31ji8q/metadata.xml
5. SSO Setup Instructions (Client-Side)
Step 1: Create App
In application IE: Okta Navigate to: Applications > Create App Integration
Select: SAML 2.0
Step 2: General Settings
Name the app (e.g., "[Client Name] SSO")
Step 3: SAML Settings
Paste:
ACS URL
Audience URI
Step 4: Assignments
Assign users or groups to the application
If not assigned, users cannot log in
Step 5: Feedback
Select: "I'm an Okta customer adding an internal app"
Click Finish
6. Required Information from Client After Setup
Client must provide ONE of the following:
Preferred
IdP Metadata URL
Alternative Options
Metadata XML file
Manual values:
IdP Entity ID
SSO URL
X.509 Certificate
7. Connection Activation
Once metadata is received Infrastructure team will:
Link the connection in WorkOS
Activate SSO connection
Status remains inactive until client completes setup and final import is done
8. SAML Attribute Statements
If an issue occurs with the SSO Login ensure that the client has updated Okta SAML Attribute Statements:
email → user.email
firstName → user.firstName
lastName → user.lastName
9. Additional Client Questions
Q: Can Keen enforce SSO-only logins?
Answer: Yes, this is supported
10. Validation & Final Steps
Confirm SSO login works successfully
Ask client to test authentication flow
Monitor logs for errors
Offer support call if needed
Closure Process
11. Final Outcome (Case Summary)
Client completed setup
Metadata provided and integrated
Attribute mappings corrected
SSO login successfully validated
Implementation marked as complete
Notes
Always ensure attribute mappings include email for domain validation
Early coordination with client IT reduces delays
Encourage metadata URL usage for easier integration