Skip to content

docs: Okta SSO setup is self-service in the dashboard - #1027

Merged
emrcbrn merged 1 commit into
netbirdio:mainfrom
emrcbrn:docs/okta-sso-self-service
Oct 8, 2026
Merged

emrcbrn merged 1 commit into
netbirdio:mainfrom
emrcbrn:docs/okta-sso-self-service

Conversation

@emrcbrn

@emrcbrn emrcbrn commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The Okta page told readers to email their Okta Client ID, Client Secret and domains to NetBird support. That's no longer how it works. SSO is self-service: Integrations > Single Sign-On > Connect Okta opens a wizard that takes those values directly.

Changes

  • Entry point: starts from the Single Sign-On tab, not the Identity Provider Sync page. The button names match the wizard: Get Started →, Continue →, Connect.
  • Configuring SSO in Okta: the "send an email to the NetBird team" step is replaced with the four form fields: Client ID, Client Secret, Okta account domain and Primary E-Mail Domain. The page now also tells readers not to share the Client Secret by email or chat.
  • Domain verification: after Connect, the dashboard can show Verify Domain Ownership. The page documents the nb-verification= TXT record, Verify Later, retrying from Settings > Domains, and the email-from-the-domain fallback. The wording is conditional ("If your primary email domain isn't verified yet…"), matching the dashboard, which only opens the dialog when the domain isn't verified.
  • Screenshots: the outdated screenshot (it showed the SCIM wizard, not SSO) is replaced with a single screenshot of the Enter your Okta details form. Everything else is described in text.
  • Small fixes: the app.netbird.io link was missing its scheme, and "log in using Okta Verify" becomes "log in with your Okta account".

The #configuring-sso-in-okta heading is unchanged, because the dashboard's "Learn more" link points at it.

Verification

  • Every step was checked against the dashboard source on main: src/modules/integrations/sso/okta/OktaSSOSetup.tsx, src/modules/integrations/sso/DomainVerificationModal.tsx and src/modules/integrations/sso/okta/OktaSSOSettings.tsx.
  • npm run lint:mdx and npm run build pass. The page was also reviewed on the local dev server.
  • Not tested end to end: the backend side of TXT verification lives in the Cloud service and isn't visible from the open source repos.

Other SSO pages (Cognito, Zoho, Zitadel, Keycloak, Authentik, cidaas, Duo, IIJ) still say to email support. That's still correct: Okta is the only provider with a self-service card on the Single Sign-On tab.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Documentation
    • Updated Okta SSO setup instructions to use the guided connection wizard, including app installation, credential entry, and domain ownership verification.
    • Added a reminder to protect the client secret like a password.

The Okta page told readers to email their Client ID, Client Secret and
domains to NetBird support. SSO is now set up in Integrations >
Single Sign-On > Connect Okta, where the wizard takes those values
directly and then asks for domain ownership verification if needed.

- Point the entry path at the Single Sign-On tab and the wizard's
  Get Started / Continue / Connect steps
- Replace the email step with the form fields and the Verify Domain
  Ownership flow (TXT record, Verify Later, email fallback)
- Replace the outdated SCIM-wizard screenshot with one of the
  Enter your Okta details form
- Fix the app.netbird.io link and drop the Okta Verify reference

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vercel

vercel Bot commented Oct 8, 2026

Copy link
Copy Markdown

@emrcbrn is attempting to deploy a commit to the NetBird GmbH Team on Vercel.

A member of the Team first needs to authorize it.

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: f691ad04-0d0a-45e2-812c-ebced8abd319
📥 Commits

Reviewing files that changed from the base of the PR and between c8cc844 and fa85aa6.

⛔ Files ignored due to path filters (2)
  • public/docs-static/img/manage/team/idp-sync/okta-sync/nwutb3Z.png is excluded by !**/*.png
  • public/docs-static/img/manage/team/idp-sync/okta-sync/okta-sso-enter-details.png is excluded by !**/*.png
📒 Files selected for processing (1)
  • src/pages/manage/team/idp-sync/okta-sync.mdx

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The Okta SSO instructions now guide readers through the Single Sign-On wizard, credential entry, and domain ownership verification. They replace instructions to email credentials for manual enablement.

Changes

Okta SSO guide

Layer / File(s) Summary
Open the SSO wizard
src/pages/manage/team/idp-sync/okta-sync.mdx
The guide directs readers to the Single Sign-On tab, the wizard, and its application installation steps.
Enter credentials and verify the domain
src/pages/manage/team/idp-sync/okta-sync.mdx
The guide explains how to enter Okta credentials in the wizard, protect the client secret, and verify domain ownership by DNS TXT record or email.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Other

Suggested reviewers: techhuttv

Merge Risk: ⚪ Minimal · up to fa85a

The guide now directs Okta administrators through dashboard-based SSO setup instead of emailing credentials. No specific mismatch or merge-blocking risk is established.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: moving Okta SSO setup to a self-service dashboard flow.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Warning

Some tools did not complete. Review the errors below.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

src/pages/manage/team/idp-sync/okta-sync.mdx

typescript-eslint does not support TS 7.0.
Please see https://devblogs.microsoft.com/typescript/announcing-typescript-7-0/#running-side-by-side-with-typescript-6.0 to run typescript-eslint using the TS 6 API.
See also typescript-eslint/typescript-eslint#10940 for tracking typescript-eslint's support for TS >=7.1

Oops! Something went wrong! :(

ESLint: 9.39.5

Error: typescript-eslint does not support TS 7.0.
at Object. (/.eslint-tmp/node_modules/typescript-eslint/dist/index.js:52:11)
at Module._compile (node:internal/modules/cjs/loader:1830:14)
at Object..js (node:internal/modules/cjs/loader:1961:10)
at Module.load (node:internal/modules/cjs/loader:1553:32)
at Module._load (node:internal/modules/cjs/loader:1355:12)
at wrapModuleLoad (node:internal/modules/cjs/loader:255:19)
at Module.require (node:internal/modules/cjs/loader:1576:12)
at require (node:internal/modules/helpers:153:16)
at Object. (/.eslint-tmp/node_modules/eslint-config-next/dist/index.js:5:64)
at Module._compile (node:internal/modules/cjs/loader:1830:14)


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit reads the wizard with care,
Then finds where Okta credentials go.
The secret stays guarded like a password,
A TXT record helps domain proof show.
The setup guide points the way,
And hops along to SSO's finish.

Comment @coderabbitai help to get the list of available commands.

@vercel

vercel Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
docs Ready Ready Preview Oct 8, 2026 11:39am UTC

Request Review

@emrcbrn
emrcbrn merged commit ad136b2 into netbirdio:main Oct 8, 2026
4 of 5 checks passed
@emrcbrn
emrcbrn deleted the docs/okta-sso-self-service branch October 8, 2026 11:38

This branch was successfully deployed

1 active deployment
Preview — fa85aa67 Deployed Oct 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants