Okta is a 3rd party authentication service that centralizes how your employees have access to and authenticate with applications. This article outlines how to set up SAML-based Single Sign-On for Ramp using Okta as your Identity Provider. We currently support SP initiated SSO.
Important Note: Enabling Okta SSO will require all of your users to both accept invitations and sign in via Okta SSO. Users cannot sign in or accept invites via Ramp's regular login if Okta SSO is enabled.
- Turn on Okta on Ramp
- Install Ramp application on Okta
- Assign Ramp access to people in your organization in Okta
#1 Turn on Okta on Ramp
- Go to the “Settings” menu on your Ramp dashboard.
- Select “Company Settings” in the menu.
- Scroll down and select "Enable Okta Single Sign-On".
- Follow the instructions in the onboarding flow.
#2 Install Ramp application on Okta
- In Okta Admin, select Applications then Add Application.
- Search for “Ramp” and Select Add.
- Select the Ramp app and go to the "Sign On" tab.
- Right click the link for Identity Provider Metadata and select Copy Address.
- Paste the Identity Provider Metadata address in Okta setup on the Ramp Dashboard. (Settings → Company Settings → Enable Okta)
- To enable Okta Single Sign-On for everyone in your organization make sure they are all are added on the Okta Admin Dashboard
#3 Assign Ramp access to people in your organization in Okta
Option 1: Enable Okta for everyone in your organization
- Make sure everyone you want is first added to Okta itself (Directory → People → Add Person)
- Select "Assign" and then "Assign to Groups" in dropdown.
- Click "Assign" on Everyone to enable Ramp for all users in your Okta org.
*This does not automatically give people access to Ramp and spend on it. Everyone still needs to be individually invited.
Option 2: Enable Okta for specific people in your organization
- Make sure everyone you want is first added to Okta itself.
- (Directory → People → Add Person)
- Select "Assign" and then "Assign to People" in dropdown.
- Click "Assign" on specific people to enable Ramp through Okta for them.
*This does not automatically give them access to Ramp and spend on it. Everyone still needs to be individually invited.
Trouble signing in
- Your business might not have enabled Okta SSO with Ramp. Double check with an Admin to configure Okta on Ramp.
- Your account may not have been added on Okta. Ask an Okta Admin to enable your email address for Ramp on Okta.
- Are pop-ups enabled in your browser? If not, you will run into the following error message "The email address you submitted is not configured to use Okta SSO."
- Make sure you are signing in through Ramp.com and not through your organizations page on Okta (we do not support IdP-iniated log ins).
Disconnect Okta on Ramp
- Go to the “Settings” menu on your Ramp dashboard
- Select “Company Settings” in the menu
- Scroll down and select "Disconnect"
Can I sign in to Ramp by clicking on the Ramp Okta application icon?
We do not support IdP-initiated flows, but are working on a solution that will be available soon.
To log in now, head to Ramp.com and click "Sign in with your identity provider".
Then, enter your email address and proceed with the log in process.