Connecting Okta Single Sign-On (SSO) to CallHippo lets your team sign in through one secure identity provider, so you can manage access centrally and keep logins consistent across web, desktop, and mobile.
Activate the Okta SSO integration in CallHippo
- Log in to your CallHippo account.
- Open Integrations from the left menu.
- Search for Okta and click Connect.
- In the popup that appears, click Connect Now.
- The integration status now shows In Progress.
-
The Integration Settings pop-up opens. The SSO SAML Settings tab shows the Recipient, ACS URL Validator, and ACS (Consumer) URL you will need in the Okta portal.
- The Integration Settings popup opens. Fill in the required details on the Configuration tab to finish setup, following the sections below.
Configure SSO in Okta
- Log in to the Okta portal with an administrator account, Go to Applications and Resources > Applications, and click Create App Integration.
- Choose the SAML 2.0 single sign-in method and click Next.
- In General Settings, add the App name as "CallHippo" and upload the CallHippo logo (optional and can be skipped), then click Next.
- In the Configure SAML tab, set the Single sign-on URL and Audience URI (SP Entity ID) using the Recipient URL shown in the CallHippo SSO SAML Settings, then click Next.
- Click Finish on the Feedback tab.
- In the Sign On tab, scroll down to SAML Signing Certificates and click Actions > Download Certificate.
- Open the downloaded certificate in text editor and copy the complete certificate.
- Back in CallHippo, open the Okta SSO Integration Settings > Configuration tab, edit the X.509 Certificate (For Web Login) field, paste the copied certificate, and click Save.
Once the certificate is saved, the integration is successful, and the CallHippo integration status shows as Integrated.
Important notes on login behavior
- Once the CallHippo and Okta integration is completed, sub-users cannot log in manually and must use SSO. This applies to the web, desktop, and mobile applications.
- Only the Owner and Admins retain the ability to log in both manually and with SSO.