Who can use this feature?
Available on the Enterprise plan.
Accessible to Owners and Admins on Web App.
Alohi SSO works across Fax.Plus and Sign.Plus. To enable Single Sign-On (SSO) and automatic user provisioning (SCIM) through Okta, and allow your team members to access Fax.Plus or Sign.Plus from their Okta dashboard, you need Admin access to both Okta and your Fax.Plus or Sign.Plus account.
Keep Okta and Fax.Plus or Sign.Plus open in separate browser tabs, as you'll copy values between them.
Once confirmed, follow these steps to set up SSO via Okta:
Step 1: Create a new app integration in Okta
- In the Okta Admin Console, go to Applications and Resources > Applications > Create App Integration.
- In the dialog, keep Okta Integration Wizard selected and click Next.
Step 2: Choose the capabilities
- Switch on the following:
- SSO (Single Sign-On): select Security Assertion Markup Language (SAML). Leave OpenID Connect (OIDC) unchecked.
- Provisioning: select SCIM 2.0.
- Click Add integration details at the bottom of the page.
Step 3: Add the integration details
- Fill in the following:
- Display name: Alohi
- Description: a meaningful description, such as "Alohi SSO Integration"
- Tenant settings: leave empty
- Authentication settings > Authentication mode: select Bearer
- Click Configure your integration.
Step 4: Configure your integration
-
Under SAML properties, enter:
- Default ACS URL: https://sso.alohi.com/login
- Entity ID / audience restriction: https://sso.alohi.com/metadata
Leave all other fields empty.
- Under SCIM provisioning properties, enter:
- Base URL: https://sso.alohi.com/scim/v2
- What objects do you want Okta to manage in your integration?: keep Users preselected.
- User operations: check Create, Read (preselected), Update, Deactivate and Support PATCH for User. Leave Change password and Import User Schema unchecked.
- Click Review and deploy at the bottom of the page.
Step 5: Review and deploy
- Review your settings.
- Click Deploy changes at the bottom of the page.
Step 6: Add the app instance
- Make sure the Application label is set to "Alohi".
- Click Done.
Step 7: Activate SSO on Fax.Plus or Sign.Plus
- In Okta, open the Alohi application and go to Sign On > Sign on methods > SAML 2.0, then expand More details.
- In a separate tab, log in to your Fax.Plus account and go to Settings > Security.
- In the Access Management box, next to Single Sign-On (SSO), click Activate.
-
Copy the following values from Okta and paste them into Fax.Plus or Sign.Plus:
Okta Fax.Plus / Sign.Plus Sign on URL Single Sign-On URL Issuer Entity ID Signing Certificate X.509 Certificate - Click Next.
- In the User Provisioning (SCIM) step, choose the Product Assignment options you need, then copy the SCIM Token. You'll paste it into Okta in the next step.
Step 8: Enable the API integration in Okta
- In Okta, open the Alohi application's Provisioning tab and click Configure API Integration.
- Paste the SCIM Token into API Token.
- Uncheck Import Groups.
- Optionally, click Test API Credentials to verify the setup. You should see "Alohi was verified successfully!".
- Click Save.
Step 9: Set up provisioning to the app
- Under Provisioning > To App, click Edit.
- Check the following:
- Create Users
- Update User Attributes
- Deactivate Users
- Leave everything else as it is and click Save.
Step 10: Set the application username
- Go back to the Sign On tab and click Edit in the top right.
- Set Application username format to Email.
- Click Save.
Important: Complete this step before assigning any users. The email address is used as the login identifier in Fax.Plus and Sign.Plus.
Step 11: Assign your users
- Open the Assignments tab.
- Assign users or groups according to your organization's policies. Assigned users are created on Fax.Plus or Sign.Plus automatically through provisioning.
- They can now sign in to their account through the Alohi SSO integration.
Benefit: By setting up the Alohi SSO, you streamline access to both Fax.Plus and Sign.Plus and centralize user management in Okta, giving your organization a more secure and efficient document workflow.
Updating users' information
If your organization has changed a domain, or a user has changed their last name, and you need to update your users, you'll need to do this via your IdP - in this case, Okta. This must be done through the user's profile; updating via the Assignments page will not work.