Skip to main content

Set up SAML single sign-on with Okta

Sign in to Pensero with Okta (SAML 2.0): prerequisites, supported features, configuration steps and troubleshooting.

Written by Wayne

Enterprise plan only. SAML single sign-on is available on the Enterprise tier and is enabled per organization by the Pensero team. If you would like to use it, contact [email protected].

Pensero is an AI-native engineering measurement platform: it connects to your git provider, issue tracker, docs and messaging tools and turns pull requests, tickets and documents into delivery, quality and AI-adoption signals per person and team. With the Okta integration your people sign in to Pensero with their Okta identity (SAML) and are provisioned, updated and deactivated automatically (SCIM), so access always matches your directory.

This guide covers the SAML (single sign-on) part of the Pensero app in the Okta Integration Network. For user provisioning, see Set up SCIM with Okta.

Prerequisites

  • A Pensero organization on the Enterprise plan, with SAML enabled by Pensero (see below).

  • You are an organization administrator in Pensero and an administrator in Okta.

  • Every person who will sign in already exists as a user in Pensero with the same email address as in Okta. The easiest way to guarantee this is to enable SCIM provisioning in the same Okta app; alternatively invite them from Organization Settings → Users.

Supported features

  • IdP-initiated SSO — users click the Pensero tile in their Okta dashboard.

  • SP-initiated SSO — users go to https://pensero.ai/auth/login/, choose Log in with SSO and enter their email; Pensero redirects them to your Okta.

  • SAML-only login — optionally block Google and Microsoft sign-in for your organization so Okta is the only way in.

Not supported:

  • Single Logout (SLO). Signing out of Pensero does not end your Okta session, and signing out of Okta does not end your Pensero session.

  • Just-in-time (JIT) provisioning. SAML never creates users. A person who does not exist in Pensero cannot sign in — use SCIM or invite them first.

  • Group or role mapping. Roles and teams are managed in Pensero (or via SCIM attributes), not from SAML attributes.

Configuration steps

1. Add the Pensero app in Okta

  1. In the Okta Admin Console go to Applications → Applications → Browse App Catalog, search for Pensero and click Add Integration.

  2. On the Sign On tab, keep SAML 2.0 selected and set Application username format to Email. Pensero matches users by email, so the SAML NameID must be the user's email address.

  3. Click Save.

2. Send your Okta metadata to Pensero

  1. Still on the Sign On tab, under SAML Signing Certificates, open Actions → View IdP metadata for the active certificate. Save the XML.

  2. Email the XML file (or the metadata URL) to [email protected] from an organization administrator account. We load it into your organization and confirm when SSO is active — usually within one business day.

Pensero's service provider values are fixed and already configured in the Okta app; you only need them if Okta asks:

  • Single sign-on URL (ACS): https://pensero.ai/saml2/acs/

  • Audience URI (SP Entity ID): https://pensero.ai/saml2/metadata/

  • Name ID format: EmailAddress

  • Attribute statement: email → user.email

SAML assertion attributes

The Pensero OIN app is preconfigured to send one attribute statement in every SAML assertion: email, with the value user.email (the user's Okta email address). No configuration is needed on your side. Pensero identifies the user by the NameID (the user's email); the email attribute is included for reference only and never changes the user's profile. Do not add other attribute statements — Pensero ignores them.

3. Assign people

On the Assignments tab assign the users or groups who should access Pensero. If SCIM provisioning is enabled in the same app, assigning is also what creates the user in Pensero.

4. Test

  • IdP-initiated: as an assigned user, click the Pensero tile in your Okta dashboard. You land in Pensero signed in.

  • SP-initiated: open https://pensero.ai/auth/login/, click Log in with SSO, enter your email and complete the Okta login.

5. Optional: make SAML the only login method

Once everyone signs in through Okta, ask [email protected] to enable SAML-only login for your organization. Google and Microsoft sign-in are then rejected for your users.

Troubleshoot

  • "This email is not associated with any organization" (SP-initiated) — the user does not exist in Pensero yet. Assign them in Okta with SCIM enabled, or invite them, then retry.

  • "SSO is not enabled for your organization" — Pensero has not loaded your metadata yet. Check with [email protected].

  • Login succeeds in Okta but Pensero shows an error — the email in the SAML assertion does not match the user's Pensero email (for example a personal alias). Make the Okta username the work email, or add the alias to the user in Pensero.

  • User is asked to pick an account — the same email exists in more than one Pensero organization. Choose the right one; this is expected.

  • Certificate rotated in Okta — send the new IdP metadata to [email protected] before activating the new certificate, otherwise sign-in fails with an invalid signature.

  • Attributes not updated by SAML — SAML only authenticates. Name, manager, level and all other profile fields are updated by SCIM or in Pensero, never from the SAML assertion.

Support

Questions or problems: [email protected].

Did this answer your question?