This guide explains how to configure the Skillcast integration in Okta so your users can sign in using SAML Single Sign-On (SSO). If SCIM provisioning is included in your project scope, you can also automate user creation, updates, and deactivation directly from Okta.
Prerequisites
Before beginning the configuration, ensure that:
Your Skillcast environment is live.
SSO is included in your project scope.
Your Customer Success Manager has provided your Client ID.
If SCIM provisioning is included, your Customer Success Manager has provided your SCIM Bearer Token.
You have administrator access to your Okta organisation.
What Skillcast Supports
Feature | Supported |
SAML SSO | Yes |
SP-initiated SSO | Yes |
Just-In-Time (JIT) Provisioning | Optional |
SCIM 2.0 Provisioning | Optional |
Create Users | Yes |
Update Users | Yes |
Deactivate Users | Yes |
Group Push | No |
Configure the Skillcast Application in Okta
Add the Application
To connect Skillcast to Okta, add the Skillcast integration from the Okta Integration Network.
Open the Okta Admin Console.
Navigate to Applications > Applications.
Browse the App Catalog and search for Skillcast.
Select Add Integration.
Enter the application label that users will see.
Enter the Client ID provided by your Customer Success Manager.
Choose whether to display the application icon to users.
Select Done to complete the installation.
The Skillcast integration is published in the Okta Integration Network, so the required SAML URLs and identifiers are populated automatically.
Important Client ID Requirement
Make sure you enter the correct value in the Client ID field during setup. An incorrect Client ID will prevent users from authenticating to Skillcast using SAML.
Configure SAML Attributes
Skillcast supports the following SAML attributes:
Attribute Name | Okta Value |
firstName | user.firstName |
lastName | user.lastName |
user.email |
Additional custom attribute mappings may be required depending on your Skillcast configuration. Your Customer Success Manager will advise on any additional mappings required during onboarding.
Generate and Send Your Identity Provider Metadata
Skillcast requires your Identity Provider metadata before SSO can be activated.
Retrieve the Metadata
Open the Skillcast application in Okta.
Select the Sign On tab.
Under SAML 2.0, select View SAML Setup Instructions.
Download the metadata XML file or copy the metadata URL.
Send the metadata file or URL to your Skillcast onboarding contact.
Once the connection has been configured, Skillcast will provide a temporary test login URL.
Assign Users and Groups
Users must be assigned to the Skillcast application before they can sign in.
Assign Access
Open the Assignments tab.
Select Assign to People or Assign to Groups.
Select the users or groups that require access.
Only assign users who should have a Skillcast account.
Ensure users who should not have access are excluded from assigned groups.
Complete all assignments before testing SSO or SCIM provisioning.
SP-Initiated SSO
SP-initiated SSO allows users to begin the sign-in process directly from the Skillcast portal.
User Sign-In Process
Navigate to your Skillcast portal login page.
Select Sign in with SSO.
Enter your organisational email address.
Skillcast redirects you to Okta for authentication.
After successful authentication, you are redirected back to your Skillcast dashboard.
Configure SCIM Provisioning
SCIM provisioning is available only when it is included within your project scope and a SCIM Bearer Token has been provided by your Customer Success Manager.
Enable the SCIM Integration
Open the Provisioning tab within the Skillcast application.
Select Configure API Integration.
Tick Enable API Integration.
Enter the SCIM Bearer Token.
Select Test API Credentials to verify the connection.
Save your settings.
Enable Provisioning Actions
Under Provisioning to App, enable the lifecycle actions you require.
Provisioning Action | Description |
Create Users | Creates new users in Skillcast |
Update User Attributes | Updates user profile information in Skillcast |
Deactivate Users | Deactivates users when access is removed in Okta |
Save your changes once the required actions have been enabled.
Final Steps and Testing
After Skillcast receives your Identity Provider metadata:
Skillcast activates the SSO connection.
You receive a temporary URL for login testing.
Assigned users test the sign-in process.
Once testing is successful, Skillcast enables the live SSO connection.
If SCIM is enabled, create, update, and deactivate provisioning workflows are tested during User Acceptance Testing (UAT).
Tips and Troubleshooting
User Receives a "Not Assigned" Error
Verify that the user or their assigned group has been added to the Skillcast application in Okta.
User Sees a Skillcast Error During Login
Check that the user has an active Skillcast account. Users must exist in Skillcast before they can access the platform via SSO.
SAML Authentication Fails
Confirm that the Client ID entered during application setup matches the Client ID provided by your Customer Success Manager.
SCIM Provisioning Is Not Working
Review the following:
The SCIM Bearer Token is correct.
API credential testing succeeds.
Users are assigned to the application.
Provisioning actions are enabled.
Users belong to the correct assigned group.
User Attributes Are Not Updating
Review your attribute mappings in the Okta Profile Editor and ensure the correct Skillcast SCIM attributes are being used.
Limitations
SCIM Group Push is not supported.
SSO cannot be enabled in production until Skillcast has activated the connection.
Conclusion
You have now configured the Skillcast integration in Okta, including SAML Single Sign-On and optional SCIM provisioning. Once testing has been completed successfully, your users can access Skillcast securely using their Okta credentials.
If you require assistance during setup, testing, or onboarding, contact your Customer Success Manager by selecting Send us a message via the help icon on your portal, or by emailing [email protected].
