Skip to main content
Use this guide to configure Okta Workforce as the identity provider for your CodeRabbit Enterprise organization. The account management SSO wizard guides you through domain verification, SAML app setup, testing, and activation. After SSO is activated, users with a verified email domain must sign in to CodeRabbit through Okta.

Before you start

Make sure you have:
  • Critical: You must have an invitation to your CodeRabbit organization from your CodeRabbit account team before starting this setup.
  • Organization admin access in the CodeRabbit account management page
  • Access to the Okta Admin Console
  • Permission to create and configure SAML applications in Okta
  • Access to your DNS provider so you can add a TXT record for domain verification
  • The users or groups that should be allowed to sign in through Okta
If you do not see the Security section or the Start configuration button in your organization profile, contact your CodeRabbit account team. Your organization must be prepared for self-serve SSO before the account management SSO wizard appears.

Set up Okta self-serve SSO

1

Open the account management SSO wizard

Accept your CodeRabbit organization invitation and sign in to the account management page. Open the organization switcher, find the invited organization, and click Manage.
Organization switcher showing the Manage button for the invited organization highlighted

Click Manage for the invited organization

In the organization profile, select Security, and click Start configuration.
Organization profile Security section with the Start configuration button highlighted

Start SSO configuration from the Security section

2

Add and verify your email domain

In Domains, enter the email domain that should use Okta for CodeRabbit sign-in, then click Add.Copy the generated TXT record details into your DNS provider:The account management SSO wizard checks DNS automatically. Continue only after the domain shows Verified.
Domain verification step showing generated TXT record host and value fields highlighted

Copy the generated DNS TXT record into your DNS provider

3

Select Okta Workforce

In Connection, select Okta Workforce as the SAML identity provider.
Identity provider selection screen with the Okta Workforce tile highlighted

Select Okta Workforce as the identity provider

4

Create the Okta SAML app

In the Okta Admin Console, go to Applications -> Applications, click Create App Integration, select SAML 2.0, and click Next.On General Settings, enter a clear app name such as CodeRabbit, then continue to the SAML configuration screen.In Configure SAML, use the values shown in the account management SSO wizard:
Account management SSO wizard showing the Single sign-on URL and Audience URI fields highlighted

Copy the service provider values from the account management SSO wizard into Okta

On the Okta feedback screen, select This is an internal app that we have created, then click Finish.
5

Add attribute statements

In the Okta app’s Attribute Statements section, add the attributes shown in the account management SSO wizard.The mail attribute is required. firstName and lastName are optional in the account management SSO wizard, but adding them helps CodeRabbit populate user profile details correctly.
Account management SSO wizard showing the mail, firstName, and lastName attribute statements highlighted

Add the SAML attribute statements required by CodeRabbit

6

Assign users or groups in Okta

Open the Okta app’s Assignments tab and assign the users or groups that should be allowed to sign in to CodeRabbit through Okta.Users cannot complete SSO sign-in until they are assigned to the Okta application.
7

Paste the Okta metadata URL

In the Okta app, open the Sign On tab. Under Settings -> SAML 2.0 -> Metadata details, copy the Metadata URL.
Okta Sign On tab with the SAML Metadata URL highlighted

Copy the Metadata URL from the Okta app Sign On tab

Return to the account management SSO wizard. In Configure Okta Workforce, keep Add via metadata selected, paste the metadata URL, and continue.
Account management SSO wizard with the Metadata URL input highlighted

Paste the Okta Metadata URL into the account management SSO wizard

8

Test the SSO connection

In Test, click Open test URL and complete the Okta sign-in flow with an assigned user whose email matches your verified domain.Return to the account management SSO wizard and click Refresh logs until the latest test result shows Success. Do not activate SSO while the latest result is Pending or failed.
Account management SSO wizard showing the Open test URL button and a successful test result highlighted

Confirm the SSO test result succeeds before activation

9

Activate SSO

In Activate, review the activation message and click Activate SSO.
Activation changes sign-in behavior for the verified domain. After activation, users with that email domain must sign in to CodeRabbit through Okta.
Account management SSO wizard with the Activate SSO button highlighted

Activate SSO after the connection test succeeds

What’s next

Enterprise SSO overview

Return to the SSO overview to understand how Enterprise SSO fits into your CodeRabbit rollout.

Roles and permissions

Pair SSO with the right access controls by reviewing how roles work in your CodeRabbit organization.

Support

Contact CodeRabbit if the Security section is missing or the SSO test does not succeed.