# Steps to configure the App in Okta

Below are the steps to configure the emsigner app in the Okta Application.

**Step 1:** Sign in to your Okta Account using the Email ID and Password.

<figure><img src="https://1693119202-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXNKpOPGIHdEkmaF2RQso%2Fuploads%2FVWX7RuMUpdlXJAaArttN%2Fimage.png?alt=media&#x26;token=fc53ebc5-c6b3-4a90-ba37-3f4cbbac6bef" alt=""><figcaption><p>Okta Signing Page</p></figcaption></figure>

**Step 2:** Click on the Admin tab present at the right side of the page at the top.

<figure><img src="https://1693119202-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXNKpOPGIHdEkmaF2RQso%2Fuploads%2Fit9FD9jb6P9SzRCBuZSa%2Fimage.png?alt=media&#x26;token=064d9603-5db5-4c7c-968a-ee0769f67738" alt=""><figcaption><p>Okta Dashboard Page</p></figcaption></figure>

**Step 3:** You will be redirected to the Admin Dashboard. Click on ‘Applications’ present in the left tab under the ‘Applications’ Menu.

<figure><img src="https://1693119202-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXNKpOPGIHdEkmaF2RQso%2Fuploads%2FtCSrzM5fiqHhCvLjsZfn%2Fimage.png?alt=media&#x26;token=25dfaaa8-6484-4b1c-a12d-4194b6a81a76" alt=""><figcaption><p>Okta Admin Dashboard</p></figcaption></figure>

**Step 4:** Click on ‘Create App Integration’ on this Page.

<figure><img src="https://1693119202-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXNKpOPGIHdEkmaF2RQso%2Fuploads%2Fy309ZQYFDGhhzKtQwiLW%2Fimage.png?alt=media&#x26;token=7aac9bd2-a53a-4da6-80e3-22d802c6cfee" alt=""><figcaption><p>App creation Page</p></figcaption></figure>

**Step 5:** Select SAML 2.0 from the options available and click on ‘Next’.

<figure><img src="https://1693119202-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXNKpOPGIHdEkmaF2RQso%2Fuploads%2Fp4aUZndSQYKH93XcPVLT%2Fimage.png?alt=media&#x26;token=f2b3653a-4567-45d3-820e-0bed4e6a88a5" alt=""><figcaption><p>App Integration Page</p></figcaption></figure>

**Step 6:** In this page Provide the App Name and add the App logo if needed to be displayed to the users and click on ‘Next’.

<figure><img src="https://1693119202-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXNKpOPGIHdEkmaF2RQso%2Fuploads%2Fp5MdcZMebWA53svY5FMO%2Fimage.png?alt=media&#x26;token=ce53f961-38b3-4360-b9e4-0be9600f1011" alt=""><figcaption><p>General Settings Page under App Creation</p></figcaption></figure>

**Step 7:** In the ‘Configure SAML’ page, provide the relevant details. Click on ‘Next’ after providing the below details. The details marked in bold below have to be taken from the eMudhra team and they vary for the UAT and PROD environments.

<figure><img src="https://1693119202-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXNKpOPGIHdEkmaF2RQso%2Fuploads%2Fx0YLAyHNy4byWvm0pOwZ%2Fimage.png?alt=media&#x26;token=9b85d5e4-959d-4763-8ed3-46c33e122211" alt=""><figcaption><p>Configure SAML Page under App Creation</p></figcaption></figure>

* **Single sign-on URL:** Here the callback URL of the emSigner application needs to be provided. Example: **https\://{{\*\*\*.emsigner.com}}/Areas/Login/LoginCallback**
* Audience URI (SP Entity ID): emSigner.com
* Name ID format: Select EmailAddress from the dropdown menu.
* Application Username: Select Email from the dropdown menu.
* Response: To be selected as Signed from the dropdown menu.
* Assertion Signature: To be selected as Signed from the dropdown menu.
* Signature Algorithm: To be selected as RSA-SHA256 from the dropdown menu.
* Digest Algorithm: To be selected as SHA256 from the dropdown menu.
* Assertion Encryption: To be selected as Unencrypted from the dropdown menu.
* Signature Certificate: Upload the .cer certificate as per the environment ([UAT Certificate](https://1693119202-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXNKpOPGIHdEkmaF2RQso%2Fuploads%2FM4i5w5jmDQGskQdG9P7g%2FemSignerUAT.cer?alt=media\&token=75c2df94-9e45-41b3-ab39-7d2307b63fd6) or [PROD Certificate](https://1693119202-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXNKpOPGIHdEkmaF2RQso%2Fuploads%2FgIKZaBxHRY8MNvTJATin%2FemSignerPROD.cer?alt=media\&token=92e45116-1a8f-4843-aabc-85580e136fa3)).
* Enable Single Logout: Check this box.
* **Single Logout URL:** Here the logout URL of the emSigner application needs to be provided. Example: **https\://{{\*\*\*.emsigner.com}}**
* SP Issuer: emSigner.com

**Step 8:** Select the relevant option, in this case the first option and click on ‘Finish’.

<figure><img src="https://1693119202-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXNKpOPGIHdEkmaF2RQso%2Fuploads%2Fu32IKOfSLxt39GvM2Plj%2Fimage.png?alt=media&#x26;token=44a8dac2-9663-4845-a248-11bc1771e124" alt=""><figcaption><p>Feedback Page under App Creation</p></figcaption></figure>

**Step 9:** The user will be redirected to the Settings page of the App where the Metadata URL will be shown. This metadata URL has to be configured in the Identity Providers Settings in emSigner.

<figure><img src="https://1693119202-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXNKpOPGIHdEkmaF2RQso%2Fuploads%2FfLt3IVEhVAvGMczwNBS6%2Fimage.png?alt=media&#x26;token=a7d6162c-155e-45da-adec-980397ddee75" alt=""><figcaption><p>Settings Page of the App</p></figcaption></figure>
