Okta + Arbitex Gateway
SAML 2.0 SSO, SCIM 2.0 automated provisioning, and Okta group-to-RBAC role mapping — enforce identity governance at the AI gateway without changing your identity infrastructure.
Three steps to Okta-governed AI access
Connect Okta to Arbitex Gateway using your existing enterprise application configuration. No custom proxies or separate credential stores required.
Register Arbitex as a SAML 2.0 Service Provider
In your Okta Admin Console, create a new SAML 2.0 application for Arbitex Gateway. Configure the Assertion Consumer Service (ACS) URL and Entity ID provided in Arbitex Cloud settings. Arbitex supports SAML 2.0 with Single Logout (SLO) — users signed out of Okta are immediately revoked at the gateway.
- ACS URL and Entity ID available in Settings → Identity → SAML 2.0 in Arbitex Cloud
- Enable the "Groups" attribute statement to pass group membership claims
- Single Logout URL configured automatically on first successful assertion
Configure SCIM 2.0 Provisioning for Automated User Lifecycle
Enable SCIM 2.0 provisioning in your Okta application to automate user creation, attribute updates, and deprovisioning. When a user is removed from the Okta application assignment, access to Arbitex is revoked automatically — no manual offboarding steps.
- SCIM base URL and bearer token available in Settings → Identity → SCIM 2.0
- Supports Create, Update, and Deactivate operations
- Group push syncs Okta group membership changes to Arbitex in near real time (subject to Okta push frequency)
Map Okta Groups to Arbitex RBAC Roles
Define group-to-role mappings in Arbitex Cloud to translate Okta group membership directly into Arbitex RBAC roles. Users inherit permissions at login — no per-user configuration required. Role assignments update automatically when group membership changes in Okta.
- Admin — full platform access, policy management, audit log export
- Analyst — read access to audit log, DLP findings, and cost reports
- Viewer — dashboard access only; no configuration changes
Designed for regulated environments
Centralizing AI access through a federated identity layer reduces credential surface and strengthens your audit posture. Okta-governed Arbitex deployments are designed to align with SOC 2 access control requirements, HIPAA workforce authentication standards, and GDPR accountability principles.
- SOC 2 (designed for) — Arbitex access control and provisioning designed to satisfy CC6.1 logical access controls; audit log captures every SSO event and provisioning action
- HIPAA alignment — workforce authentication and access management controls; automatic deprovisioning reduces PHI access risk from terminated employees
- GDPR alignment — identity federation eliminates gateway-local credential stores; data minimization at the authentication layer
Ready to configure?
The full Okta integration guide covers metadata XML download, attribute statement configuration, SCIM bearer token rotation, and group mapping syntax.
Okta access control, enforced at every AI request.
Connect Okta to Arbitex Gateway in under an hour. SAML 2.0 SSO and SCIM 2.0 provisioning are available on all plans.