Skip to main content
The Okta integration lets your team sign in to the Corsa application with the identities you already manage in your Okta workspace. You create an OIDC Web Application in Okta, add Corsa as a trusted origin, and send Corsa the resulting client credentials. Corsa completes the federation on its side.

Prerequisites

  • A Super Admin or Org Admin role in your Okta workspace. Trusted Origins fall under “Edit Okta Settings”, which only those roles can change.
  • The Corsa region your workspace runs in (US or EU). Redirect and trusted-origin values differ per region.
  • Workspace owner access in Corsa, to invite users.
  • The email domains your users sign in with (for example, yourcompany.com). Corsa uses them to route users to your Okta organization.
For how SSO sign-in, invitations, and roles work in Corsa, see the SSO overview.

Setting up the integration

Step 1: Create an OIDC Web Application

  1. Sign in to the Okta Admin Console.
  2. Go to Applications → Applications.
  3. Click Create App Integration.
  4. Choose:
    • Sign-in method: OIDC - OpenID Connect
    • Application type: Web Application
  5. Click Next.

Step 2: Configure the application

On the New Web App Integration screen:
  • App integration name: any descriptive name (for example, Corsa).
  • Grant type: keep the default Authorization Code.
  • Sign-in redirect URIs: add the Corsa callback URL for your region. US workspace:
    EU workspace:
    Also add Corsa’s branded sign-in URI for your region, so you won’t need to change anything when Corsa switches to it:
    • US workspace: https://auth.corsa.finance/login/callback
    • EU workspace: https://auth.eu.corsa.finance/login/callback
    Enter the callback URLs exactly as shown above.
  • Sign-out redirect URIs: leave empty unless your org requires one.
  • Assignments → Controlled access: choose who should be able to sign in to Corsa through Okta (typically a specific group, or everyone in your org).
Click Save.

Step 3: Add Corsa as a Trusted Origin

Trusted Origins are configured separately from the app, under Security.
  1. In the Admin Console, go to Security → API.
  2. Open the Trusted Origins tab.
  3. Click Add Origin.
  4. Enter:
    • Name: Corsa.
    • Origin URL: the Corsa app URL for your region, including the https:// scheme:
      • US workspace: https://app.corsa.finance
      • EU workspace: https://app.eu.corsa.finance
    • Type: select both CORS and Redirect.
  5. Click Save.

Step 4: Share your credentials with Corsa

From the application’s General tab, copy the values under Client Credentials and send them to the Corsa team along with your Okta domain:
  • Client ID
  • Client Secret
  • Okta domain (for example, your-org.okta.com)
  • Email domains your users sign in with (for example, yourcompany.com)
  • Corsa workspace name and region
Send these over a secure channel — the client secret grants the same access as a password. Corsa will complete the federation on its side and confirm once your users can sign in through Okta. Tell Corsa if you also want to require SSO once testing succeeds.

Step 5: Test sign-in

  1. Invite a test user to your Corsa workspace by the exact email address in their Okta profile, with the role they should have.
  2. In a private browser window, the test user opens app.corsa.finance (or app.eu.corsa.finance).
  3. They click Continue with SSO, enter their work email, and sign in on your Okta page.
  4. They land in your workspace with the invited role. They don’t need to open the invitation link.
Once the test passes, invite the rest of your team the same way. If the user sees a password screen instead of Okta, Corsa doesn’t have their email domain on file yet. If they see “No workspace access yet”, invite that exact email address.

Support

If you run into issues during setup, contact support@corsa.finance with your Okta domain and the region of your Corsa workspace.