Skip to main content
Your dedicated Ryvn hub can sign users in through your Okta organization. You create an OIDC application in Okta that points back at the hub’s sign-in service, then send the issuer and client credentials to Ryvn.
You need admin access to your Okta organization and the hub domain Ryvn gave you (for example acme.ryvn-abc12.ryvn.run). If you are not an Okta admin, forward this page to someone who is.
1

Create the application

In the Okta Admin Console go to Applications → Applications and click Create App Integration. Choose:Click Next.
2

Configure the redirect URIs

Replace <hub> with your hub domain and fill in the General Settings form:Click Save.
Check the hub domain before you save. It decides where Okta sends users after they sign in. Only use the domain Ryvn gave you directly, never one from an unsolicited link.
3

Use a static issuer

Open the application’s Sign On tab and click Edit in the OpenID Connect ID Token section. Change Issuer from Dynamic to the static URL of your Okta org (for example https://acme.okta.com), then click Save.
The hub validates tokens against a single issuer. With the default Dynamic setting the issuer varies with the URL used to reach Okta and sign-in fails.
4

Hand the credentials to Ryvn

From the application’s General tab, under Client Credentials, copy the Client ID and Client secret. Send the following to your Ryvn contact over the agreed secure channel, never in plain-text email or chat:Ryvn configures your hub with them and tells you when Okta sign-in is live.

Rotating the client secret

If the client secret is exposed, open the application’s General tab, generate a new secret under Client Credentials and send it to your Ryvn contact. Deactivate the old secret once Ryvn confirms the hub has been updated.