Add Genesys Cloud as an application that organization members can access with the credentials to their Okta account.
There is a general problem when a Service Provider (SP) receives a SAML response from an Identity Provider (IdP) and their system clocks are not in sync. This problem can result in users getting locked out of their single sign-on when logging in. The problem might be caused by the length of the clock skew between the SP and the IdP. Clock skews between Genesys Cloud and your identity provider cannot be greater than 10 seconds.
In the General > Single sign on URL field, type the URL of your Genesys Cloud organization based on the AWS region.
AWS Region | URL |
---|---|
US East (N. Virginia) | https://login.mypurecloud.com/saml |
US East 2 (Ohio) | https://login.use2.us-gov-pure.cloud/saml |
US West (Oregon) | https://login.usw2.pure.cloud/saml |
Canada (Canada Central) | https://login.cac1.pure.cloud/saml |
South America (São Paulo) | https://login.sae1.pure.cloud/saml |
EMEA (Frankfurt) | https://login.mypurecloud.de/saml |
EMEA (Ireland) | https://login.mypurecloud.ie/saml |
EMEA (London) | https://login.euw2.pure.cloud/saml |
EMEA (UAE) | https://login.mec1.pure.cloud/saml |
EMEA (Zurich) | https://login.euc2.pure.cloud/saml |
Asia Pacific (Mumbai) | https://login.aps1.pure.cloud/saml |
Asia Pacific (Seoul) | https://login.apne2.pure.cloud/saml |
Asia Pacific (Sydney) | https://login.mypurecloud.com.au/saml |
Asia Pacific (Tokyo) | https://login.mypurecloud.jp/saml |
Asia Pacific (Osaka) | https://login.apne3.pure.cloud/saml |
In General > Audience URI, the value can be any unique string that you want to use to identify your Genesys Cloud organization.
For General > Name ID Format, choose EmailAddress.
Click Show Advanced Settings.
Click the General > Enable Single Logout check box.
In General > Single Logout URL, type the URL of your Genesys Cloud organization based on the AWS region.
AWS Region | URL |
---|---|
US East (N. Virginia) | https://login.mypurecloud.com/saml/logout |
US East 2 (Ohio) | https://login.use2.us-gov-pure.cloud/saml/logout |
US West (Oregon) | https://login.usw2.pure.cloud/saml/logout |
Canada (Canada Central) | https://login.cac1.pure.cloud/saml/logout |
South America (São Paulo) | https://login.sae1.pure.cloud/saml/logout |
EMEA (Frankfurt) | https://login.mypurecloud.de/saml/logout |
EMEA (Ireland) | https://login.mypurecloud.ie/saml/logout |
EMEA (London) | https://login.euw2.pure.cloud/saml/logout |
EMEA (UAE) | https://login.mec1.pure.cloud/saml/logout |
EMEA (Zurich) | https://login.euc2.pure.cloud/saml/logout |
Asia Pacific (Mumbai) | https://login.aps1.pure.cloud/saml/logout |
Asia Pacific (Seoul) | https://login.apne2.pure.cloud/saml/logout |
Asia Pacific (Sydney) | https://login.mypurecloud.com.au/saml/logout |
Asia Pacific (Tokyo) | https://login.mypurecloud.jp/saml/logout |
Asia Pacific (Osaka) | https://login.apne3.pure.cloud/saml/logout |
Field | Description |
---|---|
Name | Type OrganizationName. |
Name Format | Leave set to Unspecified. |
Value | Type the short name of your Genesys Cloud organization. If you do not know the short name of your organization, click Admin > Account Settings > Organization Settings in Genesys Cloud. |
If the following extra SAML attributes are present in the assertion, Genesys Cloud acts on the attributes. The attributes are case-sensitive.
Attribute name | Attribute value |
---|---|
Email address of the Genesys Cloud user to be authenticated.
| |
ServiceName | (Optional) A valid URL for the browser to be redirected to after successful authentication, or one of the following keywords:
|
Metadata | Description |
---|---|
Identity Provider Single Sign-on URL | Use for the Target URI setting in Genesys Cloud. |
Identity Provider Single Logout URL | Use for the Single Logout URI setting in Genesys Cloud. |
Identity Provider Issuer | Use for the Okta Issuer URI setting in Genesys Cloud. |
X.509 Certificate | Use for the Okta Certificate setting in Genesys Cloud. |
Field | Description |
---|---|
Certificate | To upload X.509 certificates for SAML signature validation, do one of the following.
Or you can:
Uploaded certificates appear with their expiration date. To remove a certificate, click X. Note: To renew or update an expiring certificate, follow these instructions to upload X.509 certificates, repeating steps 1--3. You can upload up to five certificates to Genesys Cloud per SSO configuration, and Genesys Cloud chooses the correct certificate during single sign-on and logout. |
Issuer URI | Type the Identity Provider Issuer. |
Target URL | Type the Identity Provider Single Sign-on URL. |
Single Logout URI | Type the Identity Provider Single Logout URL. |
Single Logout Binding | Choose HTTP Redirect. |
Audience (Entity ID) | Type the value used in step 3 of “Create a SAML application.” |
Get user feedback about articles.