
This feature is available on our Enterprise plan, or as a paid add-on on our Business plan. Should you have any additional questions, please reach out to our customer support via
[email protected] or via our chat.
Single sign-on (SSO) lets your team log in to Filestage with the Okta account they already use every day. No extra passwords, tighter security, and full control over who can access your projects - and connecting Okta via OpenID Connect only takes a few minutes.
How single sign-on via OpenID Connect can help you
Connecting Filestage to Okta makes logging in easier for your team and gives your admins central control over access:
No extra passwords - everyone signs in to Filestage with their existing Okta account.
Central access control - decide in Okta who can access Filestage and remove access in one place when someone leaves your organization.
Enterprise-grade security - your authentication policies, like multi-factor authentication, automatically apply to every Filestage login.
How to set up SSO with OpenID Connect (via Okta)
Step 1: Create the app integration in Okta
Log in to your Okta Admin Dashboard. Navigate to Applications > Applications and click Create App Integration.
 Select OIDC - OpenID Connect as the sign-in method and Web Application as the application type, then click Next.
 Enter an App integration name that helps you identify the connection (e.g. Filestage). Under Grant type, select the Authorization Code option. Add the following Sign-in redirect URI: https://api.filestage.io/auth/enterprise/callback
 Under Assignments, choose who from your organization should have access to Filestage.
 Save the application. On the app's General page, copy the Client ID and the Client Secret. You'll also need your Okta domain URI - you can find it in the dropdown under your username/profile icon in the top right corner.
 |
And that's it for the Okta side - with your Client ID, Client Secret, and Okta domain URI you have everything you need to connect Filestage.
Step 2: Configure SSO in Filestage
In Filestage, go to app.filestage.io/teams/security-and-privacy - this opens the security and privacy settings of your last selected team. Scroll down to the Identity and Access Management (IAM) section and click Configure SSO.
 Select the OpenID Connect option. Fill in the details you copied from Okta: Issuer URL (your Okta domain URI), Client ID, and Client Secret. Click Save & test configuration - the verify section will appear at the bottom of the page.
 |
Step 3: Verify your SSO configuration

Once the verification is completed successfully, all your team members will be required to log in to Filestage via SSO only.
Copy the Test URL from the verify section. Sign out of Filestage, or open the test URL in an incognito window of your browser. Log in with your identity provider. If everything is configured correctly, the status switches to Verified and you'll see this confirmation:
 |
And that's it - from now on, your team members log in to Filestage with your identity provider.
💡 What’s next? Once you’re done, see how to manage your team members!
Let us know if you have any questions by reaching out to us on chat or emailing us at [email protected]. We're always happy to help!