---
title: How to Configure the Profile Application in Okta
slug: portal-sub/how-to-configure-the-profile-application-in-okta
docTags: 
createdAt: 2026-03-04T12:03:15.583Z
---

# Overview & Requirements 

This article is designed to assist administrators and technical teams in integrating Okta's powerful identity and access management capabilities with Profile. By following our step-by-step instructions, you'll be able to establish a seamless and secure user authentication process, enable Single Sign-On (SSO) for a streamlined user experience, and efficiently manage user access through Okta's centralized platform.

## Requirements

- An Okta account
- SSO is a licensed module and will need to be setup by Intrahealth. Please contact your Intrahealth representative if you wish to enable this feature.

# Configuration Process

## Okta's Admin Console: Setting up the Profile Application and User Management

::::WorkflowBlock
:::WorkflowBlockItem
In the Admin Console, go to **Applications / Applications**
:::

:::WorkflowBlockItem
Clic&#x6B;**&#xA0;Create App Integration**.
:::

:::WorkflowBlockItem
To create an OIDC app integration, select **OIDC - OpenID Connect** as the Sign-in method.
:::

:::WorkflowBlockItem
Choose the type of application to integrate with Okta. Select **Native Application**.
:::

:::WorkflowBlockItem
Click **Next**.
:::

:::WorkflowBlockItem
In the **General Settings&#xA0;**&#x73;ection, enter the following information:

1. For the **App integration name&#xA0;**&#x66;iel&#x64;**,** enter an appropriate name to indicate that this integration is intended for use with Profile (e.g. 'Profile Integration').  
2. For the **Grant type**, check the following options:
   - Authorization Code
   - Interaction Code
   - Refresh Token
:::

:::WorkflowBlockItem
In both the **Sign-in-redirect URLs&#xA0;**&#x61;nd **Sign-out redirect URLs** fields you will need to replace the default information with information you will gather from within Profile: 

1. For the **Sign-in-redirect URLs&#xA0;**&#x66;ield in the Okta Admin Console:**&#xA0;**
   1. In Profile, go to **Organisation / Preferences / Setup / Internet / Messages** tab. 
   2. Copy the information from within the **Organisation Web URL field.**
   3. Past&#x65;**&#xA0;**&#x74;he information taken from Profile and add it to the **Sign-in-redirect URLs&#xA0;**&#x66;ield in the Okta Admin Console.
   4. Add the additional path "**/sso/auth**". For example, it could read as 'https\://mycompany.com/sso/auth'.
2. For the **Sign-out-redirect URLs&#xA0;**&#x66;ield in the Okta Admin Console:**&#xA0;**
   1. In Profile, go to **Organisation / Preferences / Setup / Internet / Messages** tab. 
   2. Copy the information from within the **Organisation Web URL field.**
   3. Past&#x65;**&#xA0;**&#x74;he information taken from Profile and add it to the **Sign-out-redirect URLs&#xA0;**&#x66;ield in the Okta Admin Console.
   4. Add the additional path "**/sso/logout**". For example, it could read as 'https\://mycompany.com/sso/logout'.
:::

:::WorkflowBlockItem
In the **Assignments** section of Okta's application setup, administrators can manage the assignment of the application to specific users or groups within their organization. This section enables precise control over which individuals or groups can access and utilize the application's features and resources, streamlining the allocation of application permissions and ensuring secure and efficient access management within the organization.**Note: &#xA0;**&#x49;f an Okta user is not assigned specifically to this Profile application within Okta, this user will not be able to access Profile via Okta.
:::

:::WorkflowBlockItem
Click the **Save&#xA0;**&#x62;utton found at the bottom of the page. You will be brought to a new screen automatically, starting in the General Tab.### General Tab
:::

:::WorkflowBlockItem
### The Client Credentials section contains important information necessary for authentication flows:

- **Client ID&#xA0;**- This is the public identifier required by all OAuth flows. This identifier is randomly generated when you create the app integration. 
- This Client ID will be entered into Profile's **Client ID** field.
- **Client authentication** - Choose the method to use for client authentication.
  - **Client secret:&#xA0;**&#x53;electing this option displays a panel where you can generate a secret for use by the client. This value is known only to Okta and your app integration. Click **Save** to generate the client secret. You can view or copy the client secret. If you have a second client secret, you can change the status to select the active secret. 
  - The **Client secret &#xA0;**&#x77;ill be entered in Profile's **Client Secret** field.
  - Click **Save** to commit any changes to your **Client Credentials**. If you changed your client authentication method, see [Change client authentication methods](https://help.okta.com/en-us/content/topics/apps/oauth-client-cred-mgmt.htm#Change), in the Okta Help Center, for information on how existing secrets and keys are affected.
:::

:::WorkflowBlockItem
For the **Refresh Token** setting, check the **Use persistent token&#xA0;**&#x6F;ption.
:::

:::WorkflowBlockItem
For the **User Consent**, click the **Require consent&#xA0;**&#x6F;ption.### Sign On Tab
:::

:::WorkflowBlockItem
Click on the **Sign On&#xA0;**&#x74;ab.
:::

:::WorkflowBlockItem
Keep the default information as is.
:::
::::

# Learn More

- [Profile's SSO capabilities with Okta](docId\:IAZFooLTgyBo7h0BrvMDX)
- [How to create and configure a Profile desktop shortcut for the Okta SSO capabilities](docId\:ypf5TifhNVQcMM8-nfa7a)
- [How to configure SSO for Okta in Profile](docId:1xWeRJfXjSVpfdPq-twc5)
- [Troubleshooting guide: SSO with Okta](docId\:oTb1hsurkQK3IwROmjYxf)
- [How to log into Profile using SSO with Okta](docId\:pmgyx2Vt_2XLcR96QYFke)
- [How to log out when using SSO with Okta](docId\:JY800lubOnaArI5qutYvE)
