Knowledge Base

Find answers to common questions about Cloudmersive products and services.



Configuring Okta SAML SSO Authentication for Cloudmersive
8/3/2026 - Cloudmersive Support


Note: SAML SSO must be enabled on your Cloudmersive account before you begin. Work with
your Cloudmersive representative to enable the feature.

Cloudmersive supports SAML 2.0 single sign-on, which lets your users sign in to the
Cloudmersive Management Portal with Okta. SAML SSO is configured for your organization's
email domain. Once enabled, any user whose email address is on that domain can sign in
through Okta.

Prerequisites

  • SAML SSO is available on Enterprise plans. If the Manage SAML SSO page asks you to
    contact sales, reach out to your Cloudmersive account representative to enable it.
  • Okta administrator access.
  • A Cloudmersive account whose email address is on your organization's domain, with a
    verified email address. You can verify your email address from Settings in the portal.

Step 1: Get the Cloudmersive service provider details

  1. Sign in to the Cloudmersive Management Portal at https://portal.cloudmersive.com.
  2. Go to Security Center and click Manage Authentication, then click Manage SAML SSO.
  3. Confirm the domain shown on the page is your organization's email domain.
  4. Note the values shown under Step 1 on the page. You will enter them into Okta:
    • Service Provider Entity ID (Audience URI)
    • Assertion Consumer Service (ACS) URL

Step 2: Create the SAML application in Okta

  1. In the Okta Admin Console, go to Applications, then Applications, and click
    Create App Integration.
  2. Choose SAML 2.0 and click Next.
  3. Enter an application name such as Cloudmersive and click Next.
  4. On the Configure SAML page, enter:
    • Single sign-on URL: the ACS URL from Cloudmersive. Leave "Use this for Recipient
      URL and Destination URL" checked.
    • Audience URI (SP Entity ID): the Service Provider Entity ID from Cloudmersive.
    • Name ID format: EmailAddress
    • Application username: Email
  5. Optionally add attribute statements named firstName and lastName mapped to
    user.firstName and user.lastName.
  6. Click Next, then Finish.
  7. On the application's Sign On tab, open the SAML setup instructions (View SAML setup
    instructions or the Metadata details section). Note the following values:
    • Identity Provider Issuer
    • Identity Provider Single Sign-On URL
    • X.509 Certificate
      You can also download the metadata XML, which contains all three.
  8. On the Assignments tab, assign the application to the users or groups who should be
    able to sign in to Cloudmersive.

Step 3: Enter the Okta details in Cloudmersive

  1. Return to the Manage SAML SSO page in the Cloudmersive portal.
  2. Either paste the Okta metadata XML and click Import from metadata, or fill in the
    fields directly:
    • Identity Provider Entity ID: the Okta Identity Provider Issuer
    • Identity Provider Single Sign-On URL: the Okta Identity Provider Single Sign-On URL
    • Identity Provider Signing Certificate: the Okta X.509 Certificate
  3. Check Enable SAML sign-in for your domain.
  4. Click Save SAML Configuration.

Step 4: Sign in with SAML SSO

  1. Go to https://portal.cloudmersive.com/login and click Sign in with SAML Single Sign-On.
  2. Enter your work email address and click Continue. You are redirected to Okta to
    authenticate, including any MFA your Okta policies require.
  3. The first time each user signs in with SAML, Cloudmersive sends a one-time confirmation
    code to their email address. After that confirmation, future sign-ins go straight
    through Okta.

Existing sign-in methods such as passwords or Sign in with Microsoft continue to work
alongside SAML SSO. To require SAML for all users on your domain, contact Cloudmersive
Support.

Certificate rotation

When Okta issues a new signing certificate, add it in the Secondary Signing Certificate
field in Cloudmersive and save before activating it in Okta. Once the new certificate is
active, move it to the primary field and remove the old one. The current certificate's
expiration date is shown on the Manage SAML SSO page.

600 free API calls/month, with no expiration

Sign Up Now or Sign in with Google    Sign in with Microsoft

Questions? We'll be your guide.

Contact Sales