This article applies to organization admins in the PI2 platform.
If your organization leverages Okta at your organization, you can use it to enable single sign-on (SSO) to the Predictive Index platform.
In this article, we'll walk through Okta's Express Configuration process, which is required to get SSO with PI up and running.
Important: In addition to being an organization admin in PI2, you'll need to be an Okta admin to accomplish the following steps. If you lack proper access to Okta, we recommend reaching out to your IT team.
Supported features
Service Provider (SP)-initiated authentication (SSO) flow – Users initiate login directly via the PI app and are redirected to Okta for authentication.
Identity Provider (IdP)-initiated authentication (SSO) flow - Users can log in to the Predictive Index app through the Okta IdP.
Universal logout – When enabled, Okta can terminate user sessions and tokens when risk is detected or when an admin initiates logout.
How to enable SSO via Okta Express Configuration
Okta's Express Configuration consists of the following steps:
1. Add the instance "The Predictive Index" in your Okta org
To add PI in your Okta org:
Log in to Okta.
Select "Admin" in the top-right corner.
Click "Applications," then "Applications" once more.
Select the "Browse App Catalog" button.
Type "The Predictive Index" into the search bar.
Select our app from the available options.
Click "Add Integration."
Within "General settings - Required," add an application label (e.g., The Predictive Index).
(Optional) Select whether to hide the application from users.
Confirm with "Done."
Okta will add an instance of our app to your org, after which you will be able to assign it to end users. Click here for Okta's documentation on assigning app integrations to users.
2. Configure single sign-on (SSO)
To configure SSO for The Predictive Index:
Click the "Authentication" tab within the Predictive Index app instance in your Okta org.
Click "Express Configure SSO" within the "Express Configuration for The Predictive Index" section.
You'll be redirected to the Predictive Index login page.
Sign in using your Okta admin credentials.
Review the "Authorize App" details on the consent page to grant Okta access to The Predictive Index.
Click "Accept."
You'll automatically be redirected to your Okta org.
A message will indicate that SSO has successfully been configured.
3. Verify the configuration
To verify your IdP-initiated SSO:
Assign the app to a test user in Okta.
Sign in as that test user to the Okta dashboard.
Click the Predictive Index tile.
Confirm you’ve successfully logged in to The Predictive Index.
How to log in to PI via Okta (SP-initiated SSO)
Visit https://app.predictiveindex.com from your browser.
Enter your email address.
Hit "Continue."
You will be automatically prompted to authenticate with Okta.
Enter your Okta credentials (email and password).
Proceed to sign in.
If successful, you will be redirected to the PI dashboard.
How to log in to PI via Okta (IdP-initiated SSO)
Log in to Okta.
Navigate to your Okta dashboard.
Search for and select the app titled "The Predictive Index."
You will automatically be redirected to the PI dashboard.
Understanding universal logout via Okta
Okta will terminate user sessions across all applications in either of the following cases:
An administrator initiates a logout from the Okta Admin Console.
The Okta system detects risk and terminates sessions for security.
As part of universal logout, Okta users will also be logged out of their respective PI account.





