Fax Integration

How to Set Up WestFax Single Sign-On with Okta

Create a SAML 2.0 app integration in Okta so your team launches WestFax straight from the Okta dashboard with credentials they already have.

WestFax supports SAML 2.0 single sign-on with Okta, so your team reaches the WestFax fax console through the Okta dashboard with credentials they already have — no separate WestFax password to issue or reset. Setup is a three-step round trip: turn SSO on with your WestFax account manager and copy three endpoints off the SSO tab, create a SAML 2.0 app integration in Okta and copy two values plus a certificate back, then paste those into the WestFax admin panel and save. From then on, access is governed by Okta assignment rules.

What you’ll need

  • An Okta organization account with at least one user, and admin access to your Okta dashboard
  • A WestFax Enterprise account with SSO enabled — see step 1 if it isn’t on yet
  • The WestFax integration listing at Okta.com, if you’d rather start from the catalog entry

What you get once it’s running: control from Okta over who can reach the WestFax platform, automatic sign-in for your users, and one central place to manage the accounts.

Step 1: Turn on SSO and copy your WestFax endpoints

SSO is not on by default. Before any of the identity-provider work below will do anything, your WestFax account has to be provisioned for it — contact your account manager and ask them to activate SSO. There may be a setup fee, and they will walk you through provisioning.

Once SSO is active on the account, sign in to the WestFax admin tool and open the SSO tab. You should see a screen like this:

The SSO tab in the WestFax admin panel showing the Consume, Redirect, and Metadata endpoints

The SSO tab shows three values generated for your account. Copy all three somewhere safe — every one of them gets pasted into your identity provider in the next step. YourProviderId is unique to your WestFax account; the tab shows the real value.

  • Consume Endpointhttps://home.westfax.com/login/Consume/YourProviderId. This is the SAML assertion consumer service (ACS) URL, where your identity provider posts the signed assertion.
  • Redirect Endpointhttps://home.westfax.com/login/sso/YourProviderId. This is the link your users click to sign in, and the start URL for service-provider-initiated login.
  • Metadata Endpointhttps://home.westfax.com/login/metadata/YourProviderId. This is the SAML entity ID that identifies WestFax as the service provider.

Copy these straight off the SSO tab rather than typing them by hand. A single wrong character in the Consume Endpoint is the most common reason a first SSO attempt fails.

Step 2: Create the WestFax app integration in Okta

Sign in to your Okta admin dashboard at login.okta.com and build the SAML app that represents WestFax.

  1. Go to Applications → Applications.

    The Applications section in the Okta admin navigation

  2. Click Create App Integration.

    The Create App Integration button on the Okta applications page

  3. Choose SAML 2.0 and click Next.

    Selecting SAML 2.0 as the sign-in method for the new Okta app integration

  4. Set the app name and logo. Enter WestFax for the name. If you want the app tile to look right on the Okta dashboard, use the WestFax logo. Click Next.

    Setting the app name and logo for the WestFax integration in Okta

  5. Enter the WestFax values on the SAML Settings page. This is where the endpoints from step 1 go.

    The Okta SAML settings form with the WestFax single sign-on URL and audience URI

    1. A — Single sign-on URL: https://home.westfax.com/login/Consume/YourProviderId
    2. B — Audience URI (SP Entity ID): https://home.westfax.com/login/metadata/YourProviderId
    3. C — Name ID format / Application username: EmailAddress / Email. Other fields can be used instead — ask us if your directory keys on something else.

    Download your x.509 certificate to a secure location while you’re here. You’ll upload it to WestFax in step 3.

    Downloading the x.509 signing certificate from the Okta app configuration

  6. Finish the wizard. On the feedback page, select I’m an Okta customer adding an internal app and click Finish.

    The final Okta app creation step with the internal app option selected

  7. Click View Setup Instructions in the yellow box on the Sign On tab.

    The View Setup Instructions button in the Okta sign-on settings

  8. Copy the first two values. Take the complete Identity Provider Single Sign-On URL. For the Identity Provider Issuer, copy only the unique code that follows http://www.okta.com/ — not the whole string.

    Okta setup instructions showing the identity provider single sign-on URL and issuer

Before you test: assign the app. Open the Assignments tab and add the people or groups who should reach WestFax — an unassigned user gets an error rather than a login screen.

Step 3: Finish the setup in the WestFax admin panel

Go back to the WestFax admin panel and open the SSO section again. This is where the two values and the certificate from Okta get entered.

The WestFax SSO settings form with fields for login endpoint, client ID, and x.509 certificate

  • A — Login Endpoint — the Identity Provider Single Sign-On URL from Okta.
  • B — Client Id (App Id) — the unique code from the Identity Provider Issuer, without the http://www.okta.com/ prefix.
  • C — Certificate x.509 — the certificate file you downloaded from Okta. Click upload and select it.

Click Save Settings. That completes the configuration.

Sign in with SSO

Your team signs in through the Redirect Endpoint from step 1 — https://home.westfax.com/login/sso/YourProviderId — rather than the standard WestFax login page. Copy the exact link off the SSO tab and distribute it, or let users launch WestFax from the tile on their Okta dashboard.

Troubleshooting

  • Users can’t see or launch the WestFax tile. They aren’t assigned. Add the user or their group on the app’s Assignments tab.
  • Sign-in fails right after the Okta prompt. Check the single sign-on URL and audience URI against the SSO tab character for character, including YourProviderId.
  • WestFax rejects an authenticated user. The most common cause is the Client Id: it must be only the unique code after http://www.okta.com/, not the full issuer string. After that, check the Name ID format is EmailAddress.
  • Sign-in worked and then stopped. Okta signing certificates expire. Download the current certificate and re-upload it in the WestFax SSO panel.

Still stuck? Call us at 303-299-9329, contact our team, or reach out to your account manager.