Content is translated from English using DeepL Pro.
Required plan:
DeepL Pro Advanced, Team, Ultimate, Business, Enterprise, Voice for Conversations, Voice for Meetings or Write Pro
These setup instructions are only available in English.
Prerequisites
- Single sign on (SSO) is setup for DeepL. If you haven't set up SSO, follow the instructions in this article.
- Admin access to DeepL
- Protocol: OIDC (Open ID Connect)
- Identity provider: Okta
To use Just-In-Time (JIT) provisioning with group synchronization, you need to update your SSO configuration in both DeepL and your Okta instance.
Set the JIT group synchronization in Okta
- Go to your Okta instance and open the Applications section.
- Open your DeepL application.
- Go to the Sign On tab.
- Click Edit next to OpenID Connect ID Token.
- Select Filter for Groups claim type.
- For Groups claim filter enter groups, select Matches regex, and enter .*.
Enable JIT group synchronization in DeepL account
- Go to Settings in your DeepL admin account
- In section Team and Single sign-on click Edit.
- Enter the following information from Okta.
- OpenID Connect metadata endpoint:
https://YOUR_OKTA_DOMAIN.okta.com/.well-known/openid-configuration
(Replace YOUR_OKTA_DOMAIN with your Okta instance.) - Client Secret
- Groups claim name: groups
- OpenID Connect metadata endpoint:
- Enable JIT Group Sync. The user’s group memberships will be read by DeepL during the login.
Setup groups
- Go to Okta.
- Create groups for the DeepL access and add users to the groups.
- Open the DeepL SSO application and select the Assignments tab.
- Click on Assign and select Assign to Groups.
- Go to your DeepL account.
-
Create the same groups that you created in your Okta instance to manage your users.
JIT Provisioning Group Sync does not create groups based on the OIDC token. If the token includes groups that do not exist in DeepL, that group information will be ignored, and the user is added only to the Default group. For more information, see this article. - Go to the Groups tab and click on Create group.
- Enter a Group name.
We recommend using the same name that you used for your groups in Okta. However, you may choose a different name, e.g., if your organization uses concealed group names in the identity provider. - Enter the group name string from Okta under Group ID.
- Select one or several subscriptions the user group should have access to.
- Click on Create group to save the changes.
- Repeat this process for each group from your Okta instance. As a result, the groups you have granted access to the DeepL application will be reflected in your DeepL account.
Edit bookmark app
- Go to your DeepL bookmark app.
- Assign the same user and groups to the bookmark app as you have to the DeepL SSO app.
- Before testing, contact us by creating a request. Wait for the confirmation from our side.
- Test the SSO login with a user. Once the user logs in, they will be automatically assigned to the DeepL group or groups that match the Okta group based on the configured Group ID.