> For the complete documentation index, see [llms.txt](https://documentation.pushly.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://documentation.pushly.com/pushly-ja/platform/organizations/shingurusainon/okta-workforce.md).

# Okta Workforce

## Okta Adminで: Okta OIDCアプリケーションを作成する

会社のOkta Workforceの管理者は、Adminポータルにログインし、以下の手順に従ってOIDCアプリケーションを作成する必要があります。

選択 `アプリケーション` > `アプリケーション`、そして `App Integrationを作成`.

<figure><img src="/files/bbceb31291c36b84dee97824701a61760a3b61c6" alt=""><figcaption></figcaption></figure>

選択 `新しいアプリを作成`

選択 `OIDC` をサインイン方法として選択します。次に `Webアプリケーション` をアプリケーションタイプとして選択します。

<figure><img src="/files/3450897f8267cd7dfc16f081c65d0f9f9adc404a" alt=""><figcaption></figcaption></figure>

〜をクリック `次へ` ボタン

App統合名に「Pushly」を入力します

の下に `サインインリダイレクトURI` 次の値を入力します:

```
https://identity.pushly.com/login/callback
```

の下に `サインアウトリダイレクトURI` 次の値を入力します:

```
https://identity.pushly.com
```

もし〜を求められたら `Initiate Login URI` 次の値を入力できます:

```
https://platform.pushly.com
```

〜については `制御されたアクセス` 組織に適したオプションを選択してください。&#x20;

{% hint style="warning" %}
**Controlled Access設定は、どのOktaユーザーがPushlyアプリケーションに対して認証できるかを制御します。** もし アクセスを特定のグループに限定する場合、Pushlyにログインする必要があるすべてのユーザーは、そのグループのメンバーであるか、Oktaでこのアプリケーションに割り当てられている必要があります。割り当てられていないユーザーはログイン時にOktaによってブロックされ、すでにPushlyプラットフォームに存在していても、サインイン失敗が表示されます。
{% endhint %}

<figure><img src="/files/601636595943510f09d9a2fd5e3c7d592e6a7ed7" alt=""><figcaption></figcaption></figure>

〜をクリック `保存` ボタン

次のページで両方をコピーします `クライアントID` と `クライアントシークレット`。Pushlyプラットフォームで統合を作成するユーザーは、これら両方の値が必要です。

<figure><img src="/files/15d2bdf141c5819c70d5921ba8721665303ab7ce" alt=""><figcaption></figcaption></figure>

に加えて `クライアントID` と `クライアントシークレット` また、次を提供する必要があります `Oktaドメイン`。OktaドメインはAdminコンソールの右上にあります。あるいは、次の [手順](https://developer.okta.com/docs/guides/find-your-domain/main/) に従ってOktaドメインを取得できます。

## Pushly: Okta IDプロバイダーを作成する

これで `Oktaドメイン`, `クライアントID`、そして `クライアントシークレット` を入手したので [プラットフォームにログインし、](/pushly-ja/platform/organizations.md#accessing-organization-context) 組織設定ページへ移動

次に、 `セキュリティ` タブをクリックし、次に `プロバイダーを追加` ボタンをクリックします。

選択 `Okta Workforce` 〜から `プロバイダータイプ` ドロップダウン

その `Okta` ドメインは、 `.okta.com` を含めて入力してください。たとえば: `yourdomain.okta.com`

次を入力します `クライアントID` と `クライアントシークレット` このドキュメントの最初のステップで生成されたもの。

〜内の `関連ドメイン` テキストエリアに、組織がOkta経由でログインするために使用する各ドメイン名を1行ずつ入力します。たとえば、メールアドレスが `example@yourdomain.com` その場合、 `yourdomain.com`

<figure><img src="/files/d4c0c031e2aebc8d34c3269431a8bbc7ba148ea5" alt=""><figcaption></figcaption></figure>

プロバイダーの作成が正常に完了したら、 [ユーザーを招待する](/pushly-ja/platform/user-management.md#creating-a-user) を開始できます。招待されたユーザーのうち、メールアドレスが次のいずれかと一致するユーザーは `メールドメイン` のメールアドレスを持つユーザーは、認証のためOktaに送られます。

## トラブルシューティング

**ユーザーはログイン時に403エラーまたは「access denied」が表示されます**

ユーザーがログイン中にブロックされ、次を含むAuth0エラーが表示される場合 `access_denied` および説明文「User is not assigned to the client application,」がある場合、影響を受けるユーザーはOktaでPushlyアプリケーションに割り当てられていません。

このエラーはPushlyではなくOktaから発生します。OktaはログインフローがPushlyに戻る前にユーザーの認証を拒否するため、ユーザーのPushlyロールや権限とは関係ありません。

**解決するには:** Okta Adminコンソールで、次へ移動します `アプリケーション` → Pushlyアプリケーション →  `割り当て` タブを開き、影響を受けるユーザー（または所属グループ）をこのアプリケーションに割り当てます。影響を受けるユーザーはその後、再度ログインを試行できます。

**ユーザーはOktaで割り当て済みだが、まだログインできません**

Oktaのアプリケーション割り当てとPushlyユーザープロビジョニングは別々の要件です。OktaでユーザーをPushlyアプリに割り当てても、またはOktaアクセスを「全員を許可」に設定しても、そのユーザーがPushlyに作成されるわけではありません。ユーザーはPushlyプラットフォームにも招待されている必要があります。ユーザーがOktaで認証できるのにPushlyにアクセスできない場合は、そのユーザーがプラットフォーム上で作成されていることを確認してください。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://documentation.pushly.com/pushly-ja/platform/organizations/shingurusainon/okta-workforce.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
