ZITADELZZITADEL
Powered by
oleksandrO
ZITADEL•3mo ago•
40 replies
oleksandr

Okta/Zitadel SAML: Email is empty (EMAIL-spblu) when user not exist and auto-creation is enabled

🏬Self-hosted❓Question🧩Integrations❌Unsolved
Hi, i am trying to integrate Okta IDP with Zitadel via SAML. i made everything according to the documentation: https://zitadel.com/docs/guides/integrate/identity-providers/okta-saml

affected versions: v2.67.2 and v2.71.19
helm chart version: 8.13.1

SAML IDP configuration
- Automatic creation ✅
- Automatic update ✅
- Account creation allowed (manually) ❌
- Account linking allowed (manually) ❌

Okta returns xml with required attributes (i added more attributes on Okta side to debug)
- givenname
- surname
- emailaddress
- email
- nameID
- groups

Map script i used in Flow: External Authentication, Trigger: Post authentication
Script content took from here: https://zitadel.com/docs/guides/integrate/identity-providers/okta-saml#add-action-to-map-user-attributes

I tried to change the script in the same flow and trigger to throw an error to check if the script is running, but looks like script is not running as after changing the script i get same error:
EMAIL-spblu
EMAIL-spblu


It works perfect when the user is already present in zitadel, but it fails to create the user if it doesn't exist with the error in UI:
EMAIL-spblu
EMAIL-spblu


I didn't find any useful logs in zitadel containers with info/debug logger set

Please suggest what i can do/check to be able to auto-create users in zitadel using Okta SAML IDP?
ZITADEL banner
ZITADELJoin
ZITADEL - Identity infrastructure, simplified for you.
4,374Members
Resources
Recent Announcements

Similar Threads

Was this page helpful?

Similar Threads

Email is empty (EMAIL-spblu)
AnggakaraAAnggakara / questions-help-bugs
5mo ago
SAML + Microsoft Entra ID - user_creation_failed error on auto-creation
JeffersonJJefferson / questions-help-bugs
4mo ago
External User Not Found when trying to auto link SAML Users by Email
MarioMMario / questions-help-bugs
8mo ago
SAML response is not accepted by Zitadel?
GaiaGGaia / questions-help-bugs
8mo ago