> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getunblocked.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Claude + Okta

> Configure the Unblocked connector in Claude with Okta so members can connect using their organization’s identity

Enterprise Managed Authorization lets your organization connect members to Unblocked in Claude through Okta, without requiring each member to complete a separate Unblocked browser sign-in.

For more background, see the [official MCP documentation on Enterprise-Managed Authorization](https://modelcontextprotocol.io/extensions/auth/enterprise-managed-authorization).

## Prerequisites

Before you start, confirm that:

1. You are configuring **Claude (Anthropic)**. This setup is only for the Unblocked connector in Claude.
2. Your organization uses **Okta** as its SSO provider for both Claude and Unblocked. Other identity providers are not supported for this setup.
3. [Okta SSO for Unblocked](/team-settings/sso/okta#configure-single-sign-on) is configured.
4. [User and group provisioning (SCIM)](/team-settings/sso/okta#user-and-group-provisioning) is enabled, and the members who need access are provisioned in Unblocked.
5. You have **organization-admin access in Claude** and the **Super Admin role in Okta**.

To check your Unblocked configuration, open [Single Sign-On settings](https://getunblocked.com/dashboard/team/current/settings/org/security). Under **SAML Configuration**, look for **Configured for Okta**. Under **SCIM User Provisioning**, check the **Last Synced** timestamp to confirm provisioning has synced.

<img src="https://mintcdn.com/unblocked/ArrMDF9pw9W-hoxp/img/mcp/enterprise-managed-authorization/okta-scim-configured.png?fit=max&auto=format&n=ArrMDF9pw9W-hoxp&q=85&s=678859cc7ce0ced13d4144f5601c1d86" alt="Unblocked settings showing SAML configured for Okta and a last synced timestamp under SCIM User Provisioning" width="1978" height="338" data-path="img/mcp/enterprise-managed-authorization/okta-scim-configured.png" />

## Configure managed authorization

<Steps>
  <Step title="Open your organization settings in Claude">
    Sign in to your organization's Claude account through Okta SSO. Open your account menu and select **Organization settings**.

    <img src="https://mintcdn.com/unblocked/ArrMDF9pw9W-hoxp/img/mcp/enterprise-managed-authorization/organization-settings.png?fit=max&auto=format&n=ArrMDF9pw9W-hoxp&q=85&s=02c7e904d036d1ff525ea2c847e56957" alt="Claude account menu with Organization settings selected" width="2872" height="2236" data-path="img/mcp/enterprise-managed-authorization/organization-settings.png" />
  </Step>

  <Step title="Find the Unblocked connector">
    Select **Connectors** under **Libraries & Access**. If Unblocked is already listed, open it. Otherwise, select **Add**, then **All available** to open the connector directory.

    <img src="https://mintcdn.com/unblocked/ArrMDF9pw9W-hoxp/img/mcp/enterprise-managed-authorization/add-connector.png?fit=max&auto=format&n=ArrMDF9pw9W-hoxp&q=85&s=627daaa2a4eb5bf130339bcf95e5049a" alt="Claude organization Connectors page with Add and All available selected" width="2872" height="2236" data-path="img/mcp/enterprise-managed-authorization/add-connector.png" />

    Search for **Unblocked**. Add the connector if needed, then open its details.

    <img src="https://mintcdn.com/unblocked/ArrMDF9pw9W-hoxp/img/mcp/enterprise-managed-authorization/find-unblocked.png?fit=max&auto=format&n=ArrMDF9pw9W-hoxp&q=85&s=e0394360aee90619d6b54abcb2a3b2c7" alt="Unblocked in the Claude connector directory search results" width="2872" height="2236" data-path="img/mcp/enterprise-managed-authorization/find-unblocked.png" />
  </Step>

  <Step title="Start managed authorization setup">
    Open the **Configuration** tab. Under **Managed authorization**, select **Set up**.

    <img src="https://mintcdn.com/unblocked/ArrMDF9pw9W-hoxp/img/mcp/enterprise-managed-authorization/managed-authorization-setup.png?fit=max&auto=format&n=ArrMDF9pw9W-hoxp&q=85&s=b547c95ff8d99ea7176ab7d1efda40f1" alt="Unblocked connector Configuration tab with the Managed authorization Set up button" width="2872" height="2236" data-path="img/mcp/enterprise-managed-authorization/managed-authorization-setup.png" />
  </Step>

  <Step title="Follow Anthropic's Okta setup guide">
    In the **Connect** step, confirm that Okta is the connected identity provider, then select **Open WorkOS setup**.

    <img src="https://mintcdn.com/unblocked/ArrMDF9pw9W-hoxp/img/mcp/enterprise-managed-authorization/open-workos-setup.png?fit=max&auto=format&n=ArrMDF9pw9W-hoxp&q=85&s=39c3213b5fc4bd827f5107329c5634b5" alt="Managed authorization Connect step with the Open WorkOS setup link" width="2872" height="2236" data-path="img/mcp/enterprise-managed-authorization/open-workos-setup.png" />

    Follow all steps in the Anthropic setup guide that opens. It provides the instructions and values for configuring Cross-App Access (XAA), the AI agent, and its resource connection in Okta.

    Use the **existing Okta application that provides SSO to your Unblocked organization** when configuring the connector application. The application name may differ from the example shown below. For the agent's user access, use your organization's Claude SSO application as directed by the guide.

    <img src="https://mintcdn.com/unblocked/ArrMDF9pw9W-hoxp/img/mcp/enterprise-managed-authorization/anthropic-setup-guide.png?fit=max&auto=format&n=ArrMDF9pw9W-hoxp&q=85&s=dcb06b5016d7fc9a84ae12aa62c01542" alt="Anthropic WorkOS guide for configuring the connector application and completing the Okta setup" width="2872" height="2236" data-path="img/mcp/enterprise-managed-authorization/anthropic-setup-guide.png" />

    <Note>
      Claude may also display a step to enable managed authorization in Unblocked's admin settings. No separate Unblocked managed authorization toggle is required. Complete the SSO and provisioning prerequisites above, then continue with the setup guide.
    </Note>
  </Step>

  <Step title="Test the connection">
    After completing the Anthropic guide, return to Claude and select **Run test**. Confirm that all checks pass, then select **Continue**.

    <img src="https://mintcdn.com/unblocked/ArrMDF9pw9W-hoxp/img/mcp/enterprise-managed-authorization/connection-test.png?fit=max&auto=format&n=ArrMDF9pw9W-hoxp&q=85&s=4e2f07d7789a1df4330ae1d2417e2528" alt="Successful checks for authorization server discovery, identity request, token exchange, and connector access" width="2872" height="2236" data-path="img/mcp/enterprise-managed-authorization/connection-test.png" />
  </Step>

  <Step title="Choose who gets managed authorization">
    Select the Claude roles whose members should connect through Okta automatically. Members outside the selected roles keep browser sign-in. Select **Continue**.

    <img src="https://mintcdn.com/unblocked/ArrMDF9pw9W-hoxp/img/mcp/enterprise-managed-authorization/choose-roles.png?fit=max&auto=format&n=ArrMDF9pw9W-hoxp&q=85&s=538eda721e5976cd48aaf5dc447e9f40" alt="Claude role selection for members who will use managed authorization" width="2872" height="2236" data-path="img/mcp/enterprise-managed-authorization/choose-roles.png" />
  </Step>

  <Step title="Choose the MCP scope">
    Keep the **mcp** scope selected, then select **Save & turn on**.

    <img src="https://mintcdn.com/unblocked/ArrMDF9pw9W-hoxp/img/mcp/enterprise-managed-authorization/choose-scopes.png?fit=max&auto=format&n=ArrMDF9pw9W-hoxp&q=85&s=34b35c581b3e3e6caea98afa94f45a84" alt="The mcp scope selected with the Save and turn on button" width="2872" height="2236" data-path="img/mcp/enterprise-managed-authorization/choose-scopes.png" />
  </Step>

  <Step title="Confirm managed authorization is enabled">
    On the connector's **Configuration** tab, confirm that **Managed authorization** is on and that **Applied roles** and **Scopes** match your selections.

    <img src="https://mintcdn.com/unblocked/ArrMDF9pw9W-hoxp/img/mcp/enterprise-managed-authorization/managed-authorization-enabled.png?fit=max&auto=format&n=ArrMDF9pw9W-hoxp&q=85&s=6e7871cce7b0a8882bdb35516d58d315" alt="Unblocked connector with managed authorization enabled, applied roles, and mcp scope" width="2872" height="2236" data-path="img/mcp/enterprise-managed-authorization/managed-authorization-enabled.png" />
  </Step>
</Steps>
