Configure a custom domain
You can customize your Okta org by replacing the Okta domain name with your own domain name. For detailed information on usage and setup, see Customize domain and email address.
Share the URL exactly as you customized it. Redirect URLs don't work.
You can create more than one custom domain and associate each one with its own brand.
When you create a custom domain, verify the Content Security Policy (CSP) settings. Ensure that you enforce the policies for your security posture and desired user experience. If you use custom sign-in or error pages with the custom domain, customize the CSP for the domain. See Customize the Content Security Policy (CSP) for a custom domain.
Disabling a custom domain resets the issuer mode of identity providers, authorization servers, and OIDC apps to your org's original domain.
Start this task
- 
                                                            In the Admin Console, go to . 
- Select a brand.
- Click the Domains tab.
- Click Add domain. For more information, see Customize domain and email address.
Custom domains with Okta-managed certificates
Okta-managed certificates are automatically renewed through a free Certificate Authority called Let's Encrypt. Allowing Okta to handle certificate renewals reduces your developer maintenance costs and eliminates the risk of a site outage when certificates expire. Certificate renewals are completed only after the certificate information that you provide is verified.
Okta-managed certificates aren't compatible with network zones. If your org requires network zones, you need to manage your own certificate renewals.
Re-assign a domain to another brand
- 
                                                            In the Admin Console, go to . 
- Select a brand.
- Click the Domains tab.
- Click Edit in the row of the domain that you want to re-assign.
- Select Re-assign to another brand. The Re-assign domain to another brand dialog appears.
- In the Brand name dropdown menu, select the brand that you want to re-assign the domain to.
- Click Re-assign domain.
