Third Party Index

Snapshot 58782

Document
Security page
URL
https://gatsby.events/platform/account-settings/security-sso/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
static
Size
150250 bytes
SHA-256 (raw)
44e42404466969bb7f571e7404408121ac5ad6f33585e0e018c07c1c69f5425e
SHA-256 (normalized text)
10d1d443918d87f7805fbc39bf3ff0a5f59bb6c06d0a9e837c0892126cab67a3

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to content
Overview
Account & Settings
Security & SSO
Gatsby is SOC 2 Type II certified with enterprise SSO through Okta, Google SSO, magic link login, and enforceable two-factor authentication across your organization.
SOC 2 Type II Certified
Independently audited, annually renewed.
Send the report to your security team instead of answering 50 questions yourself.
Okta SSO
Centralized access through your identity provider.
Provision and deprovision users from Okta. No separate account management.
Enforceable 2FA
Require two-factor across your organization.
Or let individual team members enable it for their own accounts.
SOC 2 Type II Certification
Section titled “SOC 2 Type II Certification”
An independent auditor evaluates Gatsby’s security controls annually. This is a sustained review, not a self-assessment or a point-in-time snapshot, and it covers five trust principles: security, availability, processing integrity, confidentiality, and privacy.
For most enterprise procurement workflows, SOC 2 Type II is the baseline audit standard.
What the Certification Covers
Security
Data protected against unauthorized access through encryption and access controls.
Availability
Redundant infrastructure and disaster recovery for reliable uptime.
Processing Integrity
Guest data, RSVPs, and event information processed accurately.
Confidentiality
Guest lists and private event details protected from unauthorized disclosure.
Privacy
Personal information handled in compliance with privacy laws and policies.
Requesting the Report
Contact Gatsby directly through Slack or email. We provide the report for your security review or compliance documentation under NDA.
Authentication
Section titled “Authentication”
Gatsby supports Okta for enterprise SSO, Google for teams in Google Workspace, magic links for passwordless login, and standard username/password with optional 2FA.
Okta SSO
Section titled “Okta SSO”
Okta SSO is a limited-release feature. Gatsby must enable it for your org before you can configure it — contact us to get started.
Centralize Gatsby access through your Okta tenant. Users sign in once. Offboarding happens automatically when you remove someone from Okta.
What's Supported
SP-initiated SSO: Start from the Gatsby login page, authenticate through Okta
IdP-initiated SSO: Start from your Okta app dashboard, land directly in Gatsby
Automatic provisioning: Users added in Okta gain Gatsby access
Automatic deprovisioning: Users removed in Okta lose Gatsby access. Sessions persist up to 12 hours after deprovisioning — plan offboarding workflows around this window.
Requirements
Before you begin, confirm you have:
Access to an Okta tenant
Okta administrator privileges
Admin access to your Gatsby organization
Okta enabled on your team account in Gatsby (contact us)
Setup Steps
In Okta, navigate to Applications and click Browse App Catalog.
Search for “Gatsby” and click Add Integration.
Complete General Settings for your organization.
In Gatsby, open Team Settings and find the Okta Configuration section.
From Okta’s Sign On tab, copy the Client ID and Client Secret into the corresponding Gatsby fields.
For the Issuer URL, click the dropdown in Okta’s top right corner and copy the Authorization Server URL.
Click Save to complete configuration.
How Users Sign In
Once configured, users can sign in three ways:
From Okta
Click the Gatsby app tile in your Okta dashboard.
From Gatsby Login Page
Click “Login with Okta” on the standard Gatsby login page.
Direct Okta Login
Navigate directly to gatsby.events/oktaLogin for Okta-only authentication.
New User Provisioning
Users in your Okta directory don’t need to be pre-created in Gatsby. When someone logs in via Okta for the first time:
Gatsby automatically creates their account
They are assigned the Team Member role by default
No invitation email is sent — the Okta login itself serves as onboarding
You do not need to manually create accounts for users in your Okta directory before enabling the integration.
Enforcing Okta for Your Organization
When you enable Okta enforcement, all other login methods are blocked for your team members. Password login, Google SSO, and magic links stop working. This is a hard cutover, not a gradual rollout.
External Collaborators are exempt. Users with the External Collaborator role are not subject to Okta enforcement. Vendors, co-hosts, and external guests continue signing in via other methods. This is by design — you shouldn’t need to provision every outside contact through Okta.
Multi-org users. Enforcement is per-org and role-based — a user’s role in your organization determines whether they must use Okta, regardless of their roles in other Gatsby organizations. Users who belong to multiple Gatsby organizations should confirm their role assignments before you enable enforcement. If you’re unsure, contact us.
Enabling enforcement does not immediately invalidate existing sessions. Users who are already logged in remain logged in until their session expires — up to 12 hours for Okta sessions, longer for other session types. After expiry, they will be required to authenticate via Okta.
Contact us to enable enforcement for your organization.
Google SSO and Magic Links
Section titled “Google SSO and Magic Links”
For teams without enterprise SSO requirements, Gatsby offers Google SSO and passwordless magic link login.
Google SSO
Click Login with Google on the Gatsby login page
Select your Google account
Optionally grant email sending permissions during sign-in
Your Google account handles authentication security
Magic Link
Click the magic link sign-in option on the login page
Enter your email address
Check your inbox for a secure sign-in link
Click to sign in without a password
Standard Login
Username and password authentication at gatsby.events/login.
Can be combined with two-factor authentication for additional security.
Require Google Login Only
Admins can restrict sign-in to Google SSO only, alongside the magic-link and 2FA controls in Team Settings » General. When enabled, password login and magic links stop working for your team members, and they must sign in with a Google account.
This is a separate setting from Okta enforcement. If your org enables both, confirm with Gatsby support which takes precedence for a given team member, since the two controls are not designed to be layered without guidance.
Your browser does not support the video tag.
Two-Factor Authentication
Section titled “Two-Factor Authentication”
Add a second verification step to username/password logins. You can enable 2FA for yourself or require it across your organization.
Your codes come from an authenticator app on your phone. Gatsby doesn’t send them by text or email, so there’s nothing to wait for after you enter your password.
Set Up 2FA for Your Account
Click your initials in the top right corner.
Select Settings.
Open the Account Security tab.
Click Configure 2FA.
Scan the QR code with your authenticator app (Google Authenticator, Authy, 1Password, or similar).
Enter the code from your authenticator to verify setup.
If you don’t see an Account Security tab, your account signs in through Google or Okta. Those logins are secured by your identity provider and don’t use Gatsby’s 2FA.
Require 2FA for Your Organization
Admins can enforce 2FA for all team members.
Navigate to Team Settings.
Toggle Require Two Factor Authentication to on.
All team members will be prompted to set up 2FA on their next login.
When 2FA Doesn't Apply
Gatsby’s 2FA covers username/password logins only.
Google logins use Google’s own security (including their 2FA if enabled)
Okta logins use Okta’s security policies
Magic link logins verify identity through email access
Your browser does not support the video tag.
Reporting a Security Issue
Section titled “Reporting a Security Issue”
Found a vulnerability in Gatsby, or noticed something that looks wrong with your account?
Email us at: security@gatsby.events
Common Questions
Section titled “Common Questions”
Is Okta your only enterprise SSO option?
Currently, yes. Google SSO is available for teams using Google Workspace. If you have specific SSO requirements, contact us to discuss options.
Does Okta SSO cost extra?
No. The Okta integration does not carry an additional cost. Contact us to have it enabled for your account.
Can I require everyone on my team to use Okta?
Yes. When enforcement is enabled, all other login methods are blocked for your team members. Password login, Google SSO, and magic links stop working. External Collaborators are exempt and continue signing in via other methods. Contact us to enable enforcement for your account.
I never got my 2FA code. Where is it?
Nothing was sent. Your code lives in the authenticator app you scanned the QR code with during setup, and it changes every 30 seconds. Open the app, find the Gatsby entry, and type in the six digits showing at that moment.
Gatsby doesn’t send 2FA codes by text or email.
What happens if I lose access to my authenticator?
Ask an admin in your Gatsby organization to reset it for you. From the Team Members page, they hover over your status in the Two Factor Enabled column, click the arrow that appears, and choose Reset 2FA. That clears the authenticator pairing on your account. If there’s no admin available to you, contact Gatsby support and we can help you regain access.
Do you have a security questionnaire we can use?
Contact us directly. We provide our SOC 2 report and answer specific questions for your security review process.
Previous
Plan & BillingNavigate to the next section
Next
Related
Platform Overview
Playbooks Overview
Examples Overview
Pricing Overview
Log in