Apache Superset supports this out of the box through Flask-AppBuilder (FAB), the framework Superset is built on. The pieces are all there. What is missing is a single, current walkthrough that covers the Okta side, the Superset side, the role mapping, and the handful of reverse-proxy and cookie settings that turn a working configuration into a redirect loop. This is that walkthrough.
Okta as the only login path for Superset, with the local password form gone.
Users created automatically on first login, with their Okta groups mapped to Superset roles.
Role changes in Okta reflected in Superset at next login.
A troubleshooting table for the errors this setup produces in practice.
.png)
.png)

.jpg)
.jpg)
.jpg)
