What the user sees
https://contoso.okta.com/
Demo simulation — do not enter real credentials
okta
Sign In
What's happening (HTTP)
Legend
Browser request
Server response
Server-to-server
Internal
User launches the app from the Okta dashboard; Okta pushes an unsolicited SAML assertion
The flow starts at the IdP, not the application. The user opens their company Okta dashboard directly (bookmark, browser homepage, or IT portal link). No Okta session exists yet, so Okta presents its login page. The app is not involved at all in this step.