Symptom
Users attempting to log in to 8x8 Work for Desktop on macOS using Okta SSO receive an error message: "Invalid origin header detected". This issue is logged in the Okta System Log as "FastPass detected phishing attempt."
Applies To
8x8 Work for Desktop (macOS)
Okta Single Sign-On (SSO)
Okta FastPass
Resolution
Users should use the alternative option on the Okta sign-in page to log in via an external web browser instead of the embedded browser used by the 8x8 Work for Desktop application.
When the Okta sign-in page loads within the 8x8 Work for Desktop application, look for the "Use Single Sign On (browser)" option to open the sign-in page in an external browser.
Select the option to sign in via the browser. This will open the Okta sign-in page in your default web browser (e.g., Safari, Chrome).
Complete the Okta SSO process in the external browser. Upon successful authentication, you will be redirected back to the 8x8 Work for Desktop application, and you will be logged in.
Cause
This issue occurs because the 8x8 Work for Desktop application uses an embedded browser for authentication. Okta FastPass requires a valid origin header to verify the request source. The embedded browser fails to properly forward the origin header, causing Okta to interpret the request as potentially unsafe and triggering the "Invalid origin header detected" error.
The 8x8 Work for Desktop application is currently hardcoded to use the origin vod.8x8.com, which is not accepted by Okta in this scenario. Development has confirmed there is no plan to change the application's origin at this time, meaning the workaround of using an external browser is the current resolution.
Additional Information
Customers may also be able to work around this issue by modifying their Okta configuration to allow the vod.8x8.com origin, but this involves changes outside of 8x8's control and should be explored directly with their Okta administrator or Okta Support.