Okta
@keeb/oktav2026.08.25.3
01README
Okta CIAM identity models
02Release Notes
- Updated: app_schema, application, apps_credentials_csr, apps_credentials_jwk, apps_credentials_key, apps_credentials_secret, apps_feature, apps_federated_claim, apps_grant, apps_group, apps_token, apps_user, authenticator, authenticators_aaguid, authenticators_method, authorization_server_resource_key, authorization_server, authorization_servers_claim, authorization_servers_clients_token, authorization_servers_credentials_key, authorization_servers_policies_rule, authorization_servers_policy, authorization_servers_scope, brand_well_known_uri, brand, brands_theme, custom_domain, email_customization, email_domain, email_server, email_template, event_hook, group_schema, group, groups_rule, hook_key, identity_provider, identity_sources_session, idps_credentials_csr, idps_credentials_key, idps_user, inline_hook, linked_object_definition, log_stream_schema, log_stream, log, org_idps_credentials_key, policies_mapping, policies_rule, policy, profile_mapping, push_provider, realm_assignment, realm, roles_subscription, sms_template, telephony_provider, ui_schema, user_type, user, users_authenticator_enrollment, users_clients_token, users_factor, users_grant, users_subscription, webauthn_registration_users_enrollment, well_known_app_authenticator, well_known_apple_app_site, well_known_assetlinks, well_known_webauthn, yubikey_token
03Models
app_schema.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| app_id | string | Path scope for the app schema: app_id |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| definitions? | object | User profile subschemas The profile object for a user is defined by a composite schema of base and custom properties using a JSON path to reference subschemas. The `#base` properties are defined and versioned by Okta, while `#custom` properties are extensible. Custom property names for the profile o |
| properties? | object | User Object Properties |
| title? | string | User-defined display name for the schema |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a app schema
fn lookup(max_items?: number)
List app schemas and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
application.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| accessibility? | object | Specifies access settings for the app |
| label | string | User-defined display name for app |
| licensing? | object | Licenses for the app |
| profile? | record | Contains any valid JSON schema for specifying properties that can be referenced from a request (only available to OAuth 2.0 client apps). For example, add an app manager contact email address or define an allowlist of groups that you can then reference using the Okta Expression Language `getFiltered |
| signOnMode | enum | Authentication mode for the app | signOnMode | Description | | ---------- | ----------- | | AUTO_LOGIN | Secure Web Authentication (SWA) | | BASIC_AUTH | HTTP Basic Authentication with Okta Browser Plugin | | BOOKMARK | Just a bookmark (no-authentication) | | BROWSER_PLUGIN | Secure Web Authenticati |
| visibility? | object | Specifies visibility settings for the app |
| credentials? | object | Credentials for the specified `signOnMode` |
| name? | enum | `template_wsfed` is the key name for a WS-Federated app instance with a SAML 2.0 token |
| settings? | object | App settings |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a application
fn get(id: string)
Get a application
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the application |
fn lookup(q?: string, useOptimization?: string, alwaysIncludeVpnSettings?: string, filter?: string, expand?: string, includeNonDeleted?: string, max_items?: number)
List applications and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| q? | string | Searches for apps with `name` or `label` properties that starts with the `q` value using the `startsWith` operation |
| useOptimization? | string | Specifies whether to use query optimization. If you specify `useOptimization=true` in the request query, the response contains a subset of app instance properties. |
| alwaysIncludeVpnSettings? | string | Specifies whether to include the VPN configuration for existing notifications in the result, regardless of whether VPN notifications are configured |
| filter? | string | Filters apps with a supported expression for a subset of properties. Filtering supports the following limited number of properties: `id`, `status`, `credentials.signing.kid`, `settings.slo.enabled`, or `name`. See [Filter](https://developer.okta.com/docs/api/#filter). |
| expand? | string | An optional parameter used for link expansion to embed more resources in the response. Only supports `expand=user/{userId}` and must be used with the `user.id eq "{userId}"` filter query for the same user. Returns the assigned [application user](/openapi/okta-management/management/tags/applicationus |
| includeNonDeleted? | string | Specifies whether to include non-active, but not deleted apps in the results |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update application attributes
fn delete(id: string)
Delete the application
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the application |
fn sync()
Sync application state from Okta
fn activate(app_id: string)
Activate an application
| Argument | Type | Description |
|---|---|---|
| app_id | string | Path parameter: app_id |
fn create_logo(app_id: string, file: string)
Upload an application logo
| Argument | Type | Description |
|---|---|---|
| app_id | string | Path parameter: app_id |
| file | string | The image file containing the logo. The file must be in PNG, JPG, SVG, or GIF format, and less than one MB in size. For best results, use an image with a transparent background and a square dimension of 200 x 200 pixels to prevent upscaling. > **Notes:** > * Only SVG files encoded in UTF-8 are suppo |
fn deactivate(app_id: string)
Deactivate an application
| Argument | Type | Description |
|---|---|---|
| app_id | string | Path parameter: app_id |
fn get_sso_saml_metadata(app_id: string)
Preview the application SAML metadata
| Argument | Type | Description |
|---|---|---|
| app_id | string | Path parameter: app_id |
fn update_policies(app_id: string, policy_id: string)
[LIMITED_GA — requires Okta Identity Engine] Assign an app sign-in policy
| Argument | Type | Description |
|---|---|---|
| app_id | string | Path parameter: app_id |
| policy_id | string | Path parameter: policy_id |
Resources
state— Application resource state
application_action— Application action result
apps_credentials_csr.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| app_id | string | Path scope for the apps credentials csr: app_id |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| subject? | object | |
| subjectAltNames? | object | |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a apps credentials csr
fn get(id: string)
Get a apps credentials csr
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the apps credentials csr |
fn lookup(max_items?: number)
List apps credentials csrs and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn delete(id: string)
Delete the apps credentials csr
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the apps credentials csr |
fn sync()
Sync apps credentials csr state from Okta
fn publish(csr_id: string, certificate: string)
Publish a certificate signing request
| Argument | Type | Description |
|---|---|---|
| csr_id | string | Path parameter: csr_id |
| certificate | string | Raw certificate body, in the format named by the endpoint's content type |
Resources
state— Apps credentials csr resource state
apps_credentials_csr_action— Apps credentials csr action result
apps_credentials_jwk.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| app_id | string | Path scope for the apps credentials jwk: app_id |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| alg? | string | Algorithm used in the key |
| use? | enum | Acceptable use of the JSON Web Key |
| e? | string | RSA key value (exponent) for key binding |
| kty? | enum | Cryptographic algorithm family for the certificate's key pair |
| n? | string | RSA key value (modulus) for key binding |
| kid? | string | Unique identifier of the JSON Web Key in the OAUth 2.0 client's JWKS |
| status? | enum | Status of the OAuth 2.0 client JSON Web Key |
| x? | string | The public x coordinate for the elliptic curve point |
| y? | string | The public y coordinate for the elliptic curve point |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a apps credentials jwk
fn get(id: string)
Get a apps credentials jwk
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the apps credentials jwk |
fn lookup(max_items?: number)
List apps credentials jwks and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn delete(id: string)
Delete the apps credentials jwk
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the apps credentials jwk |
fn sync()
Sync apps credentials jwk state from Okta
fn activate(key_id: string)
Activate an OAuth 2.0 client JSON Web Key
| Argument | Type | Description |
|---|---|---|
| key_id | string | Path parameter: key_id |
fn deactivate(key_id: string)
Deactivate an OAuth 2.0 client JSON Web Key
| Argument | Type | Description |
|---|---|---|
| key_id | string | Path parameter: key_id |
Resources
state— Apps credentials jwk resource state
apps_credentials_jwk_action— Apps credentials jwk action result
apps_credentials_key.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| app_id | string | Path scope for the apps credentials key: app_id |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a apps credentials key
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the apps credentials key |
fn lookup(max_items?: number)
List apps credentials keys and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn sync()
Sync apps credentials key state from Okta
fn clone(key_id: string)
Clone a key credential
| Argument | Type | Description |
|---|---|---|
| key_id | string | Path parameter: key_id |
fn create_generate()
Generate a key credential
Resources
state— Apps credentials key resource state
apps_credentials_key_action— Apps credentials key action result
apps_credentials_secret.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| app_id | string | Path scope for the apps credentials secret: app_id |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| client_secret? | string | The OAuth 2.0 client secret string |
| status? | enum | Status of the OAuth 2.0 client secret |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a apps credentials secret
fn get(id: string)
Get a apps credentials secret
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the apps credentials secret |
fn lookup(max_items?: number)
List apps credentials secrets and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn delete(id: string)
Delete the apps credentials secret
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the apps credentials secret |
fn sync()
Sync apps credentials secret state from Okta
fn activate(secret_id: string)
Activate an OAuth 2.0 client secret
| Argument | Type | Description |
|---|---|---|
| secret_id | string | Path parameter: secret_id |
fn deactivate(secret_id: string)
Deactivate an OAuth 2.0 client secret
| Argument | Type | Description |
|---|---|---|
| secret_id | string | Path parameter: secret_id |
Resources
state— Apps credentials secret resource state
apps_credentials_secret_action— Apps credentials secret action result
apps_feature.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| app_id | string | Path scope for the apps feature: app_id |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| create? | object | Determines whether Okta assigns a new app account to each user managed by Okta. Okta doesn't create a new account if it detects that the username specified in Okta already exists in the app. The user's Okta username is assigned by default. |
| update? | object | Determines whether updates to a user's profile are pushed to the app |
| importRules? | object | Defines user import rules |
| importSettings? | object | Defines import settings |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a apps feature
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the apps feature |
fn lookup(max_items?: number)
List apps features and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update apps feature attributes
fn sync()
Sync apps feature state from Okta
apps_federated_claim.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| app_id | string | Path scope for the apps federated claim: app_id |
| expression? | string | The Okta Expression Language expression to be evaluated at runtime |
| name? | string | The name of the claim to be used in the produced token |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a apps federated claim
fn get(id: string)
Get a apps federated claim
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the apps federated claim |
fn lookup(max_items?: number)
List apps federated claims and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update apps federated claim attributes
fn delete(id: string)
Delete the apps federated claim
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the apps federated claim |
fn sync()
Sync apps federated claim state from Okta
apps_grant.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| app_id | string | Path scope for the apps grant: app_id |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| issuer | string | The issuer of your org authorization server. This is typically your Okta domain. |
| scopeId | string | The name of the [Okta scope](https://developer.okta.com/docs/api/oauth2/#oauth-20-scopes) for which consent is granted |
| _links? | object | Specifies link relations (see [Web Linking](https://www.rfc-editor.org/rfc/rfc8288)) available using the [JSON Hypertext Application Language](https://datatracker.ietf.org/doc/html/draft-kelly-json-hal-06) specification. This object is used for dynamic discovery of related resources and lifecycle op |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a apps grant
fn get(id: string)
Get a apps grant
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the apps grant |
fn lookup(expand?: string, max_items?: number)
List apps grants and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| expand? | string | An optional parameter to return scope details in the `_embedded` property. Valid value: `scope` |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn delete(id: string)
Delete the apps grant
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the apps grant |
fn sync()
Sync apps grant state from Okta
apps_group.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| app_id | string | Path scope for the apps group: app_id |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| lastUpdated? | string | Timestamp when the object was last updated |
| priority? | number | Priority assigned to the group. If an app has more than one group assigned to the same user, then the group with the higher priority has its profile applied to the [application user](https://developer.okta.com/docs/api/openapi/okta-management/management/tags/applicationusers). If a priority value is |
| profile? | record | Specifies the profile properties applied to [application users](https://developer.okta.com/docs/api/openapi/okta-management/management/tags/applicationusers) that are assigned to the app through group membership. Some reference properties are imported from the target app and can't be configured. See |
| _links? | object | Specifies link relations (see [Web Linking](https://www.rfc-editor.org/rfc/rfc8288)) available using the [JSON Hypertext Application Language](https://datatracker.ietf.org/doc/html/draft-kelly-json-hal-06) specification. This object is used for dynamic discovery of related resources and lifecycle op |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a apps group
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the apps group |
fn lookup(q?: string, expand?: string, max_items?: number)
List apps groups and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| q? | string | Specifies a filter for a list of assigned groups returned based on their names. The value of `q` is matched against the group `name`. This filter only supports the `startsWith` operation that matches the `q` string against the beginning of the [group name](openapi/okta-management/management/group#ta |
| expand? | string | An optional query parameter to return the corresponding assigned [group](openapi/okta-management/management/group) or the group assignment metadata details in the `_embedded` property. |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update apps group attributes
fn delete(id: string)
Delete the apps group
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the apps group |
fn sync()
Sync apps group state from Okta
fn set_group_id(group_id: string)
Update an application group
| Argument | Type | Description |
|---|---|---|
| group_id | string | Path parameter: group_id |
Resources
state— Apps group resource state
apps_group_action— Apps group action result
apps_token.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| app_id | string | Path scope for the apps token: app_id |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a apps token
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the apps token |
fn lookup(expand?: string, max_items?: number)
List apps tokens and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| expand? | string | An optional parameter to return scope details in the `_embedded` property. Valid value: `scope` |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn delete(id: string)
Delete the apps token
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the apps token |
fn sync()
Sync apps token state from Okta
apps_user.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| app_id | string | Path scope for the apps user: app_id |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| credentials? | object | Specifies a user's credentials for the app. This parameter can be omitted for apps with [sign-on mode](/openapi/okta-management/management/application/getapplication#application/getapplication/t=response&c=200&path=&d=0/signonmode) (`signOnMode`) or [authentication schemes](/openapi/okta-management/ |
| profile? | record | Specifies the default and custom profile properties for a user. Properties that are visible in the Admin Console for an app assignment can also be assigned through the API. Some properties are reference properties that are imported from the target app and can't be configured. See [profile](/openapi/ |
| created? | string | Timestamp when the object was created |
| id | string | Unique identifier for the Okta user |
| lastUpdated? | string | Timestamp when the object was last updated |
| scope? | enum | Indicates if the assignment is direct (`USER`) or by group membership (`GROUP`). If not specified, Okta tries to determine the scope based on the assignment type. |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a apps user
fn get(id: string)
Get a apps user
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the apps user |
fn lookup(q?: string, expand?: string, max_items?: number)
List apps users and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| q? | string | Specifies a filter for the list of application users returned based on their profile attributes. The value of `q` is matched against the beginning of the following profile attributes: `userName`, `firstName`, `lastName`, and `email`. This filter only supports the `startsWith` operation that matches |
| expand? | string | An optional query parameter to return the corresponding [User](/openapi/okta-management/management/tags/user) object in the `_embedded` property. Valid value: `user` |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update apps user attributes
fn delete(id: string)
Delete the apps user
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the apps user |
fn sync()
Sync apps user state from Okta
authenticator.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| description? | string | The description of the authenticator. This setting is only available for the `webauthn` authenticator type (Passkeys). |
| key? | enum | A human-readable string that identifies the authenticator |
| name? | string | Display name of the authenticator |
| status? | string | Status of the authenticator |
| type? | enum | The type of authenticator |
| _links? | object | Link relations for this object |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a authenticator
fn get(id: string)
Get a authenticator
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the authenticator |
fn lookup(max_items?: number)
List authenticators and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update authenticator attributes
fn sync()
Sync authenticator state from Okta
fn activate(authenticator_id: string)
[LIMITED_GA — requires Okta Identity Engine] Activate an authenticator
| Argument | Type | Description |
|---|---|---|
| authenticator_id | string | Path parameter: authenticator_id |
fn deactivate(authenticator_id: string)
[LIMITED_GA — requires Okta Identity Engine] Deactivate an authenticator
| Argument | Type | Description |
|---|---|---|
| authenticator_id | string | Path parameter: authenticator_id |
Resources
state— Authenticator resource state
authenticator_action— Authenticator action result
authenticators_aaguid.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| authenticator_id | string | Path scope for the authenticators aaguid: authenticator_id |
| attestationRootCertificates? | array | Contains the certificate and information about it |
| authenticatorCharacteristics? | object | Contains additional properties about custom AAGUID. |
| name? | string | The product name associated with this AAGUID. |
| aaguid? | string | An Authenticator Attestation Global Unique Identifier (AAGUID) is a 128-bit identifier indicating the model. |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a authenticators aaguid
fn get(id: string)
Get a authenticators aaguid
| Argument | Type | Description |
|---|---|---|
| id | string | The aaguid of the authenticators aaguid |
fn lookup(max_items?: number)
List authenticators aaguids and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update authenticators aaguid attributes
fn delete(id: string)
Delete the authenticators aaguid
| Argument | Type | Description |
|---|---|---|
| id | string | The aaguid of the authenticators aaguid |
fn sync()
Sync authenticators aaguid state from Okta
fn set_aaguid(aaguid: string, attestationRootCertificates?: array, authenticatorCharacteristics?: object, name?: string)
Update a custom AAGUID
| Argument | Type | Description |
|---|---|---|
| aaguid | string | Path parameter: aaguid |
| attestationRootCertificates? | array | Contains the certificate and information about it |
| authenticatorCharacteristics? | object | Contains additional properties about custom AAGUID. |
| name? | string | The product name associated with this AAGUID. |
Resources
state— Authenticators aaguid resource state
authenticators_aaguid_action— Authenticators aaguid action result
authenticators_method.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| authenticator_id | string | Path scope for the authenticators method: authenticator_id |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| status? | string | The status of the authenticator method |
| type? | enum | The type of authenticator method |
| _links? | object | Specifies link relations (see [Web Linking](https://www.rfc-editor.org/rfc/rfc8288)) available using the [JSON Hypertext Application Language](https://datatracker.ietf.org/doc/html/draft-kelly-json-hal-06) specification. This object is used for dynamic discovery of related resources and lifecycle op |
| settings? | object | The settings for the Passkey (FIDO2 WebAuthn) authenticator method |
| verifiableProperties? | array | |
| acceptableAdjacentIntervals? | number | The number of acceptable adjacent intervals, also known as the clock drift interval. This setting allows you to build in tolerance for any time difference between the token and the server. For example, with a `timeIntervalInSeconds` of 60 seconds and an `acceptableAdjacentIntervals` value of 5, Okta |
| algorithm? | enum | HMAC algorithm |
| encoding? | enum | The shared secret encoding |
| factorProfileId? | string | The `id` value of the factor profile |
| passCodeLength? | number | Number of digits in an OTP value |
| protocol? | enum | The protocol used |
| timeIntervalInSeconds? | number | Time interval for TOTP in seconds |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a authenticators method
| Argument | Type | Description |
|---|---|---|
| id | string | The type of the authenticators method |
fn lookup(max_items?: number)
List authenticators methods and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update authenticators method attributes
fn sync()
Sync authenticators method state from Okta
fn activate(method_type: string)
[LIMITED_GA — requires Okta Identity Engine] Activate an authenticator method
| Argument | Type | Description |
|---|---|---|
| method_type | string | Path parameter: method_type |
fn create_verify_rp_id_domain(web_authn_method_type: string)
[LIMITED_GA — requires Okta Identity Engine] Verify a Relying Party ID domain
| Argument | Type | Description |
|---|---|---|
| web_authn_method_type | string | Path parameter: web_authn_method_type |
fn deactivate(method_type: string)
[LIMITED_GA — requires Okta Identity Engine] Deactivate an authenticator method
| Argument | Type | Description |
|---|---|---|
| method_type | string | Path parameter: method_type |
Resources
state— Authenticators method resource state
authenticators_method_action— Authenticators method action result
authorization_server.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| accessTokenEncryptedResponseAlgorithm? | enum | The algorithm for encrypting access tokens issued by this authorization server. If this is requested, the response is signed, and then encrypted. The result is a nested JWT. The default, if omitted, is that no encryption is performed. |
| audiences? | array | The recipients that the tokens are intended for. This becomes the `aud` claim in an access token. Okta currently supports only one audience. |
| credentials? | object | |
| description? | string | The description of the custom authorization server |
| issuer? | string | The complete URL for the custom authorization server. This becomes the `iss` claim in an access token. |
| issuerMode? | string | Indicates which value is specified in the issuer of the tokens that a custom authorization server returns: the Okta org domain URL or a custom domain URL. `issuerMode` is visible if you have a custom URL domain configured or the Dynamic Issuer Mode feature enabled. If you have a custom URL domain co |
| jwks? | object | A [JSON Web Key Set](https://tools.ietf.org/html/rfc7517#section-5) for encrypting JWTs minted by the custom authorization server |
| jwks_uri? | string | URL string that references a JSON Web Key Set for encrypting JWTs minted by the custom authorization server |
| name? | string | The name of the custom authorization server |
| status? | enum | |
| _links? | object | Specifies link relations (see [Web Linking](https://www.rfc-editor.org/rfc/rfc8288)) available using the [JSON Hypertext Application Language](https://datatracker.ietf.org/doc/html/draft-kelly-json-hal-06) specification. This object is used for dynamic discovery of related resources and lifecycle op |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a authorization server
fn get(id: string)
Get a authorization server
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the authorization server |
fn lookup(q?: string, max_items?: number)
List authorization servers and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| q? | string | Searches the `name` and `audiences` of authorization servers for matching values |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update authorization server attributes
fn delete(id: string)
Delete the authorization server
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the authorization server |
fn sync()
Sync authorization server state from Okta
fn activate(auth_server_id: string)
Activate an authorization server
| Argument | Type | Description |
|---|---|---|
| auth_server_id | string | Path parameter: auth_server_id |
fn create_associated_servers(auth_server_id: string, trusted?: array)
Create an associated authorization server
| Argument | Type | Description |
|---|---|---|
| auth_server_id | string | Path parameter: auth_server_id |
| trusted? | array | A list of the authorization server IDs |
fn create_credentials_key_rotate(auth_server_id: string, use?: enum)
Rotate all credential keys
| Argument | Type | Description |
|---|---|---|
| auth_server_id | string | Path parameter: auth_server_id |
| use? | enum | Purpose of the certificate. The only supported value is `sig`. |
fn deactivate(auth_server_id: string)
Deactivate an authorization server
| Argument | Type | Description |
|---|---|---|
| auth_server_id | string | Path parameter: auth_server_id |
fn delete_associated_servers(auth_server_id: string, associated_server_id: string)
Delete an associated authorization server
| Argument | Type | Description |
|---|---|---|
| auth_server_id | string | Path parameter: auth_server_id |
| associated_server_id | string | Path parameter: associated_server_id |
fn list_associated_servers(auth_server_id: string)
List all associated authorization servers
| Argument | Type | Description |
|---|---|---|
| auth_server_id | string | Path parameter: auth_server_id |
fn list_clients(auth_server_id: string)
List all client resources for an authorization server
| Argument | Type | Description |
|---|---|---|
| auth_server_id | string | Path parameter: auth_server_id |
Resources
state— Authorization server resource state
authorization_server_action— Authorization server action result
authorization_server_resource_key.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| auth_server_id | string | Path scope for the authorization server resource key: auth_server_id |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| e? | string | RSA key value (exponent) for key binding |
| kid? | string | Unique identifier of the JSON web key in the custom authorization server's public JWKS |
| kty? | string | Cryptographic algorithm family for the certificate's key pair |
| n? | string | RSA key value (modulus) for key binding |
| status? | enum | Status of the JSON Web Key |
| use? | string | Acceptable use of the JSON Web Key |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a authorization server resource key
fn get(id: string)
Get a authorization server resource key
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the authorization server resource key |
fn lookup(max_items?: number)
List authorization server resource keys and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn delete(id: string)
Delete the authorization server resource key
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the authorization server resource key |
fn sync()
Sync authorization server resource key state from Okta
fn activate(key_id: string)
Activate a Custom Authorization Server Public JSON Web Key
| Argument | Type | Description |
|---|---|---|
| key_id | string | Path parameter: key_id |
fn deactivate(key_id: string)
Deactivate a Custom Authorization Server Public JSON Web Key
| Argument | Type | Description |
|---|---|---|
| key_id | string | Path parameter: key_id |
Resources
state— Authorization server resource key resource state
authorization_server_resource_key_action— Authorization server resource key action result
authorization_servers_claim.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| auth_server_id | string | Path scope for the authorization servers claim: auth_server_id |
| alwaysIncludeInToken? | boolean | Specifies whether to include Claims in the token. The value is always `TRUE` for access token Claims. If the value is set to `FALSE` for an ID token claim, the Claim isn't included in the ID token when the token is requested with the access token or with the `authorization_code`. The client instead |
| claimType? | enum | Specifies whether the Claim is for an access token (`RESOURCE`) or an ID token (`IDENTITY`) |
| conditions? | object | Specifies the scopes for the Claim |
| group_filter_type? | enum | Specifies the type of group filter if `valueType` is `GROUPS` If `valueType` is `GROUPS`, then the groups returned are filtered according to the value of `group_filter_type`. If you have complex filters for Groups, you can [create a Groups allowlist](https://developer.okta.com/docs/guides/customize- |
| name? | string | Name of the Claim |
| status? | enum | |
| system? | boolean | When `true`, indicates that Okta created the Claim |
| value? | string | Specifies the value of the Claim. This value must be a string literal if `valueType` is `GROUPS`, and the string literal is matched with the selected `group_filter_type`. The value must be an Okta EL expression if `valueType` is `EXPRESSION`. |
| valueType? | enum | Specifies whether the Claim is an Okta Expression Language (EL) expression (`EXPRESSION`), a set of groups (`GROUPS`), or a system claim (`SYSTEM`) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a authorization servers claim
fn get(id: string)
Get a authorization servers claim
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the authorization servers claim |
fn lookup(max_items?: number)
List authorization servers claims and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update authorization servers claim attributes
fn delete(id: string)
Delete the authorization servers claim
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the authorization servers claim |
fn sync()
Sync authorization servers claim state from Okta
authorization_servers_clients_token.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| auth_server_id | string | Path scope for the authorization servers clients token: auth_server_id |
| client_id | string | Path scope for the authorization servers clients token: client_id |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a authorization servers clients token
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the authorization servers clients token |
fn lookup(expand?: string, max_items?: number)
List authorization servers clients tokens and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| expand? | string | Valid value: `scope`. If specified, scope details are included in the `_embedded` attribute. |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn delete(id: string)
Delete the authorization servers clients token
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the authorization servers clients token |
fn sync()
Sync authorization servers clients token state from Okta
authorization_servers_credentials_key.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| auth_server_id | string | Path scope for the authorization servers credentials key: auth_server_id |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a authorization servers credentials key
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the authorization servers credentials key |
fn lookup(max_items?: number)
List authorization servers credentials keys and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn sync()
Sync authorization servers credentials key state from Okta
authorization_servers_policies_rule.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| auth_server_id | string | Path scope for the authorization servers policies rule: auth_server_id |
| policy_id | string | Path scope for the authorization servers policies rule: policy_id |
| actions? | object | |
| conditions? | object | |
| name | string | Name of the rule |
| priority? | number | Priority of the rule |
| status? | enum | Status of the rule |
| system? | boolean | Set to `true` for system rules. You can't delete system rules. |
| type | enum | Rule type |
| _links? | object | Specifies link relations (see [Web Linking](https://www.rfc-editor.org/rfc/rfc8288)) available using the [JSON Hypertext Application Language](https://datatracker.ietf.org/doc/html/draft-kelly-json-hal-06) specification. This object is used for dynamic discovery of related resources and lifecycle op |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a authorization servers policies rule
fn get(id: string)
Get a authorization servers policies rule
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the authorization servers policies rule |
fn lookup(max_items?: number)
List authorization servers policies rules and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update authorization servers policies rule attributes
fn delete(id: string)
Delete the authorization servers policies rule
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the authorization servers policies rule |
fn sync()
Sync authorization servers policies rule state from Okta
fn activate(rule_id: string)
Activate a policy rule
| Argument | Type | Description |
|---|---|---|
| rule_id | string | Path parameter: rule_id |
fn deactivate(rule_id: string)
Deactivate a policy rule
| Argument | Type | Description |
|---|---|---|
| rule_id | string | Path parameter: rule_id |
Resources
state— Authorization servers policies rule resource state
authorization_servers_policies_rule_action— Authorization servers policies rule action result
authorization_servers_policy.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| auth_server_id | string | Path scope for the authorization servers policy: auth_server_id |
| id? | string | ID of the Policy |
| type? | enum | Indicates that the Policy is an authorization server Policy |
| name? | string | Name of the Policy |
| conditions? | object | |
| description? | string | Description of the Policy |
| priority? | number | Specifies the order in which this Policy is evaluated in relation to the other Policies in a custom authorization server |
| status? | enum | Specifies whether requests have access to this Policy |
| system? | boolean | Specifies whether Okta created this Policy |
| _links? | object | Specifies link relations (see [Web Linking](https://www.rfc-editor.org/rfc/rfc8288)) available using the [JSON Hypertext Application Language](https://datatracker.ietf.org/doc/html/draft-kelly-json-hal-06) specification. This object is used for dynamic discovery of related resources and lifecycle op |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a authorization servers policy
fn get(id: string)
Get a authorization servers policy
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the authorization servers policy |
fn lookup(max_items?: number)
List authorization servers policys and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update authorization servers policy attributes
fn delete(id: string)
Delete the authorization servers policy
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the authorization servers policy |
fn sync()
Sync authorization servers policy state from Okta
fn activate(policy_id: string)
Activate a policy
| Argument | Type | Description |
|---|---|---|
| policy_id | string | Path parameter: policy_id |
fn deactivate(policy_id: string)
Deactivate a policy
| Argument | Type | Description |
|---|---|---|
| policy_id | string | Path parameter: policy_id |
Resources
state— Authorization servers policy resource state
authorization_servers_policy_action— Authorization servers policy action result
authorization_servers_scope.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| auth_server_id | string | Path scope for the authorization servers scope: auth_server_id |
| consent? | enum | Indicates whether a consent dialog is needed for the Scope |
| default? | boolean | Indicates if this Scope is a default scope |
| description? | string | Description of the Scope |
| displayName? | string | Name of the end user displayed in a consent dialog |
| metadataPublish? | enum | Indicates whether the Scope is included in the metadata |
| name | string | Scope name |
| optional? | boolean | Indicates whether the Scope is optional. When set to `true`, the user can skip consent for the scope. |
| system? | boolean | Indicates if Okta created the Scope |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a authorization servers scope
fn get(id: string)
Get a authorization servers scope
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the authorization servers scope |
fn lookup(q?: string, filter?: string, max_items?: number)
List authorization servers scopes and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| q? | string | Searches the `name` of Custom Token Scopes for matching values |
| filter? | string | Filter expression for Custom Token Scopes |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update authorization servers scope attributes
fn delete(id: string)
Delete the authorization servers scope
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the authorization servers scope |
fn sync()
Sync authorization servers scope state from Okta
brand.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| agreeToCustomPrivacyPolicy? | boolean | Consent for updating the custom privacy URL. Not required when resetting the URL. |
| customPrivacyPolicyUrl? | string | Custom privacy policy URL |
| defaultApp? | object | |
| emailDomainId? | string | The ID of the email domain |
| locale? | string | The language specified as an [IETF BCP 47 language tag](https://datatracker.ietf.org/doc/html/rfc5646) |
| name | string | The name of the brand > **Note:** You can't use the reserved `DRAPP_DOMAIN_BRAND` name. |
| removePoweredByOkta? | boolean | Removes "Powered by Okta" from the sign-in page in redirect authentication deployments, and "© [current year] Okta, Inc." from the Okta End-User Dashboard |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a brand
fn get(id: string)
Get a brand
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the brand |
fn lookup(expand?: string, q?: string, max_items?: number)
List brands and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| expand? | string | Specifies additional metadata to be included in the response |
| q? | string | Searches the records for matching value |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update brand attributes
fn delete(id: string)
Delete the brand
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the brand |
fn sync()
Sync brand state from Okta
fn delete_pages_error_customized(brand_id: string)
Delete the customized error page
| Argument | Type | Description |
|---|---|---|
| brand_id | string | Path parameter: brand_id |
fn delete_pages_error_preview(brand_id: string)
Delete the preview error page
| Argument | Type | Description |
|---|---|---|
| brand_id | string | Path parameter: brand_id |
fn delete_pages_sign_in_customized(brand_id: string)
Delete the customized sign-in page
| Argument | Type | Description |
|---|---|---|
| brand_id | string | Path parameter: brand_id |
fn delete_pages_sign_in_preview(brand_id: string)
Delete the preview sign-in page
| Argument | Type | Description |
|---|---|---|
| brand_id | string | Path parameter: brand_id |
fn get_domains(brand_id: string)
List all domains associated with a brand
| Argument | Type | Description |
|---|---|---|
| brand_id | string | Path parameter: brand_id |
fn get_pages_error(brand_id: string)
Retrieve the error page sub-resources
| Argument | Type | Description |
|---|---|---|
| brand_id | string | Path parameter: brand_id |
fn get_pages_error_customized(brand_id: string)
Retrieve the customized error page
| Argument | Type | Description |
|---|---|---|
| brand_id | string | Path parameter: brand_id |
fn get_pages_error_default(brand_id: string)
Retrieve the default error page
| Argument | Type | Description |
|---|---|---|
| brand_id | string | Path parameter: brand_id |
fn get_pages_sign_in(brand_id: string)
Retrieve the sign-in page sub-resources
| Argument | Type | Description |
|---|---|---|
| brand_id | string | Path parameter: brand_id |
fn get_pages_sign_in_customized(brand_id: string)
Retrieve the customized sign-in page
| Argument | Type | Description |
|---|---|---|
| brand_id | string | Path parameter: brand_id |
fn get_pages_sign_in_default(brand_id: string)
Retrieve the default sign-in page
| Argument | Type | Description |
|---|---|---|
| brand_id | string | Path parameter: brand_id |
fn get_pages_sign_out_customized(brand_id: string)
Retrieve the sign-out page settings
| Argument | Type | Description |
|---|---|---|
| brand_id | string | Path parameter: brand_id |
fn list_pages_sign_in_widget_versions(brand_id: string)
List all Sign-In Widget versions
| Argument | Type | Description |
|---|---|---|
| brand_id | string | Path parameter: brand_id |
fn pages_error_preview(brand_id: string)
Retrieve the preview error page preview
| Argument | Type | Description |
|---|---|---|
| brand_id | string | Path parameter: brand_id |
fn pages_sign_in_preview(brand_id: string)
Retrieve the preview sign-in page preview
| Argument | Type | Description |
|---|---|---|
| brand_id | string | Path parameter: brand_id |
fn update_pages_error_customized(brand_id: string, pageContent?: string, contentSecurityPolicySetting?: object)
Replace the customized error page
| Argument | Type | Description |
|---|---|---|
| brand_id | string | Path parameter: brand_id |
| pageContent? | string | The HTML for the page |
| contentSecurityPolicySetting? | object |
fn update_pages_sign_in_customized(brand_id: string, pageContent?: string, contentSecurityPolicySetting?: object, widgetCustomizations?: object, widgetVersion?: string)
Replace the customized sign-in page
| Argument | Type | Description |
|---|---|---|
| brand_id | string | Path parameter: brand_id |
| pageContent? | string | The HTML for the page |
| contentSecurityPolicySetting? | object | |
| widgetCustomizations? | object | |
| widgetVersion? | string | The version specified as a [Semantic Version](https://semver.org/). This value can be a wildcard (`*`), a major version range (for example, `^2`), a major-only version (for example, `7`), or a specific `Major.Minor` version (for example, `5.15`). |
fn update_pages_sign_out_customized(brand_id: string, type: enum, url?: string)
Replace the sign-out page settings
| Argument | Type | Description |
|---|---|---|
| brand_id | string | Path parameter: brand_id |
| type | enum | |
| url? | string |
Resources
state— Brand resource state
brand_action— Brand action result
brand_well_known_uri.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| brand_id | string | Path scope for the brand well known uri: brand_id |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a brand well known uri
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the brand well known uri |
fn lookup(max_items?: number)
List brand well known uris and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn sync()
Sync brand well known uri state from Okta
fn get_customized(path: string)
[LIMITED_GA — requires Okta Identity Engine] Retrieve the customized content of the specified well-known URI
| Argument | Type | Description |
|---|---|---|
| path | string | Path parameter: path |
fn update_customized(path: string, representation: record)
[LIMITED_GA — requires Okta Identity Engine] Replace the customized well-known URI of the specific path
| Argument | Type | Description |
|---|---|---|
| path | string | Path parameter: path |
| representation | record | The well-known URI content in JSON object format |
Resources
state— Brand well known uri resource state
brand_well_known_uri_action— Brand well known uri action result
brands_theme.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| brand_id | string | Path scope for the brands theme: brand_id |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| emailTemplateTouchPointVariant | enum | Variant for email templates. You can publish a theme for email templates with different combinations of assets. Variants are preset combinations of those assets. |
| endUserDashboardTouchPointVariant | enum | Variant for the Okta End-User Dashboard. You can publish a theme for end-user dashboard with different combinations of assets. Variants are preset combinations of those assets. |
| errorPageTouchPointVariant | enum | Variant for the error page. You can publish a theme for error page with different combinations of assets. Variants are preset combinations of those assets. |
| loadingPageTouchPointVariant? | enum | Variant for the Okta loading page. You can publish a theme for Okta loading page with different combinations of assets. Variants are preset combinations of those assets. |
| primaryColorContrastHex? | string | Primary color contrast hex code |
| primaryColorHex | string | Primary color hex code |
| secondaryColorContrastHex? | string | Secondary color contrast hex code |
| secondaryColorHex | string | Secondary color hex code |
| signInPageTouchPointVariant | enum | Variant for the Okta sign-in page. You can publish a theme for sign-in page with different combinations of assets. Variants are preset combinations of those assets. > **Note:** For a non-`OKTA_DEFAULT` variant, `primaryColorHex` is used for button background color and `primaryColorContrastHex` is us |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a brands theme
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the brands theme |
fn lookup(max_items?: number)
List brands themes and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update brands theme attributes
fn sync()
Sync brands theme state from Okta
fn create_background_image(theme_id: string, file: string)
Upload the background image
| Argument | Type | Description |
|---|---|---|
| theme_id | string | Path parameter: theme_id |
| file | string |
fn create_favicon(theme_id: string, file: string)
Upload the favicon
| Argument | Type | Description |
|---|---|---|
| theme_id | string | Path parameter: theme_id |
| file | string |
fn create_logo(theme_id: string, file: string)
Upload the logo
| Argument | Type | Description |
|---|---|---|
| theme_id | string | Path parameter: theme_id |
| file | string |
fn delete_background_image(theme_id: string)
Delete the background image
| Argument | Type | Description |
|---|---|---|
| theme_id | string | Path parameter: theme_id |
fn delete_favicon(theme_id: string)
Delete the favicon
| Argument | Type | Description |
|---|---|---|
| theme_id | string | Path parameter: theme_id |
fn delete_logo(theme_id: string)
Delete the logo
| Argument | Type | Description |
|---|---|---|
| theme_id | string | Path parameter: theme_id |
Resources
state— Brands theme resource state
brands_theme_action— Brands theme action result
custom_domain.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| brandId? | string | The `id` of the brand used to replace the existing brand. |
| certificateSourceType | enum | Certificate source type that indicates whether the certificate is provided by the user or Okta. |
| domain | string | Custom domain name > **Note:** You can't use the reserved `drapp.{yourOrgSubDomain}.okta.com` domain. |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a custom domain
fn get(id: string)
Get a custom domain
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the custom domain |
fn lookup(max_items?: number)
List custom domains and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update custom domain attributes
fn delete(id: string)
Delete the custom domain
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the custom domain |
fn sync()
Sync custom domain state from Okta
fn update_certificate(domain_id: string, certificate: string, certificateChain: string, privateKey: string, type: enum)
Upsert the custom domain
| Argument | Type | Description |
|---|---|---|
| domain_id | string | Path parameter: domain_id |
| certificate | string | Certificate content |
| certificateChain | string | Certificate chain |
| privateKey | string | Certificate private key |
| type | enum | Certificate type |
fn verify(domain_id: string)
Verify a custom domain
| Argument | Type | Description |
|---|---|---|
| domain_id | string | Path parameter: domain_id |
Resources
state— Custom domain resource state
custom_domain_action— Custom domain action result
email_bounce_removal.tsv2026.08.25.1
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| emailAddresses? | array | A list of email addresses to remove from the email-service bounce list |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a email bounce removal
email_customization.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| brand_id | string | Path scope for the email customization: brand_id |
| template_name | string | Path scope for the email customization: template_name |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| body | string | The HTML body of the email. May contain [variable references](https://velocity.apache.org/engine/1.7/user-guide.html#references). <x-lifecycle class="ea"></x-lifecycle> Not required if Custom languages for Okta Email Templates is enabled. A `null` body is replaced with a default value from one of th |
| subject | string | The email subject. May contain [variable references](https://velocity.apache.org/engine/1.7/user-guide.html#references). <x-lifecycle class="ea"></x-lifecycle> Not required if Custom languages for Okta Email Templates is enabled. A `null` subject is replaced with a default value from one of the foll |
| isDefault? | boolean | Whether this is the default customization for the email template. Each customized email template must have exactly one default customization. Defaults to `true` for the first customization and `false` thereafter. |
| language | string | The language specified as an [IETF BCP 47 language tag](https://datatracker.ietf.org/doc/html/rfc5646) |
| _links? | object | Specifies link relations (see [Web Linking](https://www.rfc-editor.org/rfc/rfc8288)) available using the [JSON Hypertext Application Language](https://datatracker.ietf.org/doc/html/draft-kelly-json-hal-06) specification. This object is used for dynamic discovery of related resources and lifecycle op |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a email customization
fn get(id: string)
Get a email customization
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the email customization |
fn lookup(max_items?: number)
List email customizations and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update email customization attributes
fn delete(id: string)
Delete the email customization
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the email customization |
fn sync()
Sync email customization state from Okta
fn preview(customization_id: string)
Retrieve a preview of an email customization
| Argument | Type | Description |
|---|---|---|
| customization_id | string | Path parameter: customization_id |
Resources
state— Email customization resource state
email_customization_action— Email customization action result
email_domain.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| displayName | string | |
| userName | string | |
| brandId | string | |
| domain | string | |
| validationSubdomain? | string | Subdomain for the email sender's custom mail domain. Specify your subdomain when you configure a custom mail domain. |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a email domain
fn get(id: string)
Get a email domain
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the email domain |
fn lookup(max_items?: number)
List email domains and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update email domain attributes
fn delete(id: string)
Delete the email domain
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the email domain |
fn sync()
Sync email domain state from Okta
fn verify(email_domain_id: string)
Verify an email domain
| Argument | Type | Description |
|---|---|---|
| email_domain_id | string | Path parameter: email_domain_id |
Resources
state— Email domain resource state
email_domain_action— Email domain action result
email_server.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| alias | string | Human-readable name for your SMTP server |
| authType | enum | <x-lifecycle-container><x-lifecycle class="ea"></x-lifecycle> <x-lifecycle class="oie"></x-lifecycle></x-lifecycle-container>The authentication type that\'s used by your SMTP server |
| enabled | boolean | If `true`, all email traffic is routed through your SMTP server |
| host | string | Hostname or IP address of your SMTP server |
| port | number | Port number of your SMTP server |
| username | string | Username that's used to access your SMTP server |
| password? | string | The password of the user account that's used to sign in to your SMTP server |
| clientId? | string | The client ID that's used to access your SMTP server. This client ID is obtained when you create an OAuth 2.0 app with your email provider. |
| clientSecret? | string | The client secret that's used to access your SMTP server. This client secret is obtained when you create an OAuth 2.0 app with your email provider. |
| scopes? | array | List of OAuth 2.0 scopes for your SMTP server. You must provide a scope that allows your email server to send emails. |
| tokenEndpoint? | string | The email provider's specific URL where the OAuth 2.0 app sends its credentials (or signed JWT) to exchange them for an access token |
| tokenEndpointAuthMethod? | enum | This method determines how your OAuth 2.0 app sends its credentials (`client_id` and `client_secret`) to the provider's server when requesting an access token. |
| audience? | string | The URI of the authorization server that verifies the token. This is typically the token URI of your JWT. |
| issuer? | string | The unique ID of the entity that creates the JWT. This can sometimes be the email address of the user who creates the JWT. Check with your email provider for the correct value. |
| keyId? | string | The ID of the private key that's used to sign the JWT |
| privateKey? | string | The secret RSA key that's used to cryptographically sign the JWT |
| signingAlgorithm? | enum | The signing algorithm that's used to sign the JWT |
| subject? | string | The email address of the user account that the OAuth 2.0 app impersonates to send emails |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a email server
fn get(id: string)
Get a email server
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the email server |
fn lookup(max_items?: number)
List email servers and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update email server attributes
fn delete(id: string)
Delete the email server
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the email server |
fn sync()
Sync email server state from Okta
fn test(email_server_id: string, fromAddress: string, toAddress: string)
Test an SMTP server configuration
| Argument | Type | Description |
|---|---|---|
| email_server_id | string | Path parameter: email_server_id |
| fromAddress | string | Email address that sends test emails |
| toAddress | string | Email address that receives test emails |
Resources
state— Email server resource state
email_server_action— Email server action result
email_template.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| brand_id | string | Path scope for the email template: brand_id |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a email template
| Argument | Type | Description |
|---|---|---|
| id | string | The name of the email template |
fn lookup(expand?: string, max_items?: number)
List email templates and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| expand? | string | Specifies additional metadata to be included in the response |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn sync()
Sync email template state from Okta
fn default_content_preview(template_name: string)
Retrieve a preview of the email template default content
| Argument | Type | Description |
|---|---|---|
| template_name | string | Path parameter: template_name |
fn get_default_content(template_name: string)
Retrieve an email template default content
| Argument | Type | Description |
|---|---|---|
| template_name | string | Path parameter: template_name |
fn get_settings(template_name: string)
Retrieve the email template settings
| Argument | Type | Description |
|---|---|---|
| template_name | string | Path parameter: template_name |
fn test(template_name: string)
Send a test email
| Argument | Type | Description |
|---|---|---|
| template_name | string | Path parameter: template_name |
fn update_settings(template_name: string, recipients: enum)
Replace the email template settings
| Argument | Type | Description |
|---|---|---|
| template_name | string | Path parameter: template_name |
| recipients | enum |
Resources
state— Email template resource state
email_template_action— Email template action result
event_hook.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| channel? | object | |
| description? | string | Description of the event hook |
| events? | object | |
| name | string | Display name for the event hook |
| _links? | object | Specifies link relations (see [Web Linking](https://www.rfc-editor.org/rfc/rfc8288)) available using the [JSON Hypertext Application Language](https://datatracker.ietf.org/doc/html/draft-kelly-json-hal-06) specification. This object is used for dynamic discovery of related resources and lifecycle op |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a event hook
fn get(id: string)
Get a event hook
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the event hook |
fn lookup(max_items?: number)
List event hooks and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update event hook attributes
fn delete(id: string)
Delete the event hook
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the event hook |
fn sync()
Sync event hook state from Okta
fn activate(event_hook_id: string)
Activate an event hook
| Argument | Type | Description |
|---|---|---|
| event_hook_id | string | Path parameter: event_hook_id |
fn deactivate(event_hook_id: string)
Deactivate an event hook
| Argument | Type | Description |
|---|---|---|
| event_hook_id | string | Path parameter: event_hook_id |
fn verify(event_hook_id: string)
Verify an event hook
| Argument | Type | Description |
|---|---|---|
| event_hook_id | string | Path parameter: event_hook_id |
Resources
state— Event hook resource state
event_hook_action— Event hook action result
group.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| profile? | object | Profile for any group that is not imported from Active Directory. Specifies the standard and custom profile properties for a group. The `objectClass` for these groups is `okta:user_group`. You can extend group profiles with custom properties, but you must first add the properties to the group profil |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a group
fn get(id: string)
Get a group
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the group |
fn lookup(search?: string, filter?: string, q?: string, expand?: string, sortBy?: string, sortOrder?: string, max_items?: number)
List groups and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| search? | string | Searches for groups with a supported [filtering](https://developer.okta.com/docs/api/#filter) expression for all properties except for `_embedded`, `_links`, and `objectClass`. Okta recommends this query parameter because it provides the largest range of search options and optimal performance. This |
| filter? | string | Filter expression for groups. See [Filter](https://developer.okta.com/docs/api/#filter). Filtering supports the following limited number of properties: `id`, `type`, `lastUpdated`, and `lastMembershipUpdated`. > **Note:** All filters must be [URL encoded](https://developer.mozilla.org/en-US/docs/Glo |
| q? | string | Finds a group that matches the `name` property. > **Note:** Paging and searching are currently mutually exclusive. You can't page a query. The default limit for a query is 300 results. Query is intended for an auto-complete picker use case where users refine their search string to constrain the resu |
| expand? | string | If specified, additional metadata is included in the response. Possible values are `stats` and `app`. This additional metadata is listed in the [`_embedded`](https://developer.okta.com/docs/api/openapi/okta-management/management/tag/Group/#tag/Group/operation/addGroup!c=200&path=_embedded&t=response |
| sortBy? | string | Specifies the field to sort by (for search queries only). `sortBy` can be any single property, for example `sortBy=profile.name`. Groups with the same value for the `sortBy` property are ordered by `id`'. Use with `sortOrder` to control the order of results. |
| sortOrder? | string | Specifies sort order: `asc` or `desc` (for search queries only). This parameter is ignored if `sortBy` isn't present. |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update group attributes
fn delete(id: string)
Delete the group
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the group |
fn sync()
Sync group state from Okta
fn create_owners(group_id: string, id?: string, type?: enum)
Assign a group owner
| Argument | Type | Description |
|---|---|---|
| group_id | string | Path parameter: group_id |
| id? | string | The `id` of the group owner |
| type? | enum | The entity type of the owner |
fn delete_owners(group_id: string, owner_id: string)
Delete a group owner
| Argument | Type | Description |
|---|---|---|
| group_id | string | Path parameter: group_id |
| owner_id | string | Path parameter: owner_id |
fn delete_users(group_id: string, user_id: string)
Unassign a user from a group
| Argument | Type | Description |
|---|---|---|
| group_id | string | Path parameter: group_id |
| user_id | string | Path parameter: user_id |
fn list_apps(group_id: string)
List all assigned apps
| Argument | Type | Description |
|---|---|---|
| group_id | string | Path parameter: group_id |
fn list_owners(group_id: string)
List all group owners
| Argument | Type | Description |
|---|---|---|
| group_id | string | Path parameter: group_id |
fn list_users(group_id: string)
List all member users
| Argument | Type | Description |
|---|---|---|
| group_id | string | Path parameter: group_id |
fn update_users(group_id: string, user_id: string)
Assign a user to a group
| Argument | Type | Description |
|---|---|---|
| group_id | string | Path parameter: group_id |
| user_id | string | Path parameter: user_id |
Resources
state— Group resource state
group_action— Group action result
group_schema.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| definitions? | object | |
| description? | string | Description for the schema |
| properties? | object | Group object properties |
| title? | string | User-defined display name for the schema |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a group schema
fn lookup(max_items?: number)
List group schemas and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
groups_rule.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| actions? | object | Defines which users and groups to assign |
| conditions? | object | Defines group rule conditions |
| name? | string | Name of the group rule |
| status? | enum | Status of group rule. You can't update the status of a rule from `INACTIVE` to `ACTIVE`. You must use the activate and deactivate lifecycle operations. |
| type? | enum | |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a groups rule
fn get(id: string)
Get a groups rule
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the groups rule |
fn lookup(search?: string, expand?: enum, max_items?: number)
List groups rules and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| search? | string | Specifies the keyword to search rules for |
| expand? | enum | If specified, returns the mapping of group IDs to group names in the `_embedded` object. |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update groups rule attributes
fn delete(id: string)
Delete the groups rule
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the groups rule |
fn sync()
Sync groups rule state from Okta
fn activate(group_rule_id: string)
Activate a group rule
| Argument | Type | Description |
|---|---|---|
| group_rule_id | string | Path parameter: group_rule_id |
fn deactivate(group_rule_id: string)
Deactivate a group rule
| Argument | Type | Description |
|---|---|---|
| group_rule_id | string | Path parameter: group_rule_id |
Resources
state— Groups rule resource state
groups_rule_action— Groups rule action result
hook_key.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name? | string | Display name for the key |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a hook key
fn get(id: string)
Get a hook key
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the hook key |
fn lookup(max_items?: number)
List hook keys and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update hook key attributes
fn delete(id: string)
Delete the hook key
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the hook key |
fn sync()
Sync hook key state from Okta
hook_key_public.tsv2026.08.25.1
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a hook key public
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the hook key public |
fn sync()
Sync hook key public state from Okta
identity_provider.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| issuerMode? | enum | Indicates whether Okta uses the original Okta org domain URL or a custom domain URL in the request to the social IdP |
| name? | string | Unique name for the IdP |
| policy? | object | Policy settings for the IdP. The following provisioning and account linking actions are supported by each IdP provider: | IdP type | User provisioning actions | Group provisioning actions | Account link actions | Account link filters | | -------------------------------------------------------------- |
| properties? | object | The properties in the IdP `properties` object vary depending on the IdP type |
| protocol? | object | IdP-specific protocol settings for endpoints, bindings, and algorithms used to connect with the IdP and validate messages |
| status? | enum | |
| type? | enum | The IdP object's `type` property identifies the social or enterprise IdP used for authentication. Each IdP uses a specific protocol, therefore the `protocol` object must correspond with the IdP `type`. If the protocol is OAuth 2.0-based, the `protocol` object's `scopes` property must also correspond |
| _links? | object | Specifies link relations (see [Web Linking](https://www.rfc-editor.org/rfc/rfc8288)) available using the [JSON Hypertext Application Language](https://datatracker.ietf.org/doc/html/draft-kelly-json-hal-06) specification. This object is used for dynamic discovery of related resources and lifecycle op |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a identity provider
fn get(id: string)
Get a identity provider
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the identity provider |
fn lookup(q?: string, type?: enum, max_items?: number)
List identity providers and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| q? | string | Searches the `name` property of IdPs for matching value |
| type? | enum | Filters IdPs by `type` |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update identity provider attributes
fn delete(id: string)
Delete the identity provider
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the identity provider |
fn sync()
Sync identity provider state from Okta
fn activate(idp_id: string)
Activate an IdP
| Argument | Type | Description |
|---|---|---|
| idp_id | string | Path parameter: idp_id |
fn deactivate(idp_id: string)
Deactivate an IdP
| Argument | Type | Description |
|---|---|---|
| idp_id | string | Path parameter: idp_id |
Resources
state— Identity provider resource state
identity_provider_action— Identity provider action result
identity_sources_group.tsv2026.08.25.1
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| identity_source_id | string | Path scope for the identity sources group: identity_source_id |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| externalId? | string | The external ID of the identity source group to be created |
| profile? | object | Contains a set of external group attributes and their values that are mapped to Okta standard properties. See the group [`profile` object](https://developer.okta.com/docs/api/openapi/okta-management/management/tag/Group/#tag/Group/operation/getGroup!c=200&path=profile&t=response) and Declaration of |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a identity sources group
fn get(id: string)
Get a identity sources group
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the identity sources group |
fn update()
Update identity sources group attributes
fn delete(id: string)
Delete the identity sources group
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the identity sources group |
fn sync()
Sync identity sources group state from Okta
fn create_membership(group_or_external_id: string, memberExternalId?: string)
Create the memberships for the given identity source group
| Argument | Type | Description |
|---|---|---|
| group_or_external_id | string | Path parameter: group_or_external_id |
| memberExternalId? | string | The external ID of the user to be added as a member of the group in Okta |
fn delete_membership(group_or_external_id: string, member_external_id: string)
Delete the memberships for the specified identity source group
| Argument | Type | Description |
|---|---|---|
| group_or_external_id | string | Path parameter: group_or_external_id |
| member_external_id | string | Path parameter: member_external_id |
fn get_membership(group_or_external_id: string)
Retrieve the memberships for the given identity source group
| Argument | Type | Description |
|---|---|---|
| group_or_external_id | string | Path parameter: group_or_external_id |
Resources
state— Identity sources group resource state
identity_sources_group_action— Identity sources group action result
identity_sources_session.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| identity_source_id | string | Path scope for the identity sources session: identity_source_id |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a identity sources session
fn get(id: string)
Get a identity sources session
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the identity sources session |
fn lookup(max_items?: number)
List identity sources sessions and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn delete(id: string)
Delete the identity sources session
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the identity sources session |
fn sync()
Sync identity sources session state from Okta
fn create_bulk_delete(session_id: string, entityType?: enum, profiles?: array)
Upload the data to be deleted in Okta
| Argument | Type | Description |
|---|---|---|
| session_id | string | Path parameter: session_id |
| entityType? | enum | The type of data to bulk delete in a session. Currently, only `USERS` is supported. |
| profiles? | array | Array of profiles to be deleted |
fn create_bulk_group_memberships_delete(session_id: string, memberships?: array)
Upload the group memberships to be deleted in Okta
| Argument | Type | Description |
|---|---|---|
| session_id | string | Path parameter: session_id |
| memberships? | array | Array of group memberships that need to be deleted in Okta |
fn create_bulk_group_memberships_upsert(session_id: string, memberships?: array)
Upload the group memberships to be upserted in Okta
| Argument | Type | Description |
|---|---|---|
| session_id | string | Path parameter: session_id |
| memberships? | array | Array of group memberships that need to be inserted or updated in Okta |
fn create_bulk_groups_delete(session_id: string, externalIds?: array)
Upload the group external IDs to be deleted in Okta
| Argument | Type | Description |
|---|---|---|
| session_id | string | Path parameter: session_id |
| externalIds? | array | Array of external IDs of groups that need to be deleted in Okta |
fn create_bulk_groups_upsert(session_id: string, profiles?: array)
Upload the group profiles without memberships to be upserted in Okta
| Argument | Type | Description |
|---|---|---|
| session_id | string | Path parameter: session_id |
| profiles? | array | Array of group profiles that needs to be inserted or updated in Okta |
fn create_bulk_upsert(session_id: string, entityType?: enum, profiles?: array)
Upload the data to be upserted in Okta
| Argument | Type | Description |
|---|---|---|
| session_id | string | Path parameter: session_id |
| entityType? | enum | The type of data to upsert into the session. Currently, only `USERS` is supported. |
| profiles? | array | Array of user profiles to be uploaded |
fn create_start_import(session_id: string)
Start the import from the identity source
| Argument | Type | Description |
|---|---|---|
| session_id | string | Path parameter: session_id |
Resources
state— Identity sources session resource state
identity_sources_session_action— Identity sources session action result
identity_sources_user.tsv2026.08.25.1
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| identity_source_id | string | Path scope for the identity sources user: identity_source_id |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| externalId? | string | The external ID of the user in the identity source |
| profile? | object | Contains a set of external user attributes and their values that are mapped to Okta standard and custom profile properties. See the [`profile` object](https://developer.okta.com/docs/api/openapi/okta-management/management/user/getuser#user/getuser/t=response&c=200&path=profile) and Declaration of a |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a identity sources user
fn get(id: string)
Get a identity sources user
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the identity sources user |
fn update()
Update identity sources user attributes
fn delete(id: string)
Delete the identity sources user
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the identity sources user |
fn sync()
Sync identity sources user state from Okta
fn set_external_id(external_id: string, profile?: object)
Update an identity source user
| Argument | Type | Description |
|---|---|---|
| external_id | string | Path parameter: external_id |
| profile? | object | Contains a set of external user attributes and their values that are mapped to Okta standard and custom profile properties. See the [`profile` object](https://developer.okta.com/docs/api/openapi/okta-management/management/user/getuser#user/getuser/t=response&c=200&path=profile) and Declaration of a |
Resources
state— Identity sources user resource state
identity_sources_user_action— Identity sources user action result
idps_credentials_csr.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| idp_id | string | Path scope for the idps credentials csr: idp_id |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| subject? | object | |
| subjectAltNames? | object | |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a idps credentials csr
fn get(id: string)
Get a idps credentials csr
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the idps credentials csr |
fn lookup(max_items?: number)
List idps credentials csrs and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn delete(id: string)
Delete the idps credentials csr
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the idps credentials csr |
fn sync()
Sync idps credentials csr state from Okta
fn publish(idp_csr_id: string, certificate: string)
Publish a certificate signing request
| Argument | Type | Description |
|---|---|---|
| idp_csr_id | string | Path parameter: idp_csr_id |
| certificate | string | Raw certificate body, in the format named by the endpoint's content type |
Resources
state— Idps credentials csr resource state
idps_credentials_csr_action— Idps credentials csr action result
idps_credentials_key.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| idp_id | string | Path scope for the idps credentials key: idp_id |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a idps credentials key
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the idps credentials key |
fn lookup(max_items?: number)
List idps credentials keys and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn sync()
Sync idps credentials key state from Okta
fn clone(kid: string)
Clone a signing key credential for IdP
| Argument | Type | Description |
|---|---|---|
| kid | string | Path parameter: kid |
fn create_generate()
Generate a new signing key credential for IdP
fn list_active()
List the active signing key credential for IdP
Resources
state— Idps credentials key resource state
idps_credentials_key_action— Idps credentials key action result
idps_user.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| idp_id | string | Path scope for the idps user: idp_id |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| externalId? | string | Unique IdP-specific identifier for a user |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a idps user
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the idps user |
fn lookup(q?: string, expand?: string, max_items?: number)
List idps users and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| q? | string | Searches the records for matching value |
| expand? | string | Expand user data |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update idps user attributes
fn delete(id: string)
Delete the idps user
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the idps user |
fn sync()
Sync idps user state from Okta
fn list_credentials_tokens(user_id: string)
List all tokens from OIDC IdP
| Argument | Type | Description |
|---|---|---|
| user_id | string | Path parameter: user_id |
Resources
state— Idps user resource state
idps_user_action— Idps user action result
inline_hook.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| channel? | object | |
| name? | string | The display name of the inline hook |
| version? | string | Version of the inline hook type. The currently supported version is `1.0.0`. |
| type? | enum | One of the inline hook types |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a inline hook
fn get(id: string)
Get a inline hook
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the inline hook |
fn lookup(type?: enum, max_items?: number)
List inline hooks and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| type? | enum | One of the supported inline hook types |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update inline hook attributes
fn delete(id: string)
Delete the inline hook
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the inline hook |
fn sync()
Sync inline hook state from Okta
fn activate(inline_hook_id: string)
Activate an inline hook
| Argument | Type | Description |
|---|---|---|
| inline_hook_id | string | Path parameter: inline_hook_id |
fn add_inline_hook_id(inline_hook_id: string, channel?: object, name?: string, version?: string)
Update an inline hook
| Argument | Type | Description |
|---|---|---|
| inline_hook_id | string | Path parameter: inline_hook_id |
| channel? | object | |
| name? | string | The display name of the inline hook |
| version? | string | Version of the inline hook type. The currently supported version is `1.0.0`. |
fn deactivate(inline_hook_id: string)
Deactivate an inline hook
| Argument | Type | Description |
|---|---|---|
| inline_hook_id | string | Path parameter: inline_hook_id |
fn execute(id: string)
Execute an inline hook
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the inline hook |
Resources
state— Inline hook resource state
inline_hook_action— Inline hook action result
linked_object_definition.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| associated? | object | |
| primary? | object | |
| _links? | object | Specifies link relations (see [Web Linking](https://www.rfc-editor.org/rfc/rfc8288)) available for the current status of an application using the [JSON Hypertext Application Language](https://datatracker.ietf.org/doc/html/draft-kelly-json-hal-06) specification. This object is used for dynamic discov |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a linked object definition
fn get(id: string)
Get a linked object definition
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the linked object definition |
fn lookup(max_items?: number)
List linked object definitions and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn delete(id: string)
Delete the linked object definition
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the linked object definition |
fn sync()
Sync linked object definition state from Okta
log.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn lookup(since?: string, until?: string, filter?: string, q?: string, sortOrder?: enum, max_items?: number)
List logs and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| since? | string | Filters the lower time bound of the log events `published` property for bounded queries or persistence time for polling queries |
| until? | string | Filters the upper time bound of the log events `published` property for bounded queries or persistence time for polling queries. |
| filter? | string | Filter expression that filters the results. All operators except [ ] are supported. See [Filter](https://developer.okta.com/docs/api/#filter) and [Operators](https://developer.okta.com/docs/api/#operators). |
| q? | string | Filters log events results by one or more case insensitive keywords. |
| sortOrder? | enum | The order of the returned events that are sorted by the `published` property |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
log_stream.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name | string | Unique name for the log stream object |
| type | enum | Specifies the streaming provider used Supported providers: * `aws_eventbridge` ([AWS EventBridge](https://aws.amazon.com/eventbridge)) * `splunk_cloud_logstreaming` ([Splunk Cloud](https://www.splunk.com/en_us/software/splunk-cloud-platform.html)) Select the provider type to see provider-specific co |
| settings | object | Specifies the configuration for the `splunk_cloud_logstreaming` log stream type. |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a log stream
fn get(id: string)
Get a log stream
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the log stream |
fn lookup(filter?: string, max_items?: number)
List log streams and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| filter? | string | An expression that [filters](/#filter) the returned objects. You can only use the `eq` operator on either the `status` or `type` properties in the filter expression. |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update log stream attributes
fn delete(id: string)
Delete the log stream
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the log stream |
fn sync()
Sync log stream state from Okta
fn activate(log_stream_id: string)
Activate a log stream
| Argument | Type | Description |
|---|---|---|
| log_stream_id | string | Path parameter: log_stream_id |
fn deactivate(log_stream_id: string)
Deactivate a log stream
| Argument | Type | Description |
|---|---|---|
| log_stream_id | string | Path parameter: log_stream_id |
Resources
state— Log stream resource state
log_stream_action— Log stream action result
log_stream_schema.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a log stream schema
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the log stream schema |
fn lookup(max_items?: number)
List log stream schemas and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn sync()
Sync log stream schema state from Okta
org_idps_credentials_key.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| e? | string | The exponent value for the RSA public key |
| kid? | string | Unique identifier for the key |
| kty? | string | Identifies the cryptographic algorithm family used with the key |
| n? | string | The modulus value for the RSA public key |
| use? | string | Intended use of the public key |
| x5c | array | Base64-encoded X.509 certificate chain with DER encoding |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a org idps credentials key
fn get(id: string)
Get a org idps credentials key
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the org idps credentials key |
fn lookup(max_items?: number)
List org idps credentials keys and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update org idps credentials key attributes
fn delete(id: string)
Delete the org idps credentials key
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the org idps credentials key |
fn sync()
Sync org idps credentials key state from Okta
policies_mapping.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| policy_id | string | Path scope for the policies mapping: policy_id |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| resourceId? | string | [Policy ID](https://developer.okta.com/docs/api/openapi/okta-management/management/tags/policy/#tag/Policy/operation/listPolicies!c=200&path=0/id&t=response) of the app sign-in policy that you want to map |
| resourceType? | enum | Specifies the type of resource to map. You can only map an app sign-in policy to a device signal collection policy (the `policyId` path parameter). |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a policies mapping
fn get(id: string)
Get a policies mapping
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the policies mapping |
fn lookup(max_items?: number)
List policies mappings and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn delete(id: string)
Delete the policies mapping
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the policies mapping |
fn sync()
Sync policies mapping state from Okta
policies_rule.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| policy_id | string | Path scope for the policies rule: policy_id |
| name? | string | Name of the rule |
| priority? | number | Priority of the rule |
| status? | string | Whether or not the rule is active. Use the `activate` query parameter to set the status of a rule. |
| system? | boolean | Specifies whether Okta created the policy rule (`system=true`). You can't delete policy rules that have `system` set to `true`. |
| type? | enum | Rule type |
| actions? | object | <x-lifecycle-container><x-lifecycle class="ea"></x-lifecycle> <x-lifecycle class="oie"></x-lifecycle></x-lifecycle-container>Specifies actions to be taken, or operations that may be allowed, if the rule conditions are satisfied |
| conditions? | string | Policy rule conditions aren't supported for this policy type. |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a policies rule
fn get(id: string)
Get a policies rule
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the policies rule |
fn lookup(max_items?: number)
List policies rules and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update policies rule attributes
fn delete(id: string)
Delete the policies rule
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the policies rule |
fn sync()
Sync policies rule state from Okta
fn activate(rule_id: string)
Activate a policy rule
| Argument | Type | Description |
|---|---|---|
| rule_id | string | Path parameter: rule_id |
fn deactivate(rule_id: string)
Deactivate a policy rule
| Argument | Type | Description |
|---|---|---|
| rule_id | string | Path parameter: rule_id |
Resources
state— Policies rule resource state
policies_rule_action— Policies rule action result
policy.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| description? | string | Description of the policy |
| name | string | Name of the policy |
| priority? | number | Specifies the order in which this policy is evaluated in relation to the other policies |
| status? | string | Whether or not the policy is active. Use the `activate` query parameter to set the status of a policy. |
| system? | boolean | Specifies whether Okta created the policy |
| type | enum | All Okta orgs contain only one IdP discovery policy with an immutable default rule routing to your org's sign-in page. All Okta orgs also contain just one entity risk policy, one session protection policy, and one identity claims sourcing policy. |
| _embedded? | object | |
| conditions? | string | Policy conditions aren't supported. Conditions are applied at the rule level for this policy type. |
| settings? | object | Specifies the policy level settings |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a policy
fn get(id: string)
Get a policy
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the policy |
fn lookup(type?: enum, status?: string, q?: string, expand?: string, sortBy?: string, resourceId?: string, max_items?: number)
List policys and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| type? | enum | Specifies the type of policy to return |
| status? | string | Refines the query by the `status` of the policy - `ACTIVE` or `INACTIVE` |
| q? | string | Refines the query by policy name prefix (startWith method) passed in as `q=string` |
| expand? | string | |
| sortBy? | string | Refines the query by sorting on the policy `name` in ascending order |
| resourceId? | string | Reference to the associated authorization server |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update policy attributes
fn delete(id: string)
Delete the policy
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the policy |
fn sync()
Sync policy state from Okta
fn activate(policy_id: string)
Activate a policy
| Argument | Type | Description |
|---|---|---|
| policy_id | string | Path parameter: policy_id |
fn clone(policy_id: string)
[LIMITED_GA — requires Okta Identity Engine] Clone an existing policy
| Argument | Type | Description |
|---|---|---|
| policy_id | string | Path parameter: policy_id |
fn create_simulate()
[LIMITED_GA — requires Okta Identity Engine] Create a policy simulation
fn deactivate(policy_id: string)
Deactivate a policy
| Argument | Type | Description |
|---|---|---|
| policy_id | string | Path parameter: policy_id |
Resources
state— Policy resource state
policy_action— Policy action result
profile_mapping.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| properties? | object | A target property, in string form, that maps to a valid [JSON Schema Draft](https://tools.ietf.org/html/draft-zyp-json-schema-04) document. |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a profile mapping
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the profile mapping |
fn lookup(sourceId?: string, targetId?: string, max_items?: number)
List profile mappings and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| sourceId? | string | The user type or app instance ID that acts as the source of expressions in a mapping. If this parameter is included, all returned mappings have this as their `source.id`. |
| targetId? | string | The user type or app instance ID that acts as the target of expressions in a mapping. If this parameter is included, all returned mappings have this as their `target.id`. |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update profile mapping attributes
fn sync()
Sync profile mapping state from Okta
push_provider.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name? | string | Display name of the push provider |
| providerType? | enum | |
| configuration? | object | |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a push provider
fn get(id: string)
Get a push provider
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the push provider |
fn lookup(type?: enum, max_items?: number)
List push providers and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| type? | enum | Filters push providers by `providerType` |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update push provider attributes
fn delete(id: string)
Delete the push provider
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the push provider |
fn sync()
Sync push provider state from Okta
realm.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| profile? | object | |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a realm
fn get(id: string)
Get a realm
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the realm |
fn lookup(search?: string, sortBy?: string, sortOrder?: string, max_items?: number)
List realms and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| search? | string | Searches for realms with a supported filtering expression for most properties. Searches for realms can be filtered by the contains (`co`) operator. You can only use `co` with the `profile.name` property. See [Operators](https://developer.okta.com/docs/api/#operators). |
| sortBy? | string | Specifies the field to sort by and can be any single property (for search queries only) |
| sortOrder? | string | Specifies sort order: `asc` or `desc` (for search queries only). This parameter is ignored if `sortBy` isn't present. |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update realm attributes
fn delete(id: string)
Delete the realm
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the realm |
fn sync()
Sync realm state from Okta
realm_assignment.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| actions? | object | Action to apply to a user |
| conditions? | object | Conditions of applying realm assignment |
| name? | string | Name of the realm |
| priority? | number | The priority of the realm assignment. The lower the number, the higher the priority. This helps resolve conflicts between realm assignments. > **Note:** When you create realm assignments in bulk, realm assignment priorities must be unique. |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a realm assignment
fn get(id: string)
Get a realm assignment
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the realm assignment |
fn lookup(max_items?: number)
List realm assignments and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update realm assignment attributes
fn delete(id: string)
Delete the realm assignment
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the realm assignment |
fn sync()
Sync realm assignment state from Okta
fn activate(assignment_id: string)
Activate a realm assignment
| Argument | Type | Description |
|---|---|---|
| assignment_id | string | Path parameter: assignment_id |
fn create_operations(assignmentId?: string)
Execute a realm assignment
| Argument | Type | Description |
|---|---|---|
| assignmentId? | string | ID of the realm |
fn deactivate(assignment_id: string)
Deactivate a realm assignment
| Argument | Type | Description |
|---|---|---|
| assignment_id | string | Path parameter: assignment_id |
fn list_operations()
List all realm assignment operations
Resources
state— Realm assignment resource state
realm_assignment_action— Realm assignment action result
roles_subscription.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| role_ref | string | Path scope for the roles subscription: role_ref |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a roles subscription
| Argument | Type | Description |
|---|---|---|
| id | string | The notificationType of the roles subscription |
fn lookup(max_items?: number)
List roles subscriptions and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn sync()
Sync roles subscription state from Okta
fn create_subscribe(notification_type: string)
Subscribe a role to a specific notification type
| Argument | Type | Description |
|---|---|---|
| notification_type | string | Path parameter: notification_type |
fn create_unsubscribe(notification_type: string)
Unsubscribe a role from a specific notification type
| Argument | Type | Description |
|---|---|---|
| notification_type | string | Path parameter: notification_type |
Resources
state— Roles subscription resource state
roles_subscription_action— Roles subscription action result
session.tsv2026.08.25.1
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a session
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the session |
fn delete(id: string)
Delete the session
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the session |
fn sync()
Sync session state from Okta
fn refresh(session_id: string)
Refresh a session
| Argument | Type | Description |
|---|---|---|
| session_id | string | Path parameter: session_id |
Resources
state— Session resource state
session_action— Session action result
sms_template.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name? | string | Human-readable name of the Template |
| template? | string | Text of the Template, including any [macros](https://developer.okta.com/docs/api/openapi/okta-management/management/tag/Template/) |
| translations? | record | - Template translations are optionally provided when you want to localize the SMS messages. Translations are provided as an object that contains `key:value` pairs: the language and the translated Template text. The key portion is a two-letter country code that conforms to [ISO 639-1](https://www.loc |
| type? | enum | Type of the Template |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a sms template
fn get(id: string)
Get a sms template
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the sms template |
fn lookup(templateType?: enum, max_items?: number)
List sms templates and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| templateType? | enum | |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update sms template attributes
fn delete(id: string)
Delete the sms template
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the sms template |
fn sync()
Sync sms template state from Okta
fn add_template_id(template_id: string, name?: string, template?: string, translations?: record, type?: enum)
Update an SMS template
| Argument | Type | Description |
|---|---|---|
| template_id | string | Path parameter: template_id |
| name? | string | Human-readable name of the Template |
| template? | string | Text of the Template, including any [macros](https://developer.okta.com/docs/api/openapi/okta-management/management/tag/Template/) |
| translations? | record | - Template translations are optionally provided when you want to localize the SMS messages. Translations are provided as an object that contains `key:value` pairs: the language and the translated Template text. The key portion is a two-letter country code that conforms to [ISO 639-1](https://www.loc |
| type? | enum | Type of the Template |
Resources
state— Sms template resource state
sms_template_action— Sms template action result
telephony_provider.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| id? | string | ID of the custom telephony provider |
| providerAuthToken? | string | The authentication token that's used to authenticate requests to the telephony provider. Your telephony provider gives you this token. |
| providerSettings? | object | Settings for custom telephony provider. These settings vary based on the telephony provider and the type of telephony operation (SMS or Voice). For `sms` and `call`, you can select one method per telephony operation (`sms` and `call`) for sending messages or voice calls. > **Note:** Configure your t |
| providerSid? | string | The account string identifier (SID) for your telephony provider account. Your telephony provider gives you this SID. |
| providerCapability? | enum | The types of telephony operations (SMS or Voice) that you use with your telephony provider. `ALL` is the only valid value. It indicates that your provider can handle both SMS messages and voice calls. You're not required to use both types of telephony operations, but your provider can support both. |
| providerName? | enum | The name of the telephony provider |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a telephony provider
fn get(id: string)
Get a telephony provider
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the telephony provider |
fn lookup(max_items?: number)
List telephony providers and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update telephony provider attributes
fn delete(id: string)
Delete the telephony provider
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the telephony provider |
fn sync()
Sync telephony provider state from Okta
fn activate(custom_telephony_provider_id: string)
Activate a custom telephony provider
| Argument | Type | Description |
|---|---|---|
| custom_telephony_provider_id | string | Path parameter: custom_telephony_provider_id |
fn create_set_as_primary(custom_telephony_provider_id: string)
Set a custom telephony provider as a primary telephony provider
| Argument | Type | Description |
|---|---|---|
| custom_telephony_provider_id | string | Path parameter: custom_telephony_provider_id |
fn deactivate(custom_telephony_provider_id: string)
Deactivate a custom telephony provider
| Argument | Type | Description |
|---|---|---|
| custom_telephony_provider_id | string | Path parameter: custom_telephony_provider_id |
fn test(custom_telephony_provider_id: string, countryCodeIso2?: string, factor?: enum, phoneNumber?: string)
Send a test message from a custom telephony provider
| Argument | Type | Description |
|---|---|---|
| custom_telephony_provider_id | string | Path parameter: custom_telephony_provider_id |
| countryCodeIso2? | string | The country code for the phone number. Use the [Alpha-2 code from ISO 3166-1](https://www.iso.org/obp/ui/#search) for country codes. |
| factor? | enum | The type of test message to send |
| phoneNumber? | string | The phone number to which the test message or call is sent |
Resources
state— Telephony provider resource state
telephony_provider_action— Telephony provider action result
ui_schema.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| uiSchema? | object | Properties of the UI schema |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a ui schema
fn get(id: string)
Get a ui schema
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the ui schema |
fn lookup(max_items?: number)
List ui schemas and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update ui schema attributes
fn delete(id: string)
Delete the ui schema
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the ui schema |
fn sync()
Sync ui schema state from Okta
user.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| credentials? | object | Specifies primary authentication and recovery credentials for a user. Credential types and requirements vary depending on the provider and security policy of the org. |
| profile? | object | Specifies the default and custom profile properties for a user. The default user profile is based on the [System for Cross-domain Identity Management: Core Schema](https://datatracker.ietf.org/doc/html/rfc7643). The only permitted customizations of the default profile are to update permissions, chan |
| realmId? | string | The ID of the realm in which the user is residing. See [Realms](/openapi/okta-management/management/tags/realm). |
| type? | object | The ID of the user type. Add this value if you want to create a user with a non-default [User Type](https://developer.okta.com/docs/api/openapi/okta-management/management/tag/UserType/). The user type determines which [schema](https://developer.okta.com/docs/api/openapi/okta-management/management/ta |
| groupIds? | array | The list of group IDs of groups that the user is added to at the time of creation |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a user
fn get(id: string)
Get a user
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the user |
fn lookup(search?: string, filter?: string, q?: string, sortBy?: string, sortOrder?: string, fields?: string, expand?: string, max_items?: number)
List users and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| search? | string | Searches for users with a supported filtering expression for most properties. Okta recommends this query parameter because it provides the largest range of search options and optimal performance. > **Note:** Using an overly complex or long search query can result in an error. This operation supports |
| filter? | string | Filters users with a supported expression for a subset of properties. > **Note:** Returned users include those with the `DEPROVISIONED` status. This requires [URL encoding](https://developer.mozilla.org/en-US/docs/Glossary/Percent-encoding). For example, `filter=lastUpdated gt "2013-06-01T00:00:00.0 |
| q? | string | Finds users who match the specified query. Use the `q` parameter for simple queries, such as a lookup of users by name when creating a people picker. The value of `q` is matched against `firstName`, `lastName`, or `email`. This performs a `startsWith` match, but this is an implementation detail and |
| sortBy? | string | Specifies the field to sort by (for search queries only). This can be any single property, for example `sortBy=profile.lastName`. Users with the same value for the `sortBy` property are ordered by `id`. Use with `sortOrder` to control the order of results. |
| sortOrder? | string | Specifies sort order: `asc` or `desc` (for search queries only). This parameter is ignored if `sortBy` isn't present. |
| fields? | string | Specifies a select set of user properties to query. Any other properties will be filtered out of the returned users. This is often called field projections in APIs, which can reduce payload size, improve performance, and limit unneccessary data exposure. Requested fields should be comma-separated. C |
| expand? | string | <x-lifecycle-container><x-lifecycle class="ea"></x-lifecycle></x-lifecycle-container>A parameter to include metadata in the `_embedded` property. Supported value: `classification`. |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update user attributes
fn delete(id: string)
Delete the user
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the user |
fn sync()
Sync user state from Okta
fn activate(id: string)
Activate a user
| Argument | Type | Description |
|---|---|---|
| id | string | Path parameter: id |
fn add_id(id: string, credentials?: object, profile?: object, realmId?: string, type?: object)
Update a user
| Argument | Type | Description |
|---|---|---|
| id | string | Path parameter: id |
| credentials? | object | Specifies primary authentication and recovery credentials for a user. Credential types and requirements vary depending on the provider and security policy of the org. |
| profile? | object | Specifies the default and custom profile properties for a user. The default user profile is based on the [System for Cross-domain Identity Management: Core Schema](https://datatracker.ietf.org/doc/html/rfc7643). The only permitted customizations of the default profile are to update permissions, chan |
| realmId? | string | The ID of the realm in which the user is residing. See [Realms](/openapi/okta-management/management/tags/realm). |
| type? | object | The ID of the user type. Add this value if you want to create a user with a non-default [User Type](https://developer.okta.com/docs/api/openapi/okta-management/management/tag/UserType/). The user type determines which [schema](https://developer.okta.com/docs/api/openapi/okta-management/management/ta |
fn create_credentials_forgot_password_recovery_question(user_id: string, password?: object, recovery_question?: object)
Reset password with recovery question
| Argument | Type | Description |
|---|---|---|
| user_id | string | Path parameter: user_id |
| password? | object | Specifies a password for a user. When a user has a valid password, imported hashed password, or password hook, and a response object contains a password credential, then the password object is a bare object without the value property defined (for example, `password: {}`). This indicates that a passw |
| recovery_question? | object | Specifies a secret question and answer that's validated (case insensitive) when a user forgets their password or unlocks their account. The answer property is write-only. |
fn create_expire_password_with_temp_password(id: string)
Expire the password with a temporary password
| Argument | Type | Description |
|---|---|---|
| id | string | Path parameter: id |
fn credentials_change_password(user_id: string, newPassword?: object, oldPassword?: object, revokeSessions?: boolean)
Update password
| Argument | Type | Description |
|---|---|---|
| user_id | string | Path parameter: user_id |
| newPassword? | object | Specifies a password for a user. When a user has a valid password, imported hashed password, or password hook, and a response object contains a password credential, then the password object is a bare object without the value property defined (for example, `password: {}`). This indicates that a passw |
| oldPassword? | object | Specifies a password for a user. When a user has a valid password, imported hashed password, or password hook, and a response object contains a password credential, then the password object is a bare object without the value property defined (for example, `password: {}`). This indicates that a passw |
| revokeSessions? | boolean | When set to `true`, revokes all user sessions, except for the current session |
fn credentials_change_recovery_question(user_id: string, password?: object, recovery_question?: object)
Update recovery question
| Argument | Type | Description |
|---|---|---|
| user_id | string | Path parameter: user_id |
| password? | object | Specifies a password for a user. When a user has a valid password, imported hashed password, or password hook, and a response object contains a password credential, then the password object is a bare object without the value property defined (for example, `password: {}`). This indicates that a passw |
| recovery_question? | object | Specifies a secret question and answer that's validated (case insensitive) when a user forgets their password or unlocks their account. The answer property is write-only. |
fn credentials_forgot_password(user_id: string)
Start forgot password flow
| Argument | Type | Description |
|---|---|---|
| user_id | string | Path parameter: user_id |
fn deactivate(id: string)
Deactivate a user
| Argument | Type | Description |
|---|---|---|
| id | string | Path parameter: id |
fn delete_clients_grants(user_id: string, client_id: string)
Revoke all grants for a client
| Argument | Type | Description |
|---|---|---|
| user_id | string | Path parameter: user_id |
| client_id | string | Path parameter: client_id |
fn delete_sessions(user_id: string)
Revoke all user sessions
| Argument | Type | Description |
|---|---|---|
| user_id | string | Path parameter: user_id |
fn expire_password(id: string)
Expire the password
| Argument | Type | Description |
|---|---|---|
| id | string | Path parameter: id |
fn get_classification(user_id: string)
[EA] Retrieve a user
| Argument | Type | Description |
|---|---|---|
| user_id | string | Path parameter: user_id |
fn list_app_links(id: string)
List all assigned app links
| Argument | Type | Description |
|---|---|---|
| id | string | Path parameter: id |
fn list_blocks(id: string)
List all user blocks
| Argument | Type | Description |
|---|---|---|
| id | string | Path parameter: id |
fn list_clients(user_id: string)
List all clients
| Argument | Type | Description |
|---|---|---|
| user_id | string | Path parameter: user_id |
fn list_clients_grants(user_id: string, client_id: string)
List all grants for a client
| Argument | Type | Description |
|---|---|---|
| user_id | string | Path parameter: user_id |
| client_id | string | Path parameter: client_id |
fn list_devices(user_id: string)
[LIMITED_GA — requires Okta Identity Engine] List all devices for an enrolled user
| Argument | Type | Description |
|---|---|---|
| user_id | string | Path parameter: user_id |
fn list_groups(id: string)
List all groups
| Argument | Type | Description |
|---|---|---|
| id | string | Path parameter: id |
fn list_idps(id: string)
List all IdPs for user
| Argument | Type | Description |
|---|---|---|
| id | string | Path parameter: id |
fn reactivate(id: string)
Reactivate a user
| Argument | Type | Description |
|---|---|---|
| id | string | Path parameter: id |
fn reset_factors(id: string)
Reset the factors
| Argument | Type | Description |
|---|---|---|
| id | string | Path parameter: id |
fn reset_password(id: string)
Reset a password
| Argument | Type | Description |
|---|---|---|
| id | string | Path parameter: id |
fn suspend(id: string)
Suspend a user
| Argument | Type | Description |
|---|---|---|
| id | string | Path parameter: id |
fn unlock(id: string)
Unlock a user
| Argument | Type | Description |
|---|---|---|
| id | string | Path parameter: id |
fn unsuspend(id: string)
Unsuspend a user
| Argument | Type | Description |
|---|---|---|
| id | string | Path parameter: id |
fn update_classification(user_id: string, type?: enum)
[EA] Replace the user
| Argument | Type | Description |
|---|---|---|
| user_id | string | Path parameter: user_id |
| type? | enum | The type of user classification |
Resources
state— User resource state
user_action— User action result
user_schema.tsv2026.08.25.1
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| definitions? | object | User profile subschemas The profile object for a user is defined by a composite schema of base and custom properties using a JSON path to reference subschemas. The `#base` properties are defined and versioned by Okta, while `#custom` properties are extensible. Custom property names for the profile o |
| properties? | object | User Object Properties |
| title? | string | User-defined display name for the schema |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a user schema
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the user schema |
fn update()
Update user schema attributes
fn sync()
Sync user schema state from Okta
user_type.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| description? | string | The human-readable description of the user type |
| displayName | string | The human-readable name of the user type |
| name | string | The name of the user type. The name must start with A-Z or a-z and contain only A-Z, a-z, 0-9, or underscore (_) characters. This value becomes read-only after creation and can't be updated. |
| _links? | object | Specifies link relations (see [Web Linking](https://www.rfc-editor.org/rfc/rfc8288)) available using the [JSON Hypertext Application Language](https://datatracker.ietf.org/doc/html/draft-kelly-json-hal-06) specification. This object is used for dynamic discovery of related resources and lifecycle op |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a user type
fn get(id: string)
Get a user type
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the user type |
fn lookup(max_items?: number)
List user types and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn update()
Update user type attributes
fn delete(id: string)
Delete the user type
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the user type |
fn sync()
Sync user type state from Okta
fn add_type_id(type_id: string, description?: string, displayName?: string)
Update a user type
| Argument | Type | Description |
|---|---|---|
| type_id | string | Path parameter: type_id |
| description? | string | The updated human-readable description of the user type |
| displayName? | string | The updated human-readable display name for the user type |
Resources
state— User type resource state
user_type_action— User type action result
users_authenticator_enrollment.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| user_id | string | Path scope for the users authenticator enrollment: user_id |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a users authenticator enrollment
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the users authenticator enrollment |
fn lookup(max_items?: number)
List users authenticator enrollments and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn delete(id: string)
Delete the users authenticator enrollment
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the users authenticator enrollment |
fn sync()
Sync users authenticator enrollment state from Okta
fn create_phone(authenticatorId: string, profile: object)
[LIMITED_GA — requires Okta Identity Engine] Create an auto-activated Phone authenticator enrollment
| Argument | Type | Description |
|---|---|---|
| authenticatorId | string | Unique identifier of the `phone` authenticator |
| profile | object | Defines the authenticator specific parameters |
fn create_tac(authenticatorId: string, profile?: object)
[LIMITED_GA] Create an auto-activated TAC authenticator enrollment
| Argument | Type | Description |
|---|---|---|
| authenticatorId | string | Unique identifier of the TAC authenticator |
| profile? | object | Defines the authenticator specific parameters |
Resources
state— Users authenticator enrollment resource state
users_authenticator_enrollment_action— Users authenticator enrollment action result
users_clients_token.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| user_id | string | Path scope for the users clients token: user_id |
| client_id | string | Path scope for the users clients token: client_id |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a users clients token
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the users clients token |
fn lookup(expand?: string, max_items?: number)
List users clients tokens and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| expand? | string | Valid value: `scope`. If specified, scope details are included in the `_embedded` attribute. |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn delete(id: string)
Delete the users clients token
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the users clients token |
fn sync()
Sync users clients token state from Okta
users_factor.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| user_id | string | Path scope for the users factor: user_id |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| factorType? | string | |
| provider? | enum | |
| verify? | object | |
| factorProfileId? | string | ID of an existing Custom TOTP factor profile. To create this, see [Custom TOTP factor](https://help.okta.com/okta_help.htm?id=ext-mfa-totp). |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a users factor
fn get(id: string)
Get a users factor
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the users factor |
fn lookup(max_items?: number)
List users factors and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn delete(id: string)
Delete the users factor
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the users factor |
fn sync()
Sync users factor state from Okta
fn activate(factor_id: string, passCode?: string, useNumberMatchingChallenge?: boolean, clientData?: string, registrationData?: string, attestation?: string)
Activate a factor
| Argument | Type | Description |
|---|---|---|
| factor_id | string | Path parameter: factor_id |
| passCode? | string | OTP for the current time window |
| useNumberMatchingChallenge? | boolean | Select whether to use a number matching challenge for a `push` factor. > **Note:** Sending a request with a body is required when you verify a `push` factor with a number matching challenge. |
| clientData? | string | Base64-encoded client data from the Passkey (FIDO2 WebAuthn) authenticator |
| registrationData? | string | Base64-encoded registration data from the U2F token |
| attestation? | string | Base64-encoded attestation from the Passkey (FIDO2 WebAuthn) authenticator |
fn list_catalog()
List all supported factors
fn list_questions()
List all supported security questions
fn resend(factor_id: string, factorType?: string, profile?: object, provider?: enum)
Resend a factor enrollment
| Argument | Type | Description |
|---|---|---|
| factor_id | string | Path parameter: factor_id |
| factorType? | string | |
| profile? | object | |
| provider? | enum |
fn verify(factor_id: string, passCode?: string, useNumberMatchingChallenge?: boolean, answer?: string, clientData?: string, signatureData?: string, authenticatorData?: string)
Verify a factor
| Argument | Type | Description |
|---|---|---|
| factor_id | string | Path parameter: factor_id |
| passCode? | string | OTP for the current time window |
| useNumberMatchingChallenge? | boolean | Select whether to use a number matching challenge for a `push` factor. > **Note:** Sending a request with a body is required when you verify a `push` factor with a number matching challenge. |
| answer? | string | Answer to the question |
| clientData? | string | Base64-encoded client data from the Passkey (FIDO2 WebAuthn) authenticator |
| signatureData? | string | Base64-encoded signature data from the Passkey (FIDO2 WebAuthn) authenticator |
| authenticatorData? | string | Base64-encoded authenticator data from the Passkey (FIDO2 WebAuthn) authenticator |
Resources
state— Users factor resource state
users_factor_action— Users factor action result
users_factors_transaction.tsv2026.08.25.1
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| user_id | string | Path scope for the users factors transaction: user_id |
| factor_id | string | Path scope for the users factors transaction: factor_id |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a users factors transaction
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the users factors transaction |
fn sync()
Sync users factors transaction state from Okta
users_grant.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| user_id | string | Path scope for the users grant: user_id |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a users grant
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the users grant |
fn lookup(scopeId?: string, expand?: string, max_items?: number)
List users grants and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| scopeId? | string | The scope ID to filter on |
| expand? | string | Valid value: `scope`. If specified, scope details are included in the `_embedded` attribute. |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn delete(id: string)
Delete the users grant
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the users grant |
fn sync()
Sync users grant state from Okta
users_linked_object.tsv2026.08.25.1
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| user_id_or_login | string | Path scope for the users linked object: user_id_or_login |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a users linked object
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the users linked object |
fn delete(id: string)
Delete the users linked object
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the users linked object |
fn sync()
Sync users linked object state from Okta
fn set_primary_user_id(primary_relationship_name: string, primary_user_id: string)
Assign a linked object value for primary
| Argument | Type | Description |
|---|---|---|
| primary_relationship_name | string | Path parameter: primary_relationship_name |
| primary_user_id | string | Path parameter: primary_user_id |
Resources
state— Users linked object resource state
users_linked_object_action— Users linked object action result
users_subscription.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| user_id | string | Path scope for the users subscription: user_id |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn get(id: string)
Get a users subscription
| Argument | Type | Description |
|---|---|---|
| id | string | The notificationType of the users subscription |
fn lookup(max_items?: number)
List users subscriptions and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn sync()
Sync users subscription state from Okta
fn create_subscribe(notification_type: string)
Subscribe a user to a specific notification type
| Argument | Type | Description |
|---|---|---|
| notification_type | string | Path parameter: notification_type |
fn create_unsubscribe(notification_type: string)
Unsubscribe a user from a specific notification type
| Argument | Type | Description |
|---|---|---|
| notification_type | string | Path parameter: notification_type |
Resources
state— Users subscription resource state
users_subscription_action— Users subscription action result
webauthn_registration_activate.tsv2026.08.25.1
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| credResponses? | array | List of credential responses from the fulfillment provider |
| fulfillmentProvider? | enum | Name of the fulfillment provider for the WebAuthn preregistration factor |
| pinResponseJwe? | string | Encrypted JWE of the PIN response from the fulfillment provider |
| serial? | string | Serial number of the YubiKey |
| userId? | string | ID of an existing Okta user |
| version? | string | Firmware version of the YubiKey |
| yubicoSigningJwks? | array | List of usable signing keys from Yubico (in JSON Web Key Sets (JWKS) format). The signing keys are used to verify the JSON Web Signature (JWS) inside the JWE. |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a webauthn registration activate
webauthn_registration_enroll.tsv2026.08.25.1
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| enrollmentRpIds? | array | List of relying party hostnames to register on the YubiKey |
| fulfillmentProvider? | enum | Name of the fulfillment provider for the WebAuthn preregistration factor |
| userId? | string | ID of an existing Okta user |
| yubicoTransportKeyJWK? | object | Elliptic curve key in JSON Web Key (JWK) format. It's used during enrollment to encrypt fulfillment requests to Yubico, or during activation to verify Yubico's JWS (JSON Web Signature) objects in fulfillment responses. The currently agreed protocol uses P-384. |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a webauthn registration enroll
webauthn_registration_initiate_fulfillment_request.tsv2026.08.25.1
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| fulfillmentData? | array | List of fulfillment order details |
| fulfillmentProvider? | enum | Name of the fulfillment provider for the WebAuthn preregistration factor |
| userId? | string | ID of an existing Okta user |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a webauthn registration initiate fulfillment request
webauthn_registration_send_pin.tsv2026.08.25.1
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| authenticatorEnrollmentId? | string | ID for a WebAuthn preregistration factor in Okta |
| fulfillmentProvider? | enum | Name of the fulfillment provider for the WebAuthn preregistration factor |
| userId? | string | ID of an existing Okta user |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a webauthn registration send pin
webauthn_registration_users_enrollment.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| user_id | string | Path scope for the webauthn registration users enrollment: user_id |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn lookup(max_items?: number)
List webauthn registration users enrollments and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn delete(id: string)
Delete the webauthn registration users enrollment
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the webauthn registration users enrollment |
fn create_mark_error(authenticator_enrollment_id: string)
[LIMITED_GA — requires Okta Identity Engine] Assign the fulfillment error status to a WebAuthn preregistration factor
| Argument | Type | Description |
|---|---|---|
| authenticator_enrollment_id | string | Path parameter: authenticator_enrollment_id |
Resources
state— Webauthn registration users enrollment resource state
webauthn_registration_users_enrollment_action— Webauthn registration users enrollment action result
well_known_app_authenticator.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn lookup(oauthClientId?: string, max_items?: number)
List well known app authenticators and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| oauthClientId? | string | Filters app authenticator configurations by `oauthClientId` |
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
well_known_apple_app_site.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn lookup(max_items?: number)
List well known apple app sites and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
well_known_assetlinks.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn lookup(max_items?: number)
List well known assetlinkss and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
well_known_webauthn.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name? | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn lookup(max_items?: number)
List well known webauthns and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
yubikey_token.tsv2026.08.25.2
Global Arguments
| Argument | Type | Description |
|---|---|---|
| okta_domain | string | Your Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable. |
| name | string | Instance name for this resource (used as the unique identifier in the factory pattern) |
| serialNumber? | string | The unique identifier assigned to each YubiKey device |
| publicId? | string | The YubiKey's public ID |
| privateId? | string | The YubiKey's private ID |
| aesKey? | string | The cryptographic key used in the AES (Advanced Encryption Standard) algorithm to encrypt and decrypt the YubiKey OTP |
| api_token? | string | Okta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
fn create()
Create a yubikey token
fn get(id: string)
Get a yubikey token
| Argument | Type | Description |
|---|---|---|
| id | string | The id of the yubikey token |
fn lookup(max_items?: number)
List yubikey tokens and record each as a data artifact (newest first, capped at 200 by default)
| Argument | Type | Description |
|---|---|---|
| max_items? | number | Stop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit. |
fn sync()
Sync yubikey token state from Okta
04Previous Versions
2026.08.25.2
05Stats
B
85 / 100
Downloads
18
Archive size
345.8 KB
- Has README or module doc2/2earned
- README has a code example1/1earned
- README is substantive1/1earned
- Most symbols documented1/1earned
- No slow types (deprecated)1/1earned
- Dependencies pass trust audit2/2earned
- Has description1/1earned
- Platform support declared (or universal)2/2earned
- License declared1/1earned
- Verified public repository0/2missing
06Platforms
07Labels