Skip to main content

Okta

@keeb/oktav2026.08.25.3· 1mo agoMODELS
01README

Okta CIAM identity models

02Release Notes
  • Updated: app_schema, application, apps_credentials_csr, apps_credentials_jwk, apps_credentials_key, apps_credentials_secret, apps_feature, apps_federated_claim, apps_grant, apps_group, apps_token, apps_user, authenticator, authenticators_aaguid, authenticators_method, authorization_server_resource_key, authorization_server, authorization_servers_claim, authorization_servers_clients_token, authorization_servers_credentials_key, authorization_servers_policies_rule, authorization_servers_policy, authorization_servers_scope, brand_well_known_uri, brand, brands_theme, custom_domain, email_customization, email_domain, email_server, email_template, event_hook, group_schema, group, groups_rule, hook_key, identity_provider, identity_sources_session, idps_credentials_csr, idps_credentials_key, idps_user, inline_hook, linked_object_definition, log_stream_schema, log_stream, log, org_idps_credentials_key, policies_mapping, policies_rule, policy, profile_mapping, push_provider, realm_assignment, realm, roles_subscription, sms_template, telephony_provider, ui_schema, user_type, user, users_authenticator_enrollment, users_clients_token, users_factor, users_grant, users_subscription, webauthn_registration_users_enrollment, well_known_app_authenticator, well_known_apple_app_site, well_known_assetlinks, well_known_webauthn, yubikey_token
03Models83
app_schema.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
app_idstringPath scope for the app schema: app_id
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
definitions?objectUser profile subschemas The profile object for a user is defined by a composite schema of base and custom properties using a JSON path to reference subschemas. The `#base` properties are defined and versioned by Okta, while `#custom` properties are extensible. Custom property names for the profile o
properties?objectUser Object Properties
title?stringUser-defined display name for the schema
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a app schema
fn lookup(max_items?: number)
List app schemas and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
application.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
accessibility?objectSpecifies access settings for the app
labelstringUser-defined display name for app
licensing?objectLicenses for the app
profile?recordContains any valid JSON schema for specifying properties that can be referenced from a request (only available to OAuth 2.0 client apps). For example, add an app manager contact email address or define an allowlist of groups that you can then reference using the Okta Expression Language `getFiltered
signOnModeenumAuthentication mode for the app | signOnMode | Description | | ---------- | ----------- | | AUTO_LOGIN | Secure Web Authentication (SWA) | | BASIC_AUTH | HTTP Basic Authentication with Okta Browser Plugin | | BOOKMARK | Just a bookmark (no-authentication) | | BROWSER_PLUGIN | Secure Web Authenticati
visibility?objectSpecifies visibility settings for the app
credentials?objectCredentials for the specified `signOnMode`
name?enum`template_wsfed` is the key name for a WS-Federated app instance with a SAML 2.0 token
settings?objectApp settings
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a application
fn get(id: string)
Get a application
ArgumentTypeDescription
idstringThe id of the application
fn lookup(q?: string, useOptimization?: string, alwaysIncludeVpnSettings?: string, filter?: string, expand?: string, includeNonDeleted?: string, max_items?: number)
List applications and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
q?stringSearches for apps with `name` or `label` properties that starts with the `q` value using the `startsWith` operation
useOptimization?stringSpecifies whether to use query optimization. If you specify `useOptimization=true` in the request query, the response contains a subset of app instance properties.
alwaysIncludeVpnSettings?stringSpecifies whether to include the VPN configuration for existing notifications in the result, regardless of whether VPN notifications are configured
filter?stringFilters apps with a supported expression for a subset of properties. Filtering supports the following limited number of properties: `id`, `status`, `credentials.signing.kid`, `settings.slo.enabled`, or `name`. See [Filter](https://developer.okta.com/docs/api/#filter).
expand?stringAn optional parameter used for link expansion to embed more resources in the response. Only supports `expand=user/{userId}` and must be used with the `user.id eq "{userId}"` filter query for the same user. Returns the assigned [application user](/openapi/okta-management/management/tags/applicationus
includeNonDeleted?stringSpecifies whether to include non-active, but not deleted apps in the results
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update application attributes
fn delete(id: string)
Delete the application
ArgumentTypeDescription
idstringThe id of the application
fn sync()
Sync application state from Okta
fn activate(app_id: string)
Activate an application
ArgumentTypeDescription
app_idstringPath parameter: app_id
fn create_logo(app_id: string, file: string)
Upload an application logo
ArgumentTypeDescription
app_idstringPath parameter: app_id
filestringThe image file containing the logo. The file must be in PNG, JPG, SVG, or GIF format, and less than one MB in size. For best results, use an image with a transparent background and a square dimension of 200 x 200 pixels to prevent upscaling. > **Notes:** > * Only SVG files encoded in UTF-8 are suppo
fn deactivate(app_id: string)
Deactivate an application
ArgumentTypeDescription
app_idstringPath parameter: app_id
fn get_sso_saml_metadata(app_id: string)
Preview the application SAML metadata
ArgumentTypeDescription
app_idstringPath parameter: app_id
fn update_policies(app_id: string, policy_id: string)
[LIMITED_GA — requires Okta Identity Engine] Assign an app sign-in policy
ArgumentTypeDescription
app_idstringPath parameter: app_id
policy_idstringPath parameter: policy_id

Resources

state— Application resource state
application_action— Application action result
apps_credentials_csr.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
app_idstringPath scope for the apps credentials csr: app_id
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
subject?object
subjectAltNames?object
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a apps credentials csr
fn get(id: string)
Get a apps credentials csr
ArgumentTypeDescription
idstringThe id of the apps credentials csr
fn lookup(max_items?: number)
List apps credentials csrs and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn delete(id: string)
Delete the apps credentials csr
ArgumentTypeDescription
idstringThe id of the apps credentials csr
fn sync()
Sync apps credentials csr state from Okta
fn publish(csr_id: string, certificate: string)
Publish a certificate signing request
ArgumentTypeDescription
csr_idstringPath parameter: csr_id
certificatestringRaw certificate body, in the format named by the endpoint's content type

Resources

state— Apps credentials csr resource state
apps_credentials_csr_action— Apps credentials csr action result
apps_credentials_jwk.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
app_idstringPath scope for the apps credentials jwk: app_id
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
alg?stringAlgorithm used in the key
use?enumAcceptable use of the JSON Web Key
e?stringRSA key value (exponent) for key binding
kty?enumCryptographic algorithm family for the certificate's key pair
n?stringRSA key value (modulus) for key binding
kid?stringUnique identifier of the JSON Web Key in the OAUth 2.0 client's JWKS
status?enumStatus of the OAuth 2.0 client JSON Web Key
x?stringThe public x coordinate for the elliptic curve point
y?stringThe public y coordinate for the elliptic curve point
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a apps credentials jwk
fn get(id: string)
Get a apps credentials jwk
ArgumentTypeDescription
idstringThe id of the apps credentials jwk
fn lookup(max_items?: number)
List apps credentials jwks and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn delete(id: string)
Delete the apps credentials jwk
ArgumentTypeDescription
idstringThe id of the apps credentials jwk
fn sync()
Sync apps credentials jwk state from Okta
fn activate(key_id: string)
Activate an OAuth 2.0 client JSON Web Key
ArgumentTypeDescription
key_idstringPath parameter: key_id
fn deactivate(key_id: string)
Deactivate an OAuth 2.0 client JSON Web Key
ArgumentTypeDescription
key_idstringPath parameter: key_id

Resources

state— Apps credentials jwk resource state
apps_credentials_jwk_action— Apps credentials jwk action result
apps_credentials_key.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
app_idstringPath scope for the apps credentials key: app_id
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a apps credentials key
ArgumentTypeDescription
idstringThe id of the apps credentials key
fn lookup(max_items?: number)
List apps credentials keys and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn sync()
Sync apps credentials key state from Okta
fn clone(key_id: string)
Clone a key credential
ArgumentTypeDescription
key_idstringPath parameter: key_id
fn create_generate()
Generate a key credential

Resources

state— Apps credentials key resource state
apps_credentials_key_action— Apps credentials key action result
apps_credentials_secret.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
app_idstringPath scope for the apps credentials secret: app_id
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
client_secret?stringThe OAuth 2.0 client secret string
status?enumStatus of the OAuth 2.0 client secret
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a apps credentials secret
fn get(id: string)
Get a apps credentials secret
ArgumentTypeDescription
idstringThe id of the apps credentials secret
fn lookup(max_items?: number)
List apps credentials secrets and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn delete(id: string)
Delete the apps credentials secret
ArgumentTypeDescription
idstringThe id of the apps credentials secret
fn sync()
Sync apps credentials secret state from Okta
fn activate(secret_id: string)
Activate an OAuth 2.0 client secret
ArgumentTypeDescription
secret_idstringPath parameter: secret_id
fn deactivate(secret_id: string)
Deactivate an OAuth 2.0 client secret
ArgumentTypeDescription
secret_idstringPath parameter: secret_id

Resources

state— Apps credentials secret resource state
apps_credentials_secret_action— Apps credentials secret action result
apps_feature.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
app_idstringPath scope for the apps feature: app_id
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
create?objectDetermines whether Okta assigns a new app account to each user managed by Okta. Okta doesn't create a new account if it detects that the username specified in Okta already exists in the app. The user's Okta username is assigned by default.
update?objectDetermines whether updates to a user's profile are pushed to the app
importRules?objectDefines user import rules
importSettings?objectDefines import settings
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a apps feature
ArgumentTypeDescription
idstringThe id of the apps feature
fn lookup(max_items?: number)
List apps features and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update apps feature attributes
fn sync()
Sync apps feature state from Okta
apps_federated_claim.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
app_idstringPath scope for the apps federated claim: app_id
expression?stringThe Okta Expression Language expression to be evaluated at runtime
name?stringThe name of the claim to be used in the produced token
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a apps federated claim
fn get(id: string)
Get a apps federated claim
ArgumentTypeDescription
idstringThe id of the apps federated claim
fn lookup(max_items?: number)
List apps federated claims and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update apps federated claim attributes
fn delete(id: string)
Delete the apps federated claim
ArgumentTypeDescription
idstringThe id of the apps federated claim
fn sync()
Sync apps federated claim state from Okta
apps_grant.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
app_idstringPath scope for the apps grant: app_id
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
issuerstringThe issuer of your org authorization server. This is typically your Okta domain.
scopeIdstringThe name of the [Okta scope](https://developer.okta.com/docs/api/oauth2/#oauth-20-scopes) for which consent is granted
_links?objectSpecifies link relations (see [Web Linking](https://www.rfc-editor.org/rfc/rfc8288)) available using the [JSON Hypertext Application Language](https://datatracker.ietf.org/doc/html/draft-kelly-json-hal-06) specification. This object is used for dynamic discovery of related resources and lifecycle op
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a apps grant
fn get(id: string)
Get a apps grant
ArgumentTypeDescription
idstringThe id of the apps grant
fn lookup(expand?: string, max_items?: number)
List apps grants and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
expand?stringAn optional parameter to return scope details in the `_embedded` property. Valid value: `scope`
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn delete(id: string)
Delete the apps grant
ArgumentTypeDescription
idstringThe id of the apps grant
fn sync()
Sync apps grant state from Okta
apps_group.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
app_idstringPath scope for the apps group: app_id
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
lastUpdated?stringTimestamp when the object was last updated
priority?numberPriority assigned to the group. If an app has more than one group assigned to the same user, then the group with the higher priority has its profile applied to the [application user](https://developer.okta.com/docs/api/openapi/okta-management/management/tags/applicationusers). If a priority value is
profile?recordSpecifies the profile properties applied to [application users](https://developer.okta.com/docs/api/openapi/okta-management/management/tags/applicationusers) that are assigned to the app through group membership. Some reference properties are imported from the target app and can't be configured. See
_links?objectSpecifies link relations (see [Web Linking](https://www.rfc-editor.org/rfc/rfc8288)) available using the [JSON Hypertext Application Language](https://datatracker.ietf.org/doc/html/draft-kelly-json-hal-06) specification. This object is used for dynamic discovery of related resources and lifecycle op
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a apps group
ArgumentTypeDescription
idstringThe id of the apps group
fn lookup(q?: string, expand?: string, max_items?: number)
List apps groups and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
q?stringSpecifies a filter for a list of assigned groups returned based on their names. The value of `q` is matched against the group `name`. This filter only supports the `startsWith` operation that matches the `q` string against the beginning of the [group name](openapi/okta-management/management/group#ta
expand?stringAn optional query parameter to return the corresponding assigned [group](openapi/okta-management/management/group) or the group assignment metadata details in the `_embedded` property.
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update apps group attributes
fn delete(id: string)
Delete the apps group
ArgumentTypeDescription
idstringThe id of the apps group
fn sync()
Sync apps group state from Okta
fn set_group_id(group_id: string)
Update an application group
ArgumentTypeDescription
group_idstringPath parameter: group_id

Resources

state— Apps group resource state
apps_group_action— Apps group action result
apps_token.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
app_idstringPath scope for the apps token: app_id
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a apps token
ArgumentTypeDescription
idstringThe id of the apps token
fn lookup(expand?: string, max_items?: number)
List apps tokens and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
expand?stringAn optional parameter to return scope details in the `_embedded` property. Valid value: `scope`
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn delete(id: string)
Delete the apps token
ArgumentTypeDescription
idstringThe id of the apps token
fn sync()
Sync apps token state from Okta
apps_user.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
app_idstringPath scope for the apps user: app_id
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
credentials?objectSpecifies a user's credentials for the app. This parameter can be omitted for apps with [sign-on mode](/openapi/okta-management/management/application/getapplication#application/getapplication/t=response&c=200&path=&d=0/signonmode) (`signOnMode`) or [authentication schemes](/openapi/okta-management/
profile?recordSpecifies the default and custom profile properties for a user. Properties that are visible in the Admin Console for an app assignment can also be assigned through the API. Some properties are reference properties that are imported from the target app and can't be configured. See [profile](/openapi/
created?stringTimestamp when the object was created
idstringUnique identifier for the Okta user
lastUpdated?stringTimestamp when the object was last updated
scope?enumIndicates if the assignment is direct (`USER`) or by group membership (`GROUP`). If not specified, Okta tries to determine the scope based on the assignment type.
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a apps user
fn get(id: string)
Get a apps user
ArgumentTypeDescription
idstringThe id of the apps user
fn lookup(q?: string, expand?: string, max_items?: number)
List apps users and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
q?stringSpecifies a filter for the list of application users returned based on their profile attributes. The value of `q` is matched against the beginning of the following profile attributes: `userName`, `firstName`, `lastName`, and `email`. This filter only supports the `startsWith` operation that matches
expand?stringAn optional query parameter to return the corresponding [User](/openapi/okta-management/management/tags/user) object in the `_embedded` property. Valid value: `user`
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update apps user attributes
fn delete(id: string)
Delete the apps user
ArgumentTypeDescription
idstringThe id of the apps user
fn sync()
Sync apps user state from Okta
authenticator.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
description?stringThe description of the authenticator. This setting is only available for the `webauthn` authenticator type (Passkeys).
key?enumA human-readable string that identifies the authenticator
name?stringDisplay name of the authenticator
status?stringStatus of the authenticator
type?enumThe type of authenticator
_links?objectLink relations for this object
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a authenticator
fn get(id: string)
Get a authenticator
ArgumentTypeDescription
idstringThe id of the authenticator
fn lookup(max_items?: number)
List authenticators and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update authenticator attributes
fn sync()
Sync authenticator state from Okta
fn activate(authenticator_id: string)
[LIMITED_GA — requires Okta Identity Engine] Activate an authenticator
ArgumentTypeDescription
authenticator_idstringPath parameter: authenticator_id
fn deactivate(authenticator_id: string)
[LIMITED_GA — requires Okta Identity Engine] Deactivate an authenticator
ArgumentTypeDescription
authenticator_idstringPath parameter: authenticator_id

Resources

state— Authenticator resource state
authenticator_action— Authenticator action result
authenticators_aaguid.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
authenticator_idstringPath scope for the authenticators aaguid: authenticator_id
attestationRootCertificates?arrayContains the certificate and information about it
authenticatorCharacteristics?objectContains additional properties about custom AAGUID.
name?stringThe product name associated with this AAGUID.
aaguid?stringAn Authenticator Attestation Global Unique Identifier (AAGUID) is a 128-bit identifier indicating the model.
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a authenticators aaguid
fn get(id: string)
Get a authenticators aaguid
ArgumentTypeDescription
idstringThe aaguid of the authenticators aaguid
fn lookup(max_items?: number)
List authenticators aaguids and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update authenticators aaguid attributes
fn delete(id: string)
Delete the authenticators aaguid
ArgumentTypeDescription
idstringThe aaguid of the authenticators aaguid
fn sync()
Sync authenticators aaguid state from Okta
fn set_aaguid(aaguid: string, attestationRootCertificates?: array, authenticatorCharacteristics?: object, name?: string)
Update a custom AAGUID
ArgumentTypeDescription
aaguidstringPath parameter: aaguid
attestationRootCertificates?arrayContains the certificate and information about it
authenticatorCharacteristics?objectContains additional properties about custom AAGUID.
name?stringThe product name associated with this AAGUID.

Resources

state— Authenticators aaguid resource state
authenticators_aaguid_action— Authenticators aaguid action result
authenticators_method.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
authenticator_idstringPath scope for the authenticators method: authenticator_id
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
status?stringThe status of the authenticator method
type?enumThe type of authenticator method
_links?objectSpecifies link relations (see [Web Linking](https://www.rfc-editor.org/rfc/rfc8288)) available using the [JSON Hypertext Application Language](https://datatracker.ietf.org/doc/html/draft-kelly-json-hal-06) specification. This object is used for dynamic discovery of related resources and lifecycle op
settings?objectThe settings for the Passkey (FIDO2 WebAuthn) authenticator method
verifiableProperties?array
acceptableAdjacentIntervals?numberThe number of acceptable adjacent intervals, also known as the clock drift interval. This setting allows you to build in tolerance for any time difference between the token and the server. For example, with a `timeIntervalInSeconds` of 60 seconds and an `acceptableAdjacentIntervals` value of 5, Okta
algorithm?enumHMAC algorithm
encoding?enumThe shared secret encoding
factorProfileId?stringThe `id` value of the factor profile
passCodeLength?numberNumber of digits in an OTP value
protocol?enumThe protocol used
timeIntervalInSeconds?numberTime interval for TOTP in seconds
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a authenticators method
ArgumentTypeDescription
idstringThe type of the authenticators method
fn lookup(max_items?: number)
List authenticators methods and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update authenticators method attributes
fn sync()
Sync authenticators method state from Okta
fn activate(method_type: string)
[LIMITED_GA — requires Okta Identity Engine] Activate an authenticator method
ArgumentTypeDescription
method_typestringPath parameter: method_type
fn create_verify_rp_id_domain(web_authn_method_type: string)
[LIMITED_GA — requires Okta Identity Engine] Verify a Relying Party ID domain
ArgumentTypeDescription
web_authn_method_typestringPath parameter: web_authn_method_type
fn deactivate(method_type: string)
[LIMITED_GA — requires Okta Identity Engine] Deactivate an authenticator method
ArgumentTypeDescription
method_typestringPath parameter: method_type

Resources

state— Authenticators method resource state
authenticators_method_action— Authenticators method action result
authorization_server.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
accessTokenEncryptedResponseAlgorithm?enumThe algorithm for encrypting access tokens issued by this authorization server. If this is requested, the response is signed, and then encrypted. The result is a nested JWT. The default, if omitted, is that no encryption is performed.
audiences?arrayThe recipients that the tokens are intended for. This becomes the `aud` claim in an access token. Okta currently supports only one audience.
credentials?object
description?stringThe description of the custom authorization server
issuer?stringThe complete URL for the custom authorization server. This becomes the `iss` claim in an access token.
issuerMode?stringIndicates which value is specified in the issuer of the tokens that a custom authorization server returns: the Okta org domain URL or a custom domain URL. `issuerMode` is visible if you have a custom URL domain configured or the Dynamic Issuer Mode feature enabled. If you have a custom URL domain co
jwks?objectA [JSON Web Key Set](https://tools.ietf.org/html/rfc7517#section-5) for encrypting JWTs minted by the custom authorization server
jwks_uri?stringURL string that references a JSON Web Key Set for encrypting JWTs minted by the custom authorization server
name?stringThe name of the custom authorization server
status?enum
_links?objectSpecifies link relations (see [Web Linking](https://www.rfc-editor.org/rfc/rfc8288)) available using the [JSON Hypertext Application Language](https://datatracker.ietf.org/doc/html/draft-kelly-json-hal-06) specification. This object is used for dynamic discovery of related resources and lifecycle op
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a authorization server
fn get(id: string)
Get a authorization server
ArgumentTypeDescription
idstringThe id of the authorization server
fn lookup(q?: string, max_items?: number)
List authorization servers and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
q?stringSearches the `name` and `audiences` of authorization servers for matching values
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update authorization server attributes
fn delete(id: string)
Delete the authorization server
ArgumentTypeDescription
idstringThe id of the authorization server
fn sync()
Sync authorization server state from Okta
fn activate(auth_server_id: string)
Activate an authorization server
ArgumentTypeDescription
auth_server_idstringPath parameter: auth_server_id
fn create_associated_servers(auth_server_id: string, trusted?: array)
Create an associated authorization server
ArgumentTypeDescription
auth_server_idstringPath parameter: auth_server_id
trusted?arrayA list of the authorization server IDs
fn create_credentials_key_rotate(auth_server_id: string, use?: enum)
Rotate all credential keys
ArgumentTypeDescription
auth_server_idstringPath parameter: auth_server_id
use?enumPurpose of the certificate. The only supported value is `sig`.
fn deactivate(auth_server_id: string)
Deactivate an authorization server
ArgumentTypeDescription
auth_server_idstringPath parameter: auth_server_id
fn delete_associated_servers(auth_server_id: string, associated_server_id: string)
Delete an associated authorization server
ArgumentTypeDescription
auth_server_idstringPath parameter: auth_server_id
associated_server_idstringPath parameter: associated_server_id
fn list_associated_servers(auth_server_id: string)
List all associated authorization servers
ArgumentTypeDescription
auth_server_idstringPath parameter: auth_server_id
fn list_clients(auth_server_id: string)
List all client resources for an authorization server
ArgumentTypeDescription
auth_server_idstringPath parameter: auth_server_id

Resources

state— Authorization server resource state
authorization_server_action— Authorization server action result
authorization_server_resource_key.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
auth_server_idstringPath scope for the authorization server resource key: auth_server_id
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
e?stringRSA key value (exponent) for key binding
kid?stringUnique identifier of the JSON web key in the custom authorization server's public JWKS
kty?stringCryptographic algorithm family for the certificate's key pair
n?stringRSA key value (modulus) for key binding
status?enumStatus of the JSON Web Key
use?stringAcceptable use of the JSON Web Key
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a authorization server resource key
fn get(id: string)
Get a authorization server resource key
ArgumentTypeDescription
idstringThe id of the authorization server resource key
fn lookup(max_items?: number)
List authorization server resource keys and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn delete(id: string)
Delete the authorization server resource key
ArgumentTypeDescription
idstringThe id of the authorization server resource key
fn sync()
Sync authorization server resource key state from Okta
fn activate(key_id: string)
Activate a Custom Authorization Server Public JSON Web Key
ArgumentTypeDescription
key_idstringPath parameter: key_id
fn deactivate(key_id: string)
Deactivate a Custom Authorization Server Public JSON Web Key
ArgumentTypeDescription
key_idstringPath parameter: key_id

Resources

state— Authorization server resource key resource state
authorization_server_resource_key_action— Authorization server resource key action result
authorization_servers_claim.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
auth_server_idstringPath scope for the authorization servers claim: auth_server_id
alwaysIncludeInToken?booleanSpecifies whether to include Claims in the token. The value is always `TRUE` for access token Claims. If the value is set to `FALSE` for an ID token claim, the Claim isn't included in the ID token when the token is requested with the access token or with the `authorization_code`. The client instead
claimType?enumSpecifies whether the Claim is for an access token (`RESOURCE`) or an ID token (`IDENTITY`)
conditions?objectSpecifies the scopes for the Claim
group_filter_type?enumSpecifies the type of group filter if `valueType` is `GROUPS` If `valueType` is `GROUPS`, then the groups returned are filtered according to the value of `group_filter_type`. If you have complex filters for Groups, you can [create a Groups allowlist](https://developer.okta.com/docs/guides/customize-
name?stringName of the Claim
status?enum
system?booleanWhen `true`, indicates that Okta created the Claim
value?stringSpecifies the value of the Claim. This value must be a string literal if `valueType` is `GROUPS`, and the string literal is matched with the selected `group_filter_type`. The value must be an Okta EL expression if `valueType` is `EXPRESSION`.
valueType?enumSpecifies whether the Claim is an Okta Expression Language (EL) expression (`EXPRESSION`), a set of groups (`GROUPS`), or a system claim (`SYSTEM`)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a authorization servers claim
fn get(id: string)
Get a authorization servers claim
ArgumentTypeDescription
idstringThe id of the authorization servers claim
fn lookup(max_items?: number)
List authorization servers claims and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update authorization servers claim attributes
fn delete(id: string)
Delete the authorization servers claim
ArgumentTypeDescription
idstringThe id of the authorization servers claim
fn sync()
Sync authorization servers claim state from Okta
authorization_servers_clients_token.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
auth_server_idstringPath scope for the authorization servers clients token: auth_server_id
client_idstringPath scope for the authorization servers clients token: client_id
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a authorization servers clients token
ArgumentTypeDescription
idstringThe id of the authorization servers clients token
fn lookup(expand?: string, max_items?: number)
List authorization servers clients tokens and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
expand?stringValid value: `scope`. If specified, scope details are included in the `_embedded` attribute.
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn delete(id: string)
Delete the authorization servers clients token
ArgumentTypeDescription
idstringThe id of the authorization servers clients token
fn sync()
Sync authorization servers clients token state from Okta
authorization_servers_credentials_key.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
auth_server_idstringPath scope for the authorization servers credentials key: auth_server_id
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a authorization servers credentials key
ArgumentTypeDescription
idstringThe id of the authorization servers credentials key
fn lookup(max_items?: number)
List authorization servers credentials keys and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn sync()
Sync authorization servers credentials key state from Okta
authorization_servers_policies_rule.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
auth_server_idstringPath scope for the authorization servers policies rule: auth_server_id
policy_idstringPath scope for the authorization servers policies rule: policy_id
actions?object
conditions?object
namestringName of the rule
priority?numberPriority of the rule
status?enumStatus of the rule
system?booleanSet to `true` for system rules. You can't delete system rules.
typeenumRule type
_links?objectSpecifies link relations (see [Web Linking](https://www.rfc-editor.org/rfc/rfc8288)) available using the [JSON Hypertext Application Language](https://datatracker.ietf.org/doc/html/draft-kelly-json-hal-06) specification. This object is used for dynamic discovery of related resources and lifecycle op
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a authorization servers policies rule
fn get(id: string)
Get a authorization servers policies rule
ArgumentTypeDescription
idstringThe id of the authorization servers policies rule
fn lookup(max_items?: number)
List authorization servers policies rules and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update authorization servers policies rule attributes
fn delete(id: string)
Delete the authorization servers policies rule
ArgumentTypeDescription
idstringThe id of the authorization servers policies rule
fn sync()
Sync authorization servers policies rule state from Okta
fn activate(rule_id: string)
Activate a policy rule
ArgumentTypeDescription
rule_idstringPath parameter: rule_id
fn deactivate(rule_id: string)
Deactivate a policy rule
ArgumentTypeDescription
rule_idstringPath parameter: rule_id

Resources

state— Authorization servers policies rule resource state
authorization_servers_policies_rule_action— Authorization servers policies rule action result
authorization_servers_policy.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
auth_server_idstringPath scope for the authorization servers policy: auth_server_id
id?stringID of the Policy
type?enumIndicates that the Policy is an authorization server Policy
name?stringName of the Policy
conditions?object
description?stringDescription of the Policy
priority?numberSpecifies the order in which this Policy is evaluated in relation to the other Policies in a custom authorization server
status?enumSpecifies whether requests have access to this Policy
system?booleanSpecifies whether Okta created this Policy
_links?objectSpecifies link relations (see [Web Linking](https://www.rfc-editor.org/rfc/rfc8288)) available using the [JSON Hypertext Application Language](https://datatracker.ietf.org/doc/html/draft-kelly-json-hal-06) specification. This object is used for dynamic discovery of related resources and lifecycle op
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a authorization servers policy
fn get(id: string)
Get a authorization servers policy
ArgumentTypeDescription
idstringThe id of the authorization servers policy
fn lookup(max_items?: number)
List authorization servers policys and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update authorization servers policy attributes
fn delete(id: string)
Delete the authorization servers policy
ArgumentTypeDescription
idstringThe id of the authorization servers policy
fn sync()
Sync authorization servers policy state from Okta
fn activate(policy_id: string)
Activate a policy
ArgumentTypeDescription
policy_idstringPath parameter: policy_id
fn deactivate(policy_id: string)
Deactivate a policy
ArgumentTypeDescription
policy_idstringPath parameter: policy_id

Resources

state— Authorization servers policy resource state
authorization_servers_policy_action— Authorization servers policy action result
authorization_servers_scope.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
auth_server_idstringPath scope for the authorization servers scope: auth_server_id
consent?enumIndicates whether a consent dialog is needed for the Scope
default?booleanIndicates if this Scope is a default scope
description?stringDescription of the Scope
displayName?stringName of the end user displayed in a consent dialog
metadataPublish?enumIndicates whether the Scope is included in the metadata
namestringScope name
optional?booleanIndicates whether the Scope is optional. When set to `true`, the user can skip consent for the scope.
system?booleanIndicates if Okta created the Scope
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a authorization servers scope
fn get(id: string)
Get a authorization servers scope
ArgumentTypeDescription
idstringThe id of the authorization servers scope
fn lookup(q?: string, filter?: string, max_items?: number)
List authorization servers scopes and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
q?stringSearches the `name` of Custom Token Scopes for matching values
filter?stringFilter expression for Custom Token Scopes
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update authorization servers scope attributes
fn delete(id: string)
Delete the authorization servers scope
ArgumentTypeDescription
idstringThe id of the authorization servers scope
fn sync()
Sync authorization servers scope state from Okta
brand.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
agreeToCustomPrivacyPolicy?booleanConsent for updating the custom privacy URL. Not required when resetting the URL.
customPrivacyPolicyUrl?stringCustom privacy policy URL
defaultApp?object
emailDomainId?stringThe ID of the email domain
locale?stringThe language specified as an [IETF BCP 47 language tag](https://datatracker.ietf.org/doc/html/rfc5646)
namestringThe name of the brand > **Note:** You can't use the reserved `DRAPP_DOMAIN_BRAND` name.
removePoweredByOkta?booleanRemoves "Powered by Okta" from the sign-in page in redirect authentication deployments, and "© [current year] Okta, Inc." from the Okta End-User Dashboard
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a brand
fn get(id: string)
Get a brand
ArgumentTypeDescription
idstringThe id of the brand
fn lookup(expand?: string, q?: string, max_items?: number)
List brands and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
expand?stringSpecifies additional metadata to be included in the response
q?stringSearches the records for matching value
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update brand attributes
fn delete(id: string)
Delete the brand
ArgumentTypeDescription
idstringThe id of the brand
fn sync()
Sync brand state from Okta
fn delete_pages_error_customized(brand_id: string)
Delete the customized error page
ArgumentTypeDescription
brand_idstringPath parameter: brand_id
fn delete_pages_error_preview(brand_id: string)
Delete the preview error page
ArgumentTypeDescription
brand_idstringPath parameter: brand_id
fn delete_pages_sign_in_customized(brand_id: string)
Delete the customized sign-in page
ArgumentTypeDescription
brand_idstringPath parameter: brand_id
fn delete_pages_sign_in_preview(brand_id: string)
Delete the preview sign-in page
ArgumentTypeDescription
brand_idstringPath parameter: brand_id
fn get_domains(brand_id: string)
List all domains associated with a brand
ArgumentTypeDescription
brand_idstringPath parameter: brand_id
fn get_pages_error(brand_id: string)
Retrieve the error page sub-resources
ArgumentTypeDescription
brand_idstringPath parameter: brand_id
fn get_pages_error_customized(brand_id: string)
Retrieve the customized error page
ArgumentTypeDescription
brand_idstringPath parameter: brand_id
fn get_pages_error_default(brand_id: string)
Retrieve the default error page
ArgumentTypeDescription
brand_idstringPath parameter: brand_id
fn get_pages_sign_in(brand_id: string)
Retrieve the sign-in page sub-resources
ArgumentTypeDescription
brand_idstringPath parameter: brand_id
fn get_pages_sign_in_customized(brand_id: string)
Retrieve the customized sign-in page
ArgumentTypeDescription
brand_idstringPath parameter: brand_id
fn get_pages_sign_in_default(brand_id: string)
Retrieve the default sign-in page
ArgumentTypeDescription
brand_idstringPath parameter: brand_id
fn get_pages_sign_out_customized(brand_id: string)
Retrieve the sign-out page settings
ArgumentTypeDescription
brand_idstringPath parameter: brand_id
fn list_pages_sign_in_widget_versions(brand_id: string)
List all Sign-In Widget versions
ArgumentTypeDescription
brand_idstringPath parameter: brand_id
fn pages_error_preview(brand_id: string)
Retrieve the preview error page preview
ArgumentTypeDescription
brand_idstringPath parameter: brand_id
fn pages_sign_in_preview(brand_id: string)
Retrieve the preview sign-in page preview
ArgumentTypeDescription
brand_idstringPath parameter: brand_id
fn update_pages_error_customized(brand_id: string, pageContent?: string, contentSecurityPolicySetting?: object)
Replace the customized error page
ArgumentTypeDescription
brand_idstringPath parameter: brand_id
pageContent?stringThe HTML for the page
contentSecurityPolicySetting?object
fn update_pages_sign_in_customized(brand_id: string, pageContent?: string, contentSecurityPolicySetting?: object, widgetCustomizations?: object, widgetVersion?: string)
Replace the customized sign-in page
ArgumentTypeDescription
brand_idstringPath parameter: brand_id
pageContent?stringThe HTML for the page
contentSecurityPolicySetting?object
widgetCustomizations?object
widgetVersion?stringThe version specified as a [Semantic Version](https://semver.org/). This value can be a wildcard (`*`), a major version range (for example, `^2`), a major-only version (for example, `7`), or a specific `Major.Minor` version (for example, `5.15`).
fn update_pages_sign_out_customized(brand_id: string, type: enum, url?: string)
Replace the sign-out page settings
ArgumentTypeDescription
brand_idstringPath parameter: brand_id
typeenum
url?string

Resources

state— Brand resource state
brand_action— Brand action result
brand_well_known_uri.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
brand_idstringPath scope for the brand well known uri: brand_id
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a brand well known uri
ArgumentTypeDescription
idstringThe id of the brand well known uri
fn lookup(max_items?: number)
List brand well known uris and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn sync()
Sync brand well known uri state from Okta
fn get_customized(path: string)
[LIMITED_GA — requires Okta Identity Engine] Retrieve the customized content of the specified well-known URI
ArgumentTypeDescription
pathstringPath parameter: path
fn update_customized(path: string, representation: record)
[LIMITED_GA — requires Okta Identity Engine] Replace the customized well-known URI of the specific path
ArgumentTypeDescription
pathstringPath parameter: path
representationrecordThe well-known URI content in JSON object format

Resources

state— Brand well known uri resource state
brand_well_known_uri_action— Brand well known uri action result
brands_theme.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
brand_idstringPath scope for the brands theme: brand_id
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
emailTemplateTouchPointVariantenumVariant for email templates. You can publish a theme for email templates with different combinations of assets. Variants are preset combinations of those assets.
endUserDashboardTouchPointVariantenumVariant for the Okta End-User Dashboard. You can publish a theme for end-user dashboard with different combinations of assets. Variants are preset combinations of those assets.
errorPageTouchPointVariantenumVariant for the error page. You can publish a theme for error page with different combinations of assets. Variants are preset combinations of those assets.
loadingPageTouchPointVariant?enumVariant for the Okta loading page. You can publish a theme for Okta loading page with different combinations of assets. Variants are preset combinations of those assets.
primaryColorContrastHex?stringPrimary color contrast hex code
primaryColorHexstringPrimary color hex code
secondaryColorContrastHex?stringSecondary color contrast hex code
secondaryColorHexstringSecondary color hex code
signInPageTouchPointVariantenumVariant for the Okta sign-in page. You can publish a theme for sign-in page with different combinations of assets. Variants are preset combinations of those assets. > **Note:** For a non-`OKTA_DEFAULT` variant, `primaryColorHex` is used for button background color and `primaryColorContrastHex` is us
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a brands theme
ArgumentTypeDescription
idstringThe id of the brands theme
fn lookup(max_items?: number)
List brands themes and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update brands theme attributes
fn sync()
Sync brands theme state from Okta
fn create_background_image(theme_id: string, file: string)
Upload the background image
ArgumentTypeDescription
theme_idstringPath parameter: theme_id
filestring
fn create_favicon(theme_id: string, file: string)
Upload the favicon
ArgumentTypeDescription
theme_idstringPath parameter: theme_id
filestring
fn create_logo(theme_id: string, file: string)
Upload the logo
ArgumentTypeDescription
theme_idstringPath parameter: theme_id
filestring
fn delete_background_image(theme_id: string)
Delete the background image
ArgumentTypeDescription
theme_idstringPath parameter: theme_id
fn delete_favicon(theme_id: string)
Delete the favicon
ArgumentTypeDescription
theme_idstringPath parameter: theme_id
fn delete_logo(theme_id: string)
Delete the logo
ArgumentTypeDescription
theme_idstringPath parameter: theme_id

Resources

state— Brands theme resource state
brands_theme_action— Brands theme action result
custom_domain.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
brandId?stringThe `id` of the brand used to replace the existing brand.
certificateSourceTypeenumCertificate source type that indicates whether the certificate is provided by the user or Okta.
domainstringCustom domain name > **Note:** You can't use the reserved `drapp.{yourOrgSubDomain}.okta.com` domain.
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a custom domain
fn get(id: string)
Get a custom domain
ArgumentTypeDescription
idstringThe id of the custom domain
fn lookup(max_items?: number)
List custom domains and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update custom domain attributes
fn delete(id: string)
Delete the custom domain
ArgumentTypeDescription
idstringThe id of the custom domain
fn sync()
Sync custom domain state from Okta
fn update_certificate(domain_id: string, certificate: string, certificateChain: string, privateKey: string, type: enum)
Upsert the custom domain
ArgumentTypeDescription
domain_idstringPath parameter: domain_id
certificatestringCertificate content
certificateChainstringCertificate chain
privateKeystringCertificate private key
typeenumCertificate type
fn verify(domain_id: string)
Verify a custom domain
ArgumentTypeDescription
domain_idstringPath parameter: domain_id

Resources

state— Custom domain resource state
custom_domain_action— Custom domain action result
email_bounce_removal.tsv2026.08.25.1

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
emailAddresses?arrayA list of email addresses to remove from the email-service bounce list
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a email bounce removal
email_customization.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
brand_idstringPath scope for the email customization: brand_id
template_namestringPath scope for the email customization: template_name
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
bodystringThe HTML body of the email. May contain [variable references](https://velocity.apache.org/engine/1.7/user-guide.html#references). <x-lifecycle class="ea"></x-lifecycle> Not required if Custom languages for Okta Email Templates is enabled. A `null` body is replaced with a default value from one of th
subjectstringThe email subject. May contain [variable references](https://velocity.apache.org/engine/1.7/user-guide.html#references). <x-lifecycle class="ea"></x-lifecycle> Not required if Custom languages for Okta Email Templates is enabled. A `null` subject is replaced with a default value from one of the foll
isDefault?booleanWhether this is the default customization for the email template. Each customized email template must have exactly one default customization. Defaults to `true` for the first customization and `false` thereafter.
languagestringThe language specified as an [IETF BCP 47 language tag](https://datatracker.ietf.org/doc/html/rfc5646)
_links?objectSpecifies link relations (see [Web Linking](https://www.rfc-editor.org/rfc/rfc8288)) available using the [JSON Hypertext Application Language](https://datatracker.ietf.org/doc/html/draft-kelly-json-hal-06) specification. This object is used for dynamic discovery of related resources and lifecycle op
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a email customization
fn get(id: string)
Get a email customization
ArgumentTypeDescription
idstringThe id of the email customization
fn lookup(max_items?: number)
List email customizations and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update email customization attributes
fn delete(id: string)
Delete the email customization
ArgumentTypeDescription
idstringThe id of the email customization
fn sync()
Sync email customization state from Okta
fn preview(customization_id: string)
Retrieve a preview of an email customization
ArgumentTypeDescription
customization_idstringPath parameter: customization_id

Resources

state— Email customization resource state
email_customization_action— Email customization action result
email_domain.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
displayNamestring
userNamestring
brandIdstring
domainstring
validationSubdomain?stringSubdomain for the email sender's custom mail domain. Specify your subdomain when you configure a custom mail domain.
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a email domain
fn get(id: string)
Get a email domain
ArgumentTypeDescription
idstringThe id of the email domain
fn lookup(max_items?: number)
List email domains and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update email domain attributes
fn delete(id: string)
Delete the email domain
ArgumentTypeDescription
idstringThe id of the email domain
fn sync()
Sync email domain state from Okta
fn verify(email_domain_id: string)
Verify an email domain
ArgumentTypeDescription
email_domain_idstringPath parameter: email_domain_id

Resources

state— Email domain resource state
email_domain_action— Email domain action result
email_server.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
aliasstringHuman-readable name for your SMTP server
authTypeenum<x-lifecycle-container><x-lifecycle class="ea"></x-lifecycle> <x-lifecycle class="oie"></x-lifecycle></x-lifecycle-container>The authentication type that\'s used by your SMTP server
enabledbooleanIf `true`, all email traffic is routed through your SMTP server
hoststringHostname or IP address of your SMTP server
portnumberPort number of your SMTP server
usernamestringUsername that's used to access your SMTP server
password?stringThe password of the user account that's used to sign in to your SMTP server
clientId?stringThe client ID that's used to access your SMTP server. This client ID is obtained when you create an OAuth 2.0 app with your email provider.
clientSecret?stringThe client secret that's used to access your SMTP server. This client secret is obtained when you create an OAuth 2.0 app with your email provider.
scopes?arrayList of OAuth 2.0 scopes for your SMTP server. You must provide a scope that allows your email server to send emails.
tokenEndpoint?stringThe email provider's specific URL where the OAuth 2.0 app sends its credentials (or signed JWT) to exchange them for an access token
tokenEndpointAuthMethod?enumThis method determines how your OAuth 2.0 app sends its credentials (`client_id` and `client_secret`) to the provider's server when requesting an access token.
audience?stringThe URI of the authorization server that verifies the token. This is typically the token URI of your JWT.
issuer?stringThe unique ID of the entity that creates the JWT. This can sometimes be the email address of the user who creates the JWT. Check with your email provider for the correct value.
keyId?stringThe ID of the private key that's used to sign the JWT
privateKey?stringThe secret RSA key that's used to cryptographically sign the JWT
signingAlgorithm?enumThe signing algorithm that's used to sign the JWT
subject?stringThe email address of the user account that the OAuth 2.0 app impersonates to send emails
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a email server
fn get(id: string)
Get a email server
ArgumentTypeDescription
idstringThe id of the email server
fn lookup(max_items?: number)
List email servers and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update email server attributes
fn delete(id: string)
Delete the email server
ArgumentTypeDescription
idstringThe id of the email server
fn sync()
Sync email server state from Okta
fn test(email_server_id: string, fromAddress: string, toAddress: string)
Test an SMTP server configuration
ArgumentTypeDescription
email_server_idstringPath parameter: email_server_id
fromAddressstringEmail address that sends test emails
toAddressstringEmail address that receives test emails

Resources

state— Email server resource state
email_server_action— Email server action result
email_template.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
brand_idstringPath scope for the email template: brand_id
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a email template
ArgumentTypeDescription
idstringThe name of the email template
fn lookup(expand?: string, max_items?: number)
List email templates and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
expand?stringSpecifies additional metadata to be included in the response
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn sync()
Sync email template state from Okta
fn default_content_preview(template_name: string)
Retrieve a preview of the email template default content
ArgumentTypeDescription
template_namestringPath parameter: template_name
fn get_default_content(template_name: string)
Retrieve an email template default content
ArgumentTypeDescription
template_namestringPath parameter: template_name
fn get_settings(template_name: string)
Retrieve the email template settings
ArgumentTypeDescription
template_namestringPath parameter: template_name
fn test(template_name: string)
Send a test email
ArgumentTypeDescription
template_namestringPath parameter: template_name
fn update_settings(template_name: string, recipients: enum)
Replace the email template settings
ArgumentTypeDescription
template_namestringPath parameter: template_name
recipientsenum

Resources

state— Email template resource state
email_template_action— Email template action result
event_hook.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
channel?object
description?stringDescription of the event hook
events?object
namestringDisplay name for the event hook
_links?objectSpecifies link relations (see [Web Linking](https://www.rfc-editor.org/rfc/rfc8288)) available using the [JSON Hypertext Application Language](https://datatracker.ietf.org/doc/html/draft-kelly-json-hal-06) specification. This object is used for dynamic discovery of related resources and lifecycle op
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a event hook
fn get(id: string)
Get a event hook
ArgumentTypeDescription
idstringThe id of the event hook
fn lookup(max_items?: number)
List event hooks and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update event hook attributes
fn delete(id: string)
Delete the event hook
ArgumentTypeDescription
idstringThe id of the event hook
fn sync()
Sync event hook state from Okta
fn activate(event_hook_id: string)
Activate an event hook
ArgumentTypeDescription
event_hook_idstringPath parameter: event_hook_id
fn deactivate(event_hook_id: string)
Deactivate an event hook
ArgumentTypeDescription
event_hook_idstringPath parameter: event_hook_id
fn verify(event_hook_id: string)
Verify an event hook
ArgumentTypeDescription
event_hook_idstringPath parameter: event_hook_id

Resources

state— Event hook resource state
event_hook_action— Event hook action result
group.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
profile?objectProfile for any group that is not imported from Active Directory. Specifies the standard and custom profile properties for a group. The `objectClass` for these groups is `okta:user_group`. You can extend group profiles with custom properties, but you must first add the properties to the group profil
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a group
fn get(id: string)
Get a group
ArgumentTypeDescription
idstringThe id of the group
fn lookup(search?: string, filter?: string, q?: string, expand?: string, sortBy?: string, sortOrder?: string, max_items?: number)
List groups and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
search?stringSearches for groups with a supported [filtering](https://developer.okta.com/docs/api/#filter) expression for all properties except for `_embedded`, `_links`, and `objectClass`. Okta recommends this query parameter because it provides the largest range of search options and optimal performance. This
filter?stringFilter expression for groups. See [Filter](https://developer.okta.com/docs/api/#filter). Filtering supports the following limited number of properties: `id`, `type`, `lastUpdated`, and `lastMembershipUpdated`. > **Note:** All filters must be [URL encoded](https://developer.mozilla.org/en-US/docs/Glo
q?stringFinds a group that matches the `name` property. > **Note:** Paging and searching are currently mutually exclusive. You can't page a query. The default limit for a query is 300 results. Query is intended for an auto-complete picker use case where users refine their search string to constrain the resu
expand?stringIf specified, additional metadata is included in the response. Possible values are `stats` and `app`. This additional metadata is listed in the [`_embedded`](https://developer.okta.com/docs/api/openapi/okta-management/management/tag/Group/#tag/Group/operation/addGroup!c=200&path=_embedded&t=response
sortBy?stringSpecifies the field to sort by (for search queries only). `sortBy` can be any single property, for example `sortBy=profile.name`. Groups with the same value for the `sortBy` property are ordered by `id`'. Use with `sortOrder` to control the order of results.
sortOrder?stringSpecifies sort order: `asc` or `desc` (for search queries only). This parameter is ignored if `sortBy` isn't present.
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update group attributes
fn delete(id: string)
Delete the group
ArgumentTypeDescription
idstringThe id of the group
fn sync()
Sync group state from Okta
fn create_owners(group_id: string, id?: string, type?: enum)
Assign a group owner
ArgumentTypeDescription
group_idstringPath parameter: group_id
id?stringThe `id` of the group owner
type?enumThe entity type of the owner
fn delete_owners(group_id: string, owner_id: string)
Delete a group owner
ArgumentTypeDescription
group_idstringPath parameter: group_id
owner_idstringPath parameter: owner_id
fn delete_users(group_id: string, user_id: string)
Unassign a user from a group
ArgumentTypeDescription
group_idstringPath parameter: group_id
user_idstringPath parameter: user_id
fn list_apps(group_id: string)
List all assigned apps
ArgumentTypeDescription
group_idstringPath parameter: group_id
fn list_owners(group_id: string)
List all group owners
ArgumentTypeDescription
group_idstringPath parameter: group_id
fn list_users(group_id: string)
List all member users
ArgumentTypeDescription
group_idstringPath parameter: group_id
fn update_users(group_id: string, user_id: string)
Assign a user to a group
ArgumentTypeDescription
group_idstringPath parameter: group_id
user_idstringPath parameter: user_id

Resources

state— Group resource state
group_action— Group action result
group_schema.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
definitions?object
description?stringDescription for the schema
properties?objectGroup object properties
title?stringUser-defined display name for the schema
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a group schema
fn lookup(max_items?: number)
List group schemas and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
groups_rule.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
actions?objectDefines which users and groups to assign
conditions?objectDefines group rule conditions
name?stringName of the group rule
status?enumStatus of group rule. You can't update the status of a rule from `INACTIVE` to `ACTIVE`. You must use the activate and deactivate lifecycle operations.
type?enum
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a groups rule
fn get(id: string)
Get a groups rule
ArgumentTypeDescription
idstringThe id of the groups rule
fn lookup(search?: string, expand?: enum, max_items?: number)
List groups rules and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
search?stringSpecifies the keyword to search rules for
expand?enumIf specified, returns the mapping of group IDs to group names in the `_embedded` object.
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update groups rule attributes
fn delete(id: string)
Delete the groups rule
ArgumentTypeDescription
idstringThe id of the groups rule
fn sync()
Sync groups rule state from Okta
fn activate(group_rule_id: string)
Activate a group rule
ArgumentTypeDescription
group_rule_idstringPath parameter: group_rule_id
fn deactivate(group_rule_id: string)
Deactivate a group rule
ArgumentTypeDescription
group_rule_idstringPath parameter: group_rule_id

Resources

state— Groups rule resource state
groups_rule_action— Groups rule action result
hook_key.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
name?stringDisplay name for the key
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a hook key
fn get(id: string)
Get a hook key
ArgumentTypeDescription
idstringThe id of the hook key
fn lookup(max_items?: number)
List hook keys and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update hook key attributes
fn delete(id: string)
Delete the hook key
ArgumentTypeDescription
idstringThe id of the hook key
fn sync()
Sync hook key state from Okta
hook_key_public.tsv2026.08.25.1

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a hook key public
ArgumentTypeDescription
idstringThe id of the hook key public
fn sync()
Sync hook key public state from Okta
identity_provider.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
issuerMode?enumIndicates whether Okta uses the original Okta org domain URL or a custom domain URL in the request to the social IdP
name?stringUnique name for the IdP
policy?objectPolicy settings for the IdP. The following provisioning and account linking actions are supported by each IdP provider: | IdP type | User provisioning actions | Group provisioning actions | Account link actions | Account link filters | | --------------------------------------------------------------
properties?objectThe properties in the IdP `properties` object vary depending on the IdP type
protocol?objectIdP-specific protocol settings for endpoints, bindings, and algorithms used to connect with the IdP and validate messages
status?enum
type?enumThe IdP object's `type` property identifies the social or enterprise IdP used for authentication. Each IdP uses a specific protocol, therefore the `protocol` object must correspond with the IdP `type`. If the protocol is OAuth 2.0-based, the `protocol` object's `scopes` property must also correspond
_links?objectSpecifies link relations (see [Web Linking](https://www.rfc-editor.org/rfc/rfc8288)) available using the [JSON Hypertext Application Language](https://datatracker.ietf.org/doc/html/draft-kelly-json-hal-06) specification. This object is used for dynamic discovery of related resources and lifecycle op
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a identity provider
fn get(id: string)
Get a identity provider
ArgumentTypeDescription
idstringThe id of the identity provider
fn lookup(q?: string, type?: enum, max_items?: number)
List identity providers and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
q?stringSearches the `name` property of IdPs for matching value
type?enumFilters IdPs by `type`
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update identity provider attributes
fn delete(id: string)
Delete the identity provider
ArgumentTypeDescription
idstringThe id of the identity provider
fn sync()
Sync identity provider state from Okta
fn activate(idp_id: string)
Activate an IdP
ArgumentTypeDescription
idp_idstringPath parameter: idp_id
fn deactivate(idp_id: string)
Deactivate an IdP
ArgumentTypeDescription
idp_idstringPath parameter: idp_id

Resources

state— Identity provider resource state
identity_provider_action— Identity provider action result
identity_sources_group.tsv2026.08.25.1

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
identity_source_idstringPath scope for the identity sources group: identity_source_id
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
externalId?stringThe external ID of the identity source group to be created
profile?objectContains a set of external group attributes and their values that are mapped to Okta standard properties. See the group [`profile` object](https://developer.okta.com/docs/api/openapi/okta-management/management/tag/Group/#tag/Group/operation/getGroup!c=200&path=profile&t=response) and Declaration of
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a identity sources group
fn get(id: string)
Get a identity sources group
ArgumentTypeDescription
idstringThe id of the identity sources group
fn update()
Update identity sources group attributes
fn delete(id: string)
Delete the identity sources group
ArgumentTypeDescription
idstringThe id of the identity sources group
fn sync()
Sync identity sources group state from Okta
fn create_membership(group_or_external_id: string, memberExternalId?: string)
Create the memberships for the given identity source group
ArgumentTypeDescription
group_or_external_idstringPath parameter: group_or_external_id
memberExternalId?stringThe external ID of the user to be added as a member of the group in Okta
fn delete_membership(group_or_external_id: string, member_external_id: string)
Delete the memberships for the specified identity source group
ArgumentTypeDescription
group_or_external_idstringPath parameter: group_or_external_id
member_external_idstringPath parameter: member_external_id
fn get_membership(group_or_external_id: string)
Retrieve the memberships for the given identity source group
ArgumentTypeDescription
group_or_external_idstringPath parameter: group_or_external_id

Resources

state— Identity sources group resource state
identity_sources_group_action— Identity sources group action result
identity_sources_session.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
identity_source_idstringPath scope for the identity sources session: identity_source_id
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a identity sources session
fn get(id: string)
Get a identity sources session
ArgumentTypeDescription
idstringThe id of the identity sources session
fn lookup(max_items?: number)
List identity sources sessions and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn delete(id: string)
Delete the identity sources session
ArgumentTypeDescription
idstringThe id of the identity sources session
fn sync()
Sync identity sources session state from Okta
fn create_bulk_delete(session_id: string, entityType?: enum, profiles?: array)
Upload the data to be deleted in Okta
ArgumentTypeDescription
session_idstringPath parameter: session_id
entityType?enumThe type of data to bulk delete in a session. Currently, only `USERS` is supported.
profiles?arrayArray of profiles to be deleted
fn create_bulk_group_memberships_delete(session_id: string, memberships?: array)
Upload the group memberships to be deleted in Okta
ArgumentTypeDescription
session_idstringPath parameter: session_id
memberships?arrayArray of group memberships that need to be deleted in Okta
fn create_bulk_group_memberships_upsert(session_id: string, memberships?: array)
Upload the group memberships to be upserted in Okta
ArgumentTypeDescription
session_idstringPath parameter: session_id
memberships?arrayArray of group memberships that need to be inserted or updated in Okta
fn create_bulk_groups_delete(session_id: string, externalIds?: array)
Upload the group external IDs to be deleted in Okta
ArgumentTypeDescription
session_idstringPath parameter: session_id
externalIds?arrayArray of external IDs of groups that need to be deleted in Okta
fn create_bulk_groups_upsert(session_id: string, profiles?: array)
Upload the group profiles without memberships to be upserted in Okta
ArgumentTypeDescription
session_idstringPath parameter: session_id
profiles?arrayArray of group profiles that needs to be inserted or updated in Okta
fn create_bulk_upsert(session_id: string, entityType?: enum, profiles?: array)
Upload the data to be upserted in Okta
ArgumentTypeDescription
session_idstringPath parameter: session_id
entityType?enumThe type of data to upsert into the session. Currently, only `USERS` is supported.
profiles?arrayArray of user profiles to be uploaded
fn create_start_import(session_id: string)
Start the import from the identity source
ArgumentTypeDescription
session_idstringPath parameter: session_id

Resources

state— Identity sources session resource state
identity_sources_session_action— Identity sources session action result
identity_sources_user.tsv2026.08.25.1

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
identity_source_idstringPath scope for the identity sources user: identity_source_id
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
externalId?stringThe external ID of the user in the identity source
profile?objectContains a set of external user attributes and their values that are mapped to Okta standard and custom profile properties. See the [`profile` object](https://developer.okta.com/docs/api/openapi/okta-management/management/user/getuser#user/getuser/t=response&c=200&path=profile) and Declaration of a
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a identity sources user
fn get(id: string)
Get a identity sources user
ArgumentTypeDescription
idstringThe id of the identity sources user
fn update()
Update identity sources user attributes
fn delete(id: string)
Delete the identity sources user
ArgumentTypeDescription
idstringThe id of the identity sources user
fn sync()
Sync identity sources user state from Okta
fn set_external_id(external_id: string, profile?: object)
Update an identity source user
ArgumentTypeDescription
external_idstringPath parameter: external_id
profile?objectContains a set of external user attributes and their values that are mapped to Okta standard and custom profile properties. See the [`profile` object](https://developer.okta.com/docs/api/openapi/okta-management/management/user/getuser#user/getuser/t=response&c=200&path=profile) and Declaration of a

Resources

state— Identity sources user resource state
identity_sources_user_action— Identity sources user action result
idps_credentials_csr.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
idp_idstringPath scope for the idps credentials csr: idp_id
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
subject?object
subjectAltNames?object
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a idps credentials csr
fn get(id: string)
Get a idps credentials csr
ArgumentTypeDescription
idstringThe id of the idps credentials csr
fn lookup(max_items?: number)
List idps credentials csrs and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn delete(id: string)
Delete the idps credentials csr
ArgumentTypeDescription
idstringThe id of the idps credentials csr
fn sync()
Sync idps credentials csr state from Okta
fn publish(idp_csr_id: string, certificate: string)
Publish a certificate signing request
ArgumentTypeDescription
idp_csr_idstringPath parameter: idp_csr_id
certificatestringRaw certificate body, in the format named by the endpoint's content type

Resources

state— Idps credentials csr resource state
idps_credentials_csr_action— Idps credentials csr action result
idps_credentials_key.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
idp_idstringPath scope for the idps credentials key: idp_id
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a idps credentials key
ArgumentTypeDescription
idstringThe id of the idps credentials key
fn lookup(max_items?: number)
List idps credentials keys and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn sync()
Sync idps credentials key state from Okta
fn clone(kid: string)
Clone a signing key credential for IdP
ArgumentTypeDescription
kidstringPath parameter: kid
fn create_generate()
Generate a new signing key credential for IdP
fn list_active()
List the active signing key credential for IdP

Resources

state— Idps credentials key resource state
idps_credentials_key_action— Idps credentials key action result
idps_user.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
idp_idstringPath scope for the idps user: idp_id
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
externalId?stringUnique IdP-specific identifier for a user
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a idps user
ArgumentTypeDescription
idstringThe id of the idps user
fn lookup(q?: string, expand?: string, max_items?: number)
List idps users and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
q?stringSearches the records for matching value
expand?stringExpand user data
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update idps user attributes
fn delete(id: string)
Delete the idps user
ArgumentTypeDescription
idstringThe id of the idps user
fn sync()
Sync idps user state from Okta
fn list_credentials_tokens(user_id: string)
List all tokens from OIDC IdP
ArgumentTypeDescription
user_idstringPath parameter: user_id

Resources

state— Idps user resource state
idps_user_action— Idps user action result
inline_hook.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
channel?object
name?stringThe display name of the inline hook
version?stringVersion of the inline hook type. The currently supported version is `1.0.0`.
type?enumOne of the inline hook types
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a inline hook
fn get(id: string)
Get a inline hook
ArgumentTypeDescription
idstringThe id of the inline hook
fn lookup(type?: enum, max_items?: number)
List inline hooks and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
type?enumOne of the supported inline hook types
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update inline hook attributes
fn delete(id: string)
Delete the inline hook
ArgumentTypeDescription
idstringThe id of the inline hook
fn sync()
Sync inline hook state from Okta
fn activate(inline_hook_id: string)
Activate an inline hook
ArgumentTypeDescription
inline_hook_idstringPath parameter: inline_hook_id
fn add_inline_hook_id(inline_hook_id: string, channel?: object, name?: string, version?: string)
Update an inline hook
ArgumentTypeDescription
inline_hook_idstringPath parameter: inline_hook_id
channel?object
name?stringThe display name of the inline hook
version?stringVersion of the inline hook type. The currently supported version is `1.0.0`.
fn deactivate(inline_hook_id: string)
Deactivate an inline hook
ArgumentTypeDescription
inline_hook_idstringPath parameter: inline_hook_id
fn execute(id: string)
Execute an inline hook
ArgumentTypeDescription
idstringThe id of the inline hook

Resources

state— Inline hook resource state
inline_hook_action— Inline hook action result
linked_object_definition.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
associated?object
primary?object
_links?objectSpecifies link relations (see [Web Linking](https://www.rfc-editor.org/rfc/rfc8288)) available for the current status of an application using the [JSON Hypertext Application Language](https://datatracker.ietf.org/doc/html/draft-kelly-json-hal-06) specification. This object is used for dynamic discov
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a linked object definition
fn get(id: string)
Get a linked object definition
ArgumentTypeDescription
idstringThe id of the linked object definition
fn lookup(max_items?: number)
List linked object definitions and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn delete(id: string)
Delete the linked object definition
ArgumentTypeDescription
idstringThe id of the linked object definition
fn sync()
Sync linked object definition state from Okta
log.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn lookup(since?: string, until?: string, filter?: string, q?: string, sortOrder?: enum, max_items?: number)
List logs and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
since?stringFilters the lower time bound of the log events `published` property for bounded queries or persistence time for polling queries
until?stringFilters the upper time bound of the log events `published` property for bounded queries or persistence time for polling queries.
filter?stringFilter expression that filters the results. All operators except [ ] are supported. See [Filter](https://developer.okta.com/docs/api/#filter) and [Operators](https://developer.okta.com/docs/api/#operators).
q?stringFilters log events results by one or more case insensitive keywords.
sortOrder?enumThe order of the returned events that are sorted by the `published` property
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
log_stream.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
namestringUnique name for the log stream object
typeenumSpecifies the streaming provider used Supported providers: * `aws_eventbridge` ([AWS EventBridge](https://aws.amazon.com/eventbridge)) * `splunk_cloud_logstreaming` ([Splunk Cloud](https://www.splunk.com/en_us/software/splunk-cloud-platform.html)) Select the provider type to see provider-specific co
settingsobjectSpecifies the configuration for the `splunk_cloud_logstreaming` log stream type.
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a log stream
fn get(id: string)
Get a log stream
ArgumentTypeDescription
idstringThe id of the log stream
fn lookup(filter?: string, max_items?: number)
List log streams and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
filter?stringAn expression that [filters](/#filter) the returned objects. You can only use the `eq` operator on either the `status` or `type` properties in the filter expression.
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update log stream attributes
fn delete(id: string)
Delete the log stream
ArgumentTypeDescription
idstringThe id of the log stream
fn sync()
Sync log stream state from Okta
fn activate(log_stream_id: string)
Activate a log stream
ArgumentTypeDescription
log_stream_idstringPath parameter: log_stream_id
fn deactivate(log_stream_id: string)
Deactivate a log stream
ArgumentTypeDescription
log_stream_idstringPath parameter: log_stream_id

Resources

state— Log stream resource state
log_stream_action— Log stream action result
log_stream_schema.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a log stream schema
ArgumentTypeDescription
idstringThe id of the log stream schema
fn lookup(max_items?: number)
List log stream schemas and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn sync()
Sync log stream schema state from Okta
org_idps_credentials_key.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
e?stringThe exponent value for the RSA public key
kid?stringUnique identifier for the key
kty?stringIdentifies the cryptographic algorithm family used with the key
n?stringThe modulus value for the RSA public key
use?stringIntended use of the public key
x5carrayBase64-encoded X.509 certificate chain with DER encoding
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a org idps credentials key
fn get(id: string)
Get a org idps credentials key
ArgumentTypeDescription
idstringThe id of the org idps credentials key
fn lookup(max_items?: number)
List org idps credentials keys and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update org idps credentials key attributes
fn delete(id: string)
Delete the org idps credentials key
ArgumentTypeDescription
idstringThe id of the org idps credentials key
fn sync()
Sync org idps credentials key state from Okta
policies_mapping.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
policy_idstringPath scope for the policies mapping: policy_id
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
resourceId?string[Policy ID](https://developer.okta.com/docs/api/openapi/okta-management/management/tags/policy/#tag/Policy/operation/listPolicies!c=200&path=0/id&t=response) of the app sign-in policy that you want to map
resourceType?enumSpecifies the type of resource to map. You can only map an app sign-in policy to a device signal collection policy (the `policyId` path parameter).
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a policies mapping
fn get(id: string)
Get a policies mapping
ArgumentTypeDescription
idstringThe id of the policies mapping
fn lookup(max_items?: number)
List policies mappings and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn delete(id: string)
Delete the policies mapping
ArgumentTypeDescription
idstringThe id of the policies mapping
fn sync()
Sync policies mapping state from Okta
policies_rule.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
policy_idstringPath scope for the policies rule: policy_id
name?stringName of the rule
priority?numberPriority of the rule
status?stringWhether or not the rule is active. Use the `activate` query parameter to set the status of a rule.
system?booleanSpecifies whether Okta created the policy rule (`system=true`). You can't delete policy rules that have `system` set to `true`.
type?enumRule type
actions?object<x-lifecycle-container><x-lifecycle class="ea"></x-lifecycle> <x-lifecycle class="oie"></x-lifecycle></x-lifecycle-container>Specifies actions to be taken, or operations that may be allowed, if the rule conditions are satisfied
conditions?stringPolicy rule conditions aren't supported for this policy type.
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a policies rule
fn get(id: string)
Get a policies rule
ArgumentTypeDescription
idstringThe id of the policies rule
fn lookup(max_items?: number)
List policies rules and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update policies rule attributes
fn delete(id: string)
Delete the policies rule
ArgumentTypeDescription
idstringThe id of the policies rule
fn sync()
Sync policies rule state from Okta
fn activate(rule_id: string)
Activate a policy rule
ArgumentTypeDescription
rule_idstringPath parameter: rule_id
fn deactivate(rule_id: string)
Deactivate a policy rule
ArgumentTypeDescription
rule_idstringPath parameter: rule_id

Resources

state— Policies rule resource state
policies_rule_action— Policies rule action result
policy.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
description?stringDescription of the policy
namestringName of the policy
priority?numberSpecifies the order in which this policy is evaluated in relation to the other policies
status?stringWhether or not the policy is active. Use the `activate` query parameter to set the status of a policy.
system?booleanSpecifies whether Okta created the policy
typeenumAll Okta orgs contain only one IdP discovery policy with an immutable default rule routing to your org's sign-in page. All Okta orgs also contain just one entity risk policy, one session protection policy, and one identity claims sourcing policy.
_embedded?object
conditions?stringPolicy conditions aren't supported. Conditions are applied at the rule level for this policy type.
settings?objectSpecifies the policy level settings
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a policy
fn get(id: string)
Get a policy
ArgumentTypeDescription
idstringThe id of the policy
fn lookup(type?: enum, status?: string, q?: string, expand?: string, sortBy?: string, resourceId?: string, max_items?: number)
List policys and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
type?enumSpecifies the type of policy to return
status?stringRefines the query by the `status` of the policy - `ACTIVE` or `INACTIVE`
q?stringRefines the query by policy name prefix (startWith method) passed in as `q=string`
expand?string
sortBy?stringRefines the query by sorting on the policy `name` in ascending order
resourceId?stringReference to the associated authorization server
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update policy attributes
fn delete(id: string)
Delete the policy
ArgumentTypeDescription
idstringThe id of the policy
fn sync()
Sync policy state from Okta
fn activate(policy_id: string)
Activate a policy
ArgumentTypeDescription
policy_idstringPath parameter: policy_id
fn clone(policy_id: string)
[LIMITED_GA — requires Okta Identity Engine] Clone an existing policy
ArgumentTypeDescription
policy_idstringPath parameter: policy_id
fn create_simulate()
[LIMITED_GA — requires Okta Identity Engine] Create a policy simulation
fn deactivate(policy_id: string)
Deactivate a policy
ArgumentTypeDescription
policy_idstringPath parameter: policy_id

Resources

state— Policy resource state
policy_action— Policy action result
profile_mapping.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
properties?objectA target property, in string form, that maps to a valid [JSON Schema Draft](https://tools.ietf.org/html/draft-zyp-json-schema-04) document.
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a profile mapping
ArgumentTypeDescription
idstringThe id of the profile mapping
fn lookup(sourceId?: string, targetId?: string, max_items?: number)
List profile mappings and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
sourceId?stringThe user type or app instance ID that acts as the source of expressions in a mapping. If this parameter is included, all returned mappings have this as their `source.id`.
targetId?stringThe user type or app instance ID that acts as the target of expressions in a mapping. If this parameter is included, all returned mappings have this as their `target.id`.
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update profile mapping attributes
fn sync()
Sync profile mapping state from Okta
push_provider.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
name?stringDisplay name of the push provider
providerType?enum
configuration?object
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a push provider
fn get(id: string)
Get a push provider
ArgumentTypeDescription
idstringThe id of the push provider
fn lookup(type?: enum, max_items?: number)
List push providers and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
type?enumFilters push providers by `providerType`
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update push provider attributes
fn delete(id: string)
Delete the push provider
ArgumentTypeDescription
idstringThe id of the push provider
fn sync()
Sync push provider state from Okta
realm.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
profile?object
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a realm
fn get(id: string)
Get a realm
ArgumentTypeDescription
idstringThe id of the realm
fn lookup(search?: string, sortBy?: string, sortOrder?: string, max_items?: number)
List realms and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
search?stringSearches for realms with a supported filtering expression for most properties. Searches for realms can be filtered by the contains (`co`) operator. You can only use `co` with the `profile.name` property. See [Operators](https://developer.okta.com/docs/api/#operators).
sortBy?stringSpecifies the field to sort by and can be any single property (for search queries only)
sortOrder?stringSpecifies sort order: `asc` or `desc` (for search queries only). This parameter is ignored if `sortBy` isn't present.
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update realm attributes
fn delete(id: string)
Delete the realm
ArgumentTypeDescription
idstringThe id of the realm
fn sync()
Sync realm state from Okta
realm_assignment.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
actions?objectAction to apply to a user
conditions?objectConditions of applying realm assignment
name?stringName of the realm
priority?numberThe priority of the realm assignment. The lower the number, the higher the priority. This helps resolve conflicts between realm assignments. > **Note:** When you create realm assignments in bulk, realm assignment priorities must be unique.
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a realm assignment
fn get(id: string)
Get a realm assignment
ArgumentTypeDescription
idstringThe id of the realm assignment
fn lookup(max_items?: number)
List realm assignments and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update realm assignment attributes
fn delete(id: string)
Delete the realm assignment
ArgumentTypeDescription
idstringThe id of the realm assignment
fn sync()
Sync realm assignment state from Okta
fn activate(assignment_id: string)
Activate a realm assignment
ArgumentTypeDescription
assignment_idstringPath parameter: assignment_id
fn create_operations(assignmentId?: string)
Execute a realm assignment
ArgumentTypeDescription
assignmentId?stringID of the realm
fn deactivate(assignment_id: string)
Deactivate a realm assignment
ArgumentTypeDescription
assignment_idstringPath parameter: assignment_id
fn list_operations()
List all realm assignment operations

Resources

state— Realm assignment resource state
realm_assignment_action— Realm assignment action result
roles_subscription.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
role_refstringPath scope for the roles subscription: role_ref
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a roles subscription
ArgumentTypeDescription
idstringThe notificationType of the roles subscription
fn lookup(max_items?: number)
List roles subscriptions and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn sync()
Sync roles subscription state from Okta
fn create_subscribe(notification_type: string)
Subscribe a role to a specific notification type
ArgumentTypeDescription
notification_typestringPath parameter: notification_type
fn create_unsubscribe(notification_type: string)
Unsubscribe a role from a specific notification type
ArgumentTypeDescription
notification_typestringPath parameter: notification_type

Resources

state— Roles subscription resource state
roles_subscription_action— Roles subscription action result
session.tsv2026.08.25.1

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a session
ArgumentTypeDescription
idstringThe id of the session
fn delete(id: string)
Delete the session
ArgumentTypeDescription
idstringThe id of the session
fn sync()
Sync session state from Okta
fn refresh(session_id: string)
Refresh a session
ArgumentTypeDescription
session_idstringPath parameter: session_id

Resources

state— Session resource state
session_action— Session action result
sms_template.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
name?stringHuman-readable name of the Template
template?stringText of the Template, including any [macros](https://developer.okta.com/docs/api/openapi/okta-management/management/tag/Template/)
translations?record- Template translations are optionally provided when you want to localize the SMS messages. Translations are provided as an object that contains `key:value` pairs: the language and the translated Template text. The key portion is a two-letter country code that conforms to [ISO 639-1](https://www.loc
type?enumType of the Template
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a sms template
fn get(id: string)
Get a sms template
ArgumentTypeDescription
idstringThe id of the sms template
fn lookup(templateType?: enum, max_items?: number)
List sms templates and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
templateType?enum
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update sms template attributes
fn delete(id: string)
Delete the sms template
ArgumentTypeDescription
idstringThe id of the sms template
fn sync()
Sync sms template state from Okta
fn add_template_id(template_id: string, name?: string, template?: string, translations?: record, type?: enum)
Update an SMS template
ArgumentTypeDescription
template_idstringPath parameter: template_id
name?stringHuman-readable name of the Template
template?stringText of the Template, including any [macros](https://developer.okta.com/docs/api/openapi/okta-management/management/tag/Template/)
translations?record- Template translations are optionally provided when you want to localize the SMS messages. Translations are provided as an object that contains `key:value` pairs: the language and the translated Template text. The key portion is a two-letter country code that conforms to [ISO 639-1](https://www.loc
type?enumType of the Template

Resources

state— Sms template resource state
sms_template_action— Sms template action result
telephony_provider.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
id?stringID of the custom telephony provider
providerAuthToken?stringThe authentication token that's used to authenticate requests to the telephony provider. Your telephony provider gives you this token.
providerSettings?objectSettings for custom telephony provider. These settings vary based on the telephony provider and the type of telephony operation (SMS or Voice). For `sms` and `call`, you can select one method per telephony operation (`sms` and `call`) for sending messages or voice calls. > **Note:** Configure your t
providerSid?stringThe account string identifier (SID) for your telephony provider account. Your telephony provider gives you this SID.
providerCapability?enumThe types of telephony operations (SMS or Voice) that you use with your telephony provider. `ALL` is the only valid value. It indicates that your provider can handle both SMS messages and voice calls. You're not required to use both types of telephony operations, but your provider can support both.
providerName?enumThe name of the telephony provider
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a telephony provider
fn get(id: string)
Get a telephony provider
ArgumentTypeDescription
idstringThe id of the telephony provider
fn lookup(max_items?: number)
List telephony providers and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update telephony provider attributes
fn delete(id: string)
Delete the telephony provider
ArgumentTypeDescription
idstringThe id of the telephony provider
fn sync()
Sync telephony provider state from Okta
fn activate(custom_telephony_provider_id: string)
Activate a custom telephony provider
ArgumentTypeDescription
custom_telephony_provider_idstringPath parameter: custom_telephony_provider_id
fn create_set_as_primary(custom_telephony_provider_id: string)
Set a custom telephony provider as a primary telephony provider
ArgumentTypeDescription
custom_telephony_provider_idstringPath parameter: custom_telephony_provider_id
fn deactivate(custom_telephony_provider_id: string)
Deactivate a custom telephony provider
ArgumentTypeDescription
custom_telephony_provider_idstringPath parameter: custom_telephony_provider_id
fn test(custom_telephony_provider_id: string, countryCodeIso2?: string, factor?: enum, phoneNumber?: string)
Send a test message from a custom telephony provider
ArgumentTypeDescription
custom_telephony_provider_idstringPath parameter: custom_telephony_provider_id
countryCodeIso2?stringThe country code for the phone number. Use the [Alpha-2 code from ISO 3166-1](https://www.iso.org/obp/ui/#search) for country codes.
factor?enumThe type of test message to send
phoneNumber?stringThe phone number to which the test message or call is sent

Resources

state— Telephony provider resource state
telephony_provider_action— Telephony provider action result
ui_schema.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
uiSchema?objectProperties of the UI schema
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a ui schema
fn get(id: string)
Get a ui schema
ArgumentTypeDescription
idstringThe id of the ui schema
fn lookup(max_items?: number)
List ui schemas and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update ui schema attributes
fn delete(id: string)
Delete the ui schema
ArgumentTypeDescription
idstringThe id of the ui schema
fn sync()
Sync ui schema state from Okta
user.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
credentials?objectSpecifies primary authentication and recovery credentials for a user. Credential types and requirements vary depending on the provider and security policy of the org.
profile?objectSpecifies the default and custom profile properties for a user. The default user profile is based on the [System for Cross-domain Identity Management: Core Schema](https://datatracker.ietf.org/doc/html/rfc7643). The only permitted customizations of the default profile are to update permissions, chan
realmId?stringThe ID of the realm in which the user is residing. See [Realms](/openapi/okta-management/management/tags/realm).
type?objectThe ID of the user type. Add this value if you want to create a user with a non-default [User Type](https://developer.okta.com/docs/api/openapi/okta-management/management/tag/UserType/). The user type determines which [schema](https://developer.okta.com/docs/api/openapi/okta-management/management/ta
groupIds?arrayThe list of group IDs of groups that the user is added to at the time of creation
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a user
fn get(id: string)
Get a user
ArgumentTypeDescription
idstringThe id of the user
fn lookup(search?: string, filter?: string, q?: string, sortBy?: string, sortOrder?: string, fields?: string, expand?: string, max_items?: number)
List users and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
search?stringSearches for users with a supported filtering expression for most properties. Okta recommends this query parameter because it provides the largest range of search options and optimal performance. > **Note:** Using an overly complex or long search query can result in an error. This operation supports
filter?stringFilters users with a supported expression for a subset of properties. > **Note:** Returned users include those with the `DEPROVISIONED` status. This requires [URL encoding](https://developer.mozilla.org/en-US/docs/Glossary/Percent-encoding). For example, `filter=lastUpdated gt "2013-06-01T00:00:00.0
q?stringFinds users who match the specified query. Use the `q` parameter for simple queries, such as a lookup of users by name when creating a people picker. The value of `q` is matched against `firstName`, `lastName`, or `email`. This performs a `startsWith` match, but this is an implementation detail and
sortBy?stringSpecifies the field to sort by (for search queries only). This can be any single property, for example `sortBy=profile.lastName`. Users with the same value for the `sortBy` property are ordered by `id`. Use with `sortOrder` to control the order of results.
sortOrder?stringSpecifies sort order: `asc` or `desc` (for search queries only). This parameter is ignored if `sortBy` isn't present.
fields?stringSpecifies a select set of user properties to query. Any other properties will be filtered out of the returned users. This is often called field projections in APIs, which can reduce payload size, improve performance, and limit unneccessary data exposure. Requested fields should be comma-separated. C
expand?string<x-lifecycle-container><x-lifecycle class="ea"></x-lifecycle></x-lifecycle-container>A parameter to include metadata in the `_embedded` property. Supported value: `classification`.
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update user attributes
fn delete(id: string)
Delete the user
ArgumentTypeDescription
idstringThe id of the user
fn sync()
Sync user state from Okta
fn activate(id: string)
Activate a user
ArgumentTypeDescription
idstringPath parameter: id
fn add_id(id: string, credentials?: object, profile?: object, realmId?: string, type?: object)
Update a user
ArgumentTypeDescription
idstringPath parameter: id
credentials?objectSpecifies primary authentication and recovery credentials for a user. Credential types and requirements vary depending on the provider and security policy of the org.
profile?objectSpecifies the default and custom profile properties for a user. The default user profile is based on the [System for Cross-domain Identity Management: Core Schema](https://datatracker.ietf.org/doc/html/rfc7643). The only permitted customizations of the default profile are to update permissions, chan
realmId?stringThe ID of the realm in which the user is residing. See [Realms](/openapi/okta-management/management/tags/realm).
type?objectThe ID of the user type. Add this value if you want to create a user with a non-default [User Type](https://developer.okta.com/docs/api/openapi/okta-management/management/tag/UserType/). The user type determines which [schema](https://developer.okta.com/docs/api/openapi/okta-management/management/ta
fn create_credentials_forgot_password_recovery_question(user_id: string, password?: object, recovery_question?: object)
Reset password with recovery question
ArgumentTypeDescription
user_idstringPath parameter: user_id
password?objectSpecifies a password for a user. When a user has a valid password, imported hashed password, or password hook, and a response object contains a password credential, then the password object is a bare object without the value property defined (for example, `password: {}`). This indicates that a passw
recovery_question?objectSpecifies a secret question and answer that's validated (case insensitive) when a user forgets their password or unlocks their account. The answer property is write-only.
fn create_expire_password_with_temp_password(id: string)
Expire the password with a temporary password
ArgumentTypeDescription
idstringPath parameter: id
fn credentials_change_password(user_id: string, newPassword?: object, oldPassword?: object, revokeSessions?: boolean)
Update password
ArgumentTypeDescription
user_idstringPath parameter: user_id
newPassword?objectSpecifies a password for a user. When a user has a valid password, imported hashed password, or password hook, and a response object contains a password credential, then the password object is a bare object without the value property defined (for example, `password: {}`). This indicates that a passw
oldPassword?objectSpecifies a password for a user. When a user has a valid password, imported hashed password, or password hook, and a response object contains a password credential, then the password object is a bare object without the value property defined (for example, `password: {}`). This indicates that a passw
revokeSessions?booleanWhen set to `true`, revokes all user sessions, except for the current session
fn credentials_change_recovery_question(user_id: string, password?: object, recovery_question?: object)
Update recovery question
ArgumentTypeDescription
user_idstringPath parameter: user_id
password?objectSpecifies a password for a user. When a user has a valid password, imported hashed password, or password hook, and a response object contains a password credential, then the password object is a bare object without the value property defined (for example, `password: {}`). This indicates that a passw
recovery_question?objectSpecifies a secret question and answer that's validated (case insensitive) when a user forgets their password or unlocks their account. The answer property is write-only.
fn credentials_forgot_password(user_id: string)
Start forgot password flow
ArgumentTypeDescription
user_idstringPath parameter: user_id
fn deactivate(id: string)
Deactivate a user
ArgumentTypeDescription
idstringPath parameter: id
fn delete_clients_grants(user_id: string, client_id: string)
Revoke all grants for a client
ArgumentTypeDescription
user_idstringPath parameter: user_id
client_idstringPath parameter: client_id
fn delete_sessions(user_id: string)
Revoke all user sessions
ArgumentTypeDescription
user_idstringPath parameter: user_id
fn expire_password(id: string)
Expire the password
ArgumentTypeDescription
idstringPath parameter: id
fn get_classification(user_id: string)
[EA] Retrieve a user
ArgumentTypeDescription
user_idstringPath parameter: user_id
fn list_app_links(id: string)
List all assigned app links
ArgumentTypeDescription
idstringPath parameter: id
fn list_blocks(id: string)
List all user blocks
ArgumentTypeDescription
idstringPath parameter: id
fn list_clients(user_id: string)
List all clients
ArgumentTypeDescription
user_idstringPath parameter: user_id
fn list_clients_grants(user_id: string, client_id: string)
List all grants for a client
ArgumentTypeDescription
user_idstringPath parameter: user_id
client_idstringPath parameter: client_id
fn list_devices(user_id: string)
[LIMITED_GA — requires Okta Identity Engine] List all devices for an enrolled user
ArgumentTypeDescription
user_idstringPath parameter: user_id
fn list_groups(id: string)
List all groups
ArgumentTypeDescription
idstringPath parameter: id
fn list_idps(id: string)
List all IdPs for user
ArgumentTypeDescription
idstringPath parameter: id
fn reactivate(id: string)
Reactivate a user
ArgumentTypeDescription
idstringPath parameter: id
fn reset_factors(id: string)
Reset the factors
ArgumentTypeDescription
idstringPath parameter: id
fn reset_password(id: string)
Reset a password
ArgumentTypeDescription
idstringPath parameter: id
fn suspend(id: string)
Suspend a user
ArgumentTypeDescription
idstringPath parameter: id
fn unlock(id: string)
Unlock a user
ArgumentTypeDescription
idstringPath parameter: id
fn unsuspend(id: string)
Unsuspend a user
ArgumentTypeDescription
idstringPath parameter: id
fn update_classification(user_id: string, type?: enum)
[EA] Replace the user
ArgumentTypeDescription
user_idstringPath parameter: user_id
type?enumThe type of user classification

Resources

state— User resource state
user_action— User action result
user_schema.tsv2026.08.25.1

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
definitions?objectUser profile subschemas The profile object for a user is defined by a composite schema of base and custom properties using a JSON path to reference subschemas. The `#base` properties are defined and versioned by Okta, while `#custom` properties are extensible. Custom property names for the profile o
properties?objectUser Object Properties
title?stringUser-defined display name for the schema
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a user schema
ArgumentTypeDescription
idstringThe id of the user schema
fn update()
Update user schema attributes
fn sync()
Sync user schema state from Okta
user_type.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
description?stringThe human-readable description of the user type
displayNamestringThe human-readable name of the user type
namestringThe name of the user type. The name must start with A-Z or a-z and contain only A-Z, a-z, 0-9, or underscore (_) characters. This value becomes read-only after creation and can't be updated.
_links?objectSpecifies link relations (see [Web Linking](https://www.rfc-editor.org/rfc/rfc8288)) available using the [JSON Hypertext Application Language](https://datatracker.ietf.org/doc/html/draft-kelly-json-hal-06) specification. This object is used for dynamic discovery of related resources and lifecycle op
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a user type
fn get(id: string)
Get a user type
ArgumentTypeDescription
idstringThe id of the user type
fn lookup(max_items?: number)
List user types and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn update()
Update user type attributes
fn delete(id: string)
Delete the user type
ArgumentTypeDescription
idstringThe id of the user type
fn sync()
Sync user type state from Okta
fn add_type_id(type_id: string, description?: string, displayName?: string)
Update a user type
ArgumentTypeDescription
type_idstringPath parameter: type_id
description?stringThe updated human-readable description of the user type
displayName?stringThe updated human-readable display name for the user type

Resources

state— User type resource state
user_type_action— User type action result
users_authenticator_enrollment.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
user_idstringPath scope for the users authenticator enrollment: user_id
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a users authenticator enrollment
ArgumentTypeDescription
idstringThe id of the users authenticator enrollment
fn lookup(max_items?: number)
List users authenticator enrollments and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn delete(id: string)
Delete the users authenticator enrollment
ArgumentTypeDescription
idstringThe id of the users authenticator enrollment
fn sync()
Sync users authenticator enrollment state from Okta
fn create_phone(authenticatorId: string, profile: object)
[LIMITED_GA — requires Okta Identity Engine] Create an auto-activated Phone authenticator enrollment
ArgumentTypeDescription
authenticatorIdstringUnique identifier of the `phone` authenticator
profileobjectDefines the authenticator specific parameters
fn create_tac(authenticatorId: string, profile?: object)
[LIMITED_GA] Create an auto-activated TAC authenticator enrollment
ArgumentTypeDescription
authenticatorIdstringUnique identifier of the TAC authenticator
profile?objectDefines the authenticator specific parameters

Resources

state— Users authenticator enrollment resource state
users_authenticator_enrollment_action— Users authenticator enrollment action result
users_clients_token.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
user_idstringPath scope for the users clients token: user_id
client_idstringPath scope for the users clients token: client_id
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a users clients token
ArgumentTypeDescription
idstringThe id of the users clients token
fn lookup(expand?: string, max_items?: number)
List users clients tokens and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
expand?stringValid value: `scope`. If specified, scope details are included in the `_embedded` attribute.
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn delete(id: string)
Delete the users clients token
ArgumentTypeDescription
idstringThe id of the users clients token
fn sync()
Sync users clients token state from Okta
users_factor.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
user_idstringPath scope for the users factor: user_id
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
factorType?string
provider?enum
verify?object
factorProfileId?stringID of an existing Custom TOTP factor profile. To create this, see [Custom TOTP factor](https://help.okta.com/okta_help.htm?id=ext-mfa-totp).
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a users factor
fn get(id: string)
Get a users factor
ArgumentTypeDescription
idstringThe id of the users factor
fn lookup(max_items?: number)
List users factors and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn delete(id: string)
Delete the users factor
ArgumentTypeDescription
idstringThe id of the users factor
fn sync()
Sync users factor state from Okta
fn activate(factor_id: string, passCode?: string, useNumberMatchingChallenge?: boolean, clientData?: string, registrationData?: string, attestation?: string)
Activate a factor
ArgumentTypeDescription
factor_idstringPath parameter: factor_id
passCode?stringOTP for the current time window
useNumberMatchingChallenge?booleanSelect whether to use a number matching challenge for a `push` factor. > **Note:** Sending a request with a body is required when you verify a `push` factor with a number matching challenge.
clientData?stringBase64-encoded client data from the Passkey (FIDO2 WebAuthn) authenticator
registrationData?stringBase64-encoded registration data from the U2F token
attestation?stringBase64-encoded attestation from the Passkey (FIDO2 WebAuthn) authenticator
fn list_catalog()
List all supported factors
fn list_questions()
List all supported security questions
fn resend(factor_id: string, factorType?: string, profile?: object, provider?: enum)
Resend a factor enrollment
ArgumentTypeDescription
factor_idstringPath parameter: factor_id
factorType?string
profile?object
provider?enum
fn verify(factor_id: string, passCode?: string, useNumberMatchingChallenge?: boolean, answer?: string, clientData?: string, signatureData?: string, authenticatorData?: string)
Verify a factor
ArgumentTypeDescription
factor_idstringPath parameter: factor_id
passCode?stringOTP for the current time window
useNumberMatchingChallenge?booleanSelect whether to use a number matching challenge for a `push` factor. > **Note:** Sending a request with a body is required when you verify a `push` factor with a number matching challenge.
answer?stringAnswer to the question
clientData?stringBase64-encoded client data from the Passkey (FIDO2 WebAuthn) authenticator
signatureData?stringBase64-encoded signature data from the Passkey (FIDO2 WebAuthn) authenticator
authenticatorData?stringBase64-encoded authenticator data from the Passkey (FIDO2 WebAuthn) authenticator

Resources

state— Users factor resource state
users_factor_action— Users factor action result
users_factors_transaction.tsv2026.08.25.1

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
user_idstringPath scope for the users factors transaction: user_id
factor_idstringPath scope for the users factors transaction: factor_id
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a users factors transaction
ArgumentTypeDescription
idstringThe id of the users factors transaction
fn sync()
Sync users factors transaction state from Okta
users_grant.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
user_idstringPath scope for the users grant: user_id
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a users grant
ArgumentTypeDescription
idstringThe id of the users grant
fn lookup(scopeId?: string, expand?: string, max_items?: number)
List users grants and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
scopeId?stringThe scope ID to filter on
expand?stringValid value: `scope`. If specified, scope details are included in the `_embedded` attribute.
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn delete(id: string)
Delete the users grant
ArgumentTypeDescription
idstringThe id of the users grant
fn sync()
Sync users grant state from Okta
users_linked_object.tsv2026.08.25.1

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
user_id_or_loginstringPath scope for the users linked object: user_id_or_login
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a users linked object
ArgumentTypeDescription
idstringThe id of the users linked object
fn delete(id: string)
Delete the users linked object
ArgumentTypeDescription
idstringThe id of the users linked object
fn sync()
Sync users linked object state from Okta
fn set_primary_user_id(primary_relationship_name: string, primary_user_id: string)
Assign a linked object value for primary
ArgumentTypeDescription
primary_relationship_namestringPath parameter: primary_relationship_name
primary_user_idstringPath parameter: primary_user_id

Resources

state— Users linked object resource state
users_linked_object_action— Users linked object action result
users_subscription.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
user_idstringPath scope for the users subscription: user_id
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn get(id: string)
Get a users subscription
ArgumentTypeDescription
idstringThe notificationType of the users subscription
fn lookup(max_items?: number)
List users subscriptions and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn sync()
Sync users subscription state from Okta
fn create_subscribe(notification_type: string)
Subscribe a user to a specific notification type
ArgumentTypeDescription
notification_typestringPath parameter: notification_type
fn create_unsubscribe(notification_type: string)
Unsubscribe a user from a specific notification type
ArgumentTypeDescription
notification_typestringPath parameter: notification_type

Resources

state— Users subscription resource state
users_subscription_action— Users subscription action result
webauthn_registration_activate.tsv2026.08.25.1

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
credResponses?arrayList of credential responses from the fulfillment provider
fulfillmentProvider?enumName of the fulfillment provider for the WebAuthn preregistration factor
pinResponseJwe?stringEncrypted JWE of the PIN response from the fulfillment provider
serial?stringSerial number of the YubiKey
userId?stringID of an existing Okta user
version?stringFirmware version of the YubiKey
yubicoSigningJwks?arrayList of usable signing keys from Yubico (in JSON Web Key Sets (JWKS) format). The signing keys are used to verify the JSON Web Signature (JWS) inside the JWE.
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a webauthn registration activate
webauthn_registration_enroll.tsv2026.08.25.1

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
enrollmentRpIds?arrayList of relying party hostnames to register on the YubiKey
fulfillmentProvider?enumName of the fulfillment provider for the WebAuthn preregistration factor
userId?stringID of an existing Okta user
yubicoTransportKeyJWK?objectElliptic curve key in JSON Web Key (JWK) format. It's used during enrollment to encrypt fulfillment requests to Yubico, or during activation to verify Yubico's JWS (JSON Web Signature) objects in fulfillment responses. The currently agreed protocol uses P-384.
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a webauthn registration enroll
webauthn_registration_initiate_fulfillment_request.tsv2026.08.25.1

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
fulfillmentData?arrayList of fulfillment order details
fulfillmentProvider?enumName of the fulfillment provider for the WebAuthn preregistration factor
userId?stringID of an existing Okta user
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a webauthn registration initiate fulfillment request
webauthn_registration_send_pin.tsv2026.08.25.1

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
authenticatorEnrollmentId?stringID for a WebAuthn preregistration factor in Okta
fulfillmentProvider?enumName of the fulfillment provider for the WebAuthn preregistration factor
userId?stringID of an existing Okta user
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a webauthn registration send pin
webauthn_registration_users_enrollment.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
user_idstringPath scope for the webauthn registration users enrollment: user_id
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn lookup(max_items?: number)
List webauthn registration users enrollments and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn delete(id: string)
Delete the webauthn registration users enrollment
ArgumentTypeDescription
idstringThe id of the webauthn registration users enrollment
fn create_mark_error(authenticator_enrollment_id: string)
[LIMITED_GA — requires Okta Identity Engine] Assign the fulfillment error status to a WebAuthn preregistration factor
ArgumentTypeDescription
authenticator_enrollment_idstringPath parameter: authenticator_enrollment_id

Resources

state— Webauthn registration users enrollment resource state
webauthn_registration_users_enrollment_action— Webauthn registration users enrollment action result
well_known_app_authenticator.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn lookup(oauthClientId?: string, max_items?: number)
List well known app authenticators and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
oauthClientId?stringFilters app authenticator configurations by `oauthClientId`
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
well_known_apple_app_site.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn lookup(max_items?: number)
List well known apple app sites and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
well_known_assetlinks.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn lookup(max_items?: number)
List well known assetlinkss and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
well_known_webauthn.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
name?stringInstance name for this resource (used as the unique identifier in the factory pattern)
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn lookup(max_items?: number)
List well known webauthns and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
yubikey_token.tsv2026.08.25.2

Global Arguments

ArgumentTypeDescription
okta_domainstringYour Okta org domain, e.g. acme.okta.com. Overrides the OKTA_DOMAIN environment variable.
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
serialNumber?stringThe unique identifier assigned to each YubiKey device
publicId?stringThe YubiKey's public ID
privateId?stringThe YubiKey's private ID
aesKey?stringThe cryptographic key used in the AES (Advanced Encryption Standard) algorithm to encrypt and decrypt the YubiKey OTP
api_token?stringOkta API token, sent as 'Authorization: SSWS <token>'. Overrides the OKTA_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
fn create()
Create a yubikey token
fn get(id: string)
Get a yubikey token
ArgumentTypeDescription
idstringThe id of the yubikey token
fn lookup(max_items?: number)
List yubikey tokens and record each as a data artifact (newest first, capped at 200 by default)
ArgumentTypeDescription
max_items?numberStop after this many results (default 200). Raise deliberately: large walks can exhaust Okta's per-endpoint rate limit.
fn sync()
Sync yubikey token state from Okta
04Previous Versions1
2026.08.25.2
05Stats
B
85 / 100
Downloads
18
Archive size
345.8 KB
  • Has README or module doc2/2earned
  • README has a code example1/1earned
  • README is substantive1/1earned
  • Most symbols documented1/1earned
  • No slow types (deprecated)1/1earned
  • Dependencies pass trust audit2/2earned
  • Has description1/1earned
  • Platform support declared (or universal)2/2earned
  • License declared1/1earned
  • Verified public repository0/2missing
06Platforms
07Labels