| Push new users |
- When you assign a user to Kong AI in Okta, Okta sends the user an invitation to join Kong AI. The user must accept the invitation before their account becomes active.
- The required field is email. Kong AI uses the invited email address as the user's identity, so the Okta username and email must match and be unique for each user.
- Kong AI's invitation endpoint accepts only an email address. Okta can't set the user's first name, last name, or role at creation time. Okta applies the name afterward through Push Profile Updates.
Note:
Push Groups syncs team membership only. It doesn't create users in Kong AI. Assign users to the app first so Okta provisions them, and then push group membership.
|
| Push profile updates |
- Updates that you make to a user in Okta push to the user's Kong AI account.
- The only attributes that you can update are First name and Last name. Kong AI stores a single full name field, so Okta combines the first and last name into it.
- You can't update the username or email. The email address is immutable in Kong AI and serves as the user's identity.
|
| Push user deactivation |
- Deactivating a user, or removing their access to the app in Okta, removes the user from Kong AI.
- Kong AI has no inactive state. Re-creating the account requires a new invitation that the user must accept again.
|
| Import new users |
- Okta imports all user accounts from Kong AI, including users who have a pending invitation.
- If a user is missing a first or last name, Okta assigns the placeholder values FNU and LNU.
- You can add a pending user to a Kong AI team before they accept their invitation.
- Kong AI has no separate username field, so Okta sets the username to the user's email address when you import users.
|
| Push groups |
- You can push groups and their members to Kong AI, where they're created as teams. See Manage Group Push.
- You can update a group's display name and description, and add or remove group members.
- Deleting a pushed group deletes the team in Kong AI along with its memberships. The members remain as users in the organization.
- Removing a user from a pushed group removes only their team membership. Okta doesn't delete the user from Kong AI.
- Kong AI allows multiple teams with the same name, so give each pushed group a distinct name. Otherwise, a push can match the wrong team.
- Kong AI's system teams are out of scope. Okta doesn't import them, and you can't create, rename, or delete them from Okta.
- Okta skips group names that contain emoji or special characters during import.
Note:
This integration doesn't assign a default role to provisioned users. As an admin, you need to create a team in Konnect with the baseline roles and add each user to it after they accept their invitation. Role management for groups isn't available from Okta.
|