Scopes for Okta connector cards
Your Okta connector accesses the Okta API using scoped OAuth 2.0 access tokens. Each access token enables the bearer to perform specific actions on specific Okta endpoints. The scopes contained in the access token control the ability to perform these actions.
Grant the required scopes for each of the event and action cards that you want to use in your Okta connector.
For an existing connection, you must reauthorize the connection to pick up any scope changes.
The OAuth 2.0 Scopes topic in the Okta developer documentation contains detailed descriptions for all available scopes.
Default scopes
These default scopes are automatically granted. You don't need to grant them through the Okta Workflows OAuth app. They appear in the Permissions tab of the Okta connector.
The connection authorization fails if you revoke any of these automatically granted scopes from the OAuth app.
- address
- groups
- offline_access
- openid
- phone
- profile
Event cards
The event cards for the Okta connector require the scopes indicated in the following table.
Connector card |
Required scopes |
---|---|
okta.eventHooks.manage |
|
okta.apps.read |
|
okta.apps.read |
|
okta.apps.read |
|
okta.apps.read |
Action cards
The action cards for the Okta connector require the scopes indicated in the following table.
Connector card |
Required scopes |
---|---|
okta.apps.manage |
|
okta.groups.manage |
|
okta.users.read okta.users.manage |
|
okta.groups.manage |
|
okta.apps.manage |
|
okta.apps.manage okta.apps.read |
|
okta.apps.manage okta.apps.read |
|
okta.schemas.read okta.identitySources.manage |
|
okta.users.manage |
|
okta.groups.manage okta.schemas.read |
|
okta.groups.manage |
|
okta.identitySources.manage okta.apps.read |
|
okta.users.manage okta.schemas.read |
|
Any scopes required by the API endpoint. |
|
okta.apps.manage |
|
okta.groups.manage |
|
okta.users.read okta.users.manage |
|
okta.apps.manage |
|
okta.groups.manage |
|
okta.groups.manage |
|
okta.identitySources.manage okta.apps.read |
|
okta.users.manage okta.linkedObjects.read |
|
okta.users.manage |
|
okta.users.read |
|
okta.apps.read |
|
okta.users.read okta.linkedObjects.read |
|
okta.users.read okta.linkedObjects.read |
|
okta.users.read |
|
okta.apps.read |
|
okta.apps.read |
|
okta.groups.read |
|
okta.apps.read |
|
okta.identitySources.read okta.apps.read |
|
okta.apps.read |
|
okta.users.read |
|
okta.users.read okta.schemas.read |
|
okta.apps.read |
|
okta.apps.read |
|
okta.apps.read |
|
okta.groups.read |
|
okta.groups.read |
|
okta.identitySources.read okta.apps.read |
|
okta.users.read |
|
okta.apps.manage |
|
okta.apps.manage |
|
okta.groups.manage |
|
okta.users.manage |
|
okta.apps.read |
|
okta.groups.read |
|
okta.groups.read okta.schemas.read |
|
okta.logs.read |
|
okta.users.manage okta.linkedObjects.read |
|
okta.users.read okta.users.manage |
|
okta.identitySources.manage okta.apps.read |
|
okta.users.read okta.users.manage |
|
okta.apps.read okta.apps.manage |
|
okta.apps.read okta.apps.manage |
|
okta.groups.manage |
|
okta.groups.read |
|
okta.users.read okta.users.manage okta.schemas.read |