Skip to content

Okta

The Okta integration imports your organization’s users as user account assets, including email addresses, login names, display names, and account status. Suspended and deactivated users are included so you can review access and offboarding.

Oneleet uses an Okta API token. The token inherits the permissions of the administrator who creates it. If your organization has Okta Privileged Access enabled, it is recommended to use a dedicated service account with Read-only Administrator access to all users.

  1. Sign in to the Okta Admin Console as an admin user or the service account that was created.
  2. Go to Security > API > Tokens and click Create token.
  3. Name the token Oneleet. If you restrict the token to particular network zones, ensure they allow API requests from Oneleet.
  4. Create the token and copy its value. Okta shows the value only once.
  5. In Oneleet, go to Integrations > Add integration > Okta. Enter your original Okta hostname and API Token, then click Connect. Paste only the token value, without an SSWS prefix.

Use a hostname such as example.okta.com, without https:// or a path. Regional and preview Okta domains are supported. Custom sign-in domains aren’t supported.

Keep the token private and its service account active. Okta revokes tokens when their creator is deactivated, and tokens expire after 30 days without an API request. Each use renews that period. When rotating the token, update the connection with the new value.

Oneleet imports users across all lifecycle statuses. SUSPENDED and DEPROVISIONED accounts are marked deactivated. Temporary lockouts and pending activation aren’t treated as offboarding.

This integration doesn’t import MFA enrollment, admin roles, profile images, or organization security policies. Their absence doesn’t indicate that a user lacks MFA or administrative access.

If a scan fails to authenticate, check that the token hasn’t expired or been revoked and that its creator is still active. If it fails with insufficient permissions, confirm the account can read all users and that the token’s network restrictions allow requests from Oneleet.