# Okta integration

> Identity and access management API for users, groups, applications, MFA factors, devices, sessions, policies, and the system log.

- Authentication: apiKey

## Tools (79)

- **Activate Application**: Activate an app integration
- **Activate Group Rule**: Activate a group rule so it starts assigning users
- **Activate MFA Factor**: Complete factor enrollment by submitting the verification code
- **Activate User**: Activate a STAGED or DEPROVISIONED user, optionally sending the activation email
- **Assign Group to Application**: Assign a group to an app so all members get access
- **Assign User to Application**: Assign a user directly to an app, optionally setting app-specific profile/credentials
- **Assign User to Group**: Add a user to an Okta group
- **Change User Password**: Change a user's password by providing the old and new passwords
- **Create Application**: Add an app integration (OIDC, SAML, SWA, or catalog app) to the org
- **Create Group**: Create an Okta group with a name and description
- **Create Group Rule**: Create an expression rule that auto-assigns matching users to groups
- **Create User**: Create a user, optionally activated immediately, with profile, credentials, and group memberships
- **Deactivate Application**: Deactivate an app integration — users lose access until reactivated
- **Deactivate Device**: Deactivate a device (required before deletion)
- **Deactivate User**: Deactivate a user — sessions are revoked and the user becomes DEPROVISIONED
- **Delete Application**: Delete an INACTIVE app integration
- **Delete Device**: Permanently remove a DEACTIVATED device
- **Delete Group**: Delete an Okta group (memberships are removed, users are untouched)
- **Delete Group Rule**: Delete a group rule, optionally removing the memberships it created
- **Delete User**: Delete a user — deactivates on first call, permanently erases a DEPROVISIONED user on second call
- **Enroll MFA Factor**: Enroll a new MFA factor (SMS, TOTP, email, security question, WebAuthn) for a user
- **Expire Password With Temporary Password**: Expire the password and issue a one-time temporary password
- **Expire User Password**: Force the user to change their password at next sign-in
- **List API Tokens**: List metadata for the org's API tokens (names, users, last use — not values)
- **List Application Groups**: List the group assignments on an app
- **List Applications**: List app integrations in the org, filterable by name or assigned user/group
- **List Application Users**: List the users assigned to an app
- **List Authenticators**: List the org's configured authenticators (password, email, phone, Okta Verify, WebAuthn)
- **List Devices**: List devices registered in the org, filterable by SCIM search expression
- **List Device Users**: List the users associated with a device
- **List Enrolled MFA Factors**: List the MFA factors a user has enrolled
- **List Event Hooks**: List the org's outbound event hook subscriptions
- **List Factor Catalog**: List the factor types a user is eligible to enroll per org policy
- **List Group Assigned Apps**: List the applications assigned to a group
- **List Group Members**: List the users in a group
- **List Group Rules**: List the rules that automatically assign users to groups
- **List Groups**: List or search groups by name, filter expression, or SCIM search
- **List Identity Providers**: List configured identity providers (SAML, OIDC, social)
- **List Policies**: List policies of a given type (sign-on, password, MFA enrollment, access)
- **List Policy Rules**: List the rules of a policy
- **List System Log Events**: Query the org's System Log for audit events (sign-ins, lifecycle changes, admin actions) with time bounds, filters, and cursor pagination
- **List User App Links**: List the app links (assigned apps) shown on a user's dashboard
- **List User Devices**: List the devices a user is enrolled on
- **List User Grants**: List the OAuth scope consent grants a user has given
- **List User Groups**: List the groups a user belongs to
- **List Users**: List or search users with SCIM filter expressions, name queries, or property filters
- **Reactivate User**: Restart the activation flow for a user stuck in PROVISIONED status
- **Replace Group**: Update a group's name and description
- **Replace Group Rule**: Update an INACTIVE group rule's expression, name, or target groups
- **Replace User**: Replace a user's entire profile — attributes omitted from the body are cleared
- **Reset User MFA Factors**: Unenroll all of a user's MFA factors so they re-enroll at next sign-in
- **Reset User Password**: Start the password-reset flow, emailing the user a reset link or returning the reset URL
- **Retrieve Application**: Fetch a single app integration by ID
- **Retrieve Application User**: Fetch one user's assignment to an app
- **Retrieve Authenticator**: Fetch one authenticator's configuration
- **Retrieve Device**: Fetch a single registered device
- **Retrieve Group**: Fetch a single group by ID
- **Retrieve Group Rule**: Fetch a single group rule
- **Retrieve Identity Provider**: Fetch one identity provider's configuration
- **Retrieve MFA Factor**: Fetch one enrolled MFA factor for a user
- **Retrieve Org Settings**: Fetch the org's general settings (company name, subdomain, contact info)
- **Retrieve Policy**: Fetch one policy by ID
- **Retrieve Policy Rule**: Fetch one rule of a policy
- **Retrieve Session**: Fetch details of an identity-provider session by ID
- **Retrieve User**: Fetch a single user by Okta ID, login email, or login shortname
- **Revoke All User Grants**: Revoke every OAuth scope consent grant a user has given
- **Revoke All User Sessions**: Sign a user out everywhere, optionally revoking their OAuth tokens too
- **Revoke Session**: End one identity-provider session
- **Revoke User Grant**: Revoke a single OAuth scope consent grant for a user
- **Start Forgot Password Flow**: Trigger the forgot-password recovery flow for a user
- **Suspend User**: Suspend an ACTIVE user — blocks sign-in but keeps app assignments and group memberships
- **Unassign Group from Application**: Remove a group assignment from an app
- **Unassign User from Application**: Remove a user's direct assignment from an app
- **Unassign User from Group**: Remove a user from an Okta group
- **Unenroll MFA Factor**: Remove an enrolled MFA factor from a user
- **Unlock User**: Unlock a LOCKED_OUT user so they can sign in again
- **Unsuspend User**: Return a SUSPENDED user to ACTIVE status
- **Update User**: Partially update a user's profile or credentials (only provided attributes change)
- **Verify MFA Factor**: Challenge and verify an enrolled factor (send/validate an OTP or push)

## Triggers (1)

- **New System Log Event in Okta**: Triggers when a new event is written to the Okta System Log (sign-ins, lifecycle changes, admin actions).

Connect Okta in General Input: https://www.generalinput.com/apps/okta