Connect Okta
Argus scans an Okta org read-only with a private-key JWT client. Nothing is installed in the org, and Argus only ever reads.
Before you start
- Permission to create an API service app in Okta.
- An available account slot: Free connects one account, Pro connects an unlimited number. See Billing & plans.
Provider-side setup
- In Okta, create an API service app that authenticates with a private-key JWT.
- Grant it read-only scopes, such as reading users and logs. Argus only reads.
- Copy the app's Client ID and its signing private key.
Required permissions
Grant the service app these read-only OAuth scopes, and assign it the Read-Only Administrator role:
okta.policies.read,okta.brands.read,okta.apps.read,okta.authenticators.read,okta.networkZones.read,okta.apiTokens.read,okta.roles.read,okta.groups.read,okta.logStreams.read,okta.idps.read
A few checks covering Okta's own first-party apps require the Super Administrator role instead.
Connect in Argus
Go to Accounts and click Connect account. Pick Okta, then the Private-key JWT method. Enter:
| Field | Value |
|---|---|
| Okta org URL | your org URL, e.g. https://yourorg.okta.com |
| Client ID | the API service app's client id |
| Private key (JWK / PEM) | the signing private key |
| Scopes | optional, space-separated; blank uses the default set |
Connection test
Finish the wizard. Argus stores the credential server-side and runs an asynchronous connection test before the first scan. The account card reports Connected, Checking…, or Failed. On a failure, re-check the values above and use Test connection on the account card to retry.