Skip to main content

Connect Okta

Argus scans an Okta org read-only with a private-key JWT client. Nothing is installed in the org, and Argus only ever reads.

Before you start​

  • Permission to create an API service app in Okta.
  • An available account slot: Free connects one account, Pro connects an unlimited number. See Billing & plans.

Provider-side setup​

  1. In Okta, create an API service app that authenticates with a private-key JWT.
  2. Grant it read-only scopes, such as reading users and logs. Argus only reads.
  3. Copy the app's Client ID and its signing private key.

Required permissions​

Grant the service app these read-only OAuth scopes, and assign it the Read-Only Administrator role:

  • okta.policies.read, okta.brands.read, okta.apps.read, okta.authenticators.read, okta.networkZones.read, okta.apiTokens.read, okta.roles.read, okta.groups.read, okta.logStreams.read, okta.idps.read

A few checks covering Okta's own first-party apps require the Super Administrator role instead.

Connect in Argus​

Go to Accounts and click Connect account. Pick Okta, then the Private-key JWT method. Enter:

FieldValue
Okta org URLyour org URL, e.g. https://yourorg.okta.com
Client IDthe API service app's client id
Private key (JWK / PEM)the signing private key
Scopesoptional, space-separated; blank uses the default set

Connection test​

Finish the wizard. Argus stores the credential server-side and runs an asynchronous connection test before the first scan. The account card reports Connected, Checking…, or Failed. On a failure, re-check the values above and use Test connection on the account card to retry.

Official Okta documentation​