Identity connector

Okta

Receive Okta lifecycle and group events in Tessel as typed events. Use them to run onboarding, revoke access across your stack and keep group membership in sync with HR.

Connect Okta
Connect Okta
See setup steps
See setup steps

Identity

Category

Events

Sync mode

p95 520 ms

Latency

7 min

Setup time

What it can do

Triggers · 4
  • User createdWebhook
  • User deactivatedWebhook
  • Added to a groupWebhook
  • Sign-in risk detectedWebhook
Actions · 5
  • Look up a userRead
  • Create a userWrite
  • Add to a groupWrite
  • Suspend a userWrite
  • Clear user sessionsWrite

Overview

The Okta connector registers an event hook in your org, so Tessel hears about lifecycle and membership changes as they happen. Each event arrives typed, with the actor, target user and outcome attached, and it appears in the trace of the run it started.

Teams use it to open laptop and account requests when a user is created, to strip access from Slack, Google Workspace and Salesforce when someone is deactivated, and to page security when Okta flags a risky sign-in.

Event coverage

  • user.lifecycle.create, user.lifecycle.activate and user.lifecycle.deactivate

  • group.user_membership.add and group.user_membership.remove

  • user.risk.detect and user.session.start for security workflows

How event hooks work

Tessel creates an event hook pointed at a regional endpoint and answers Okta's one-time verification request. Okta then posts batches of events, which Tessel splits, checks against the schema and delivers in order. Duplicate deliveries are dropped by event ID.

POST /api/v1/eventHooks
{
  "name": "Tessel",
  "events": { "type": "EVENT_TYPE",
    "items": ["user.lifecycle.create", "user.lifecycle.deactivate"] },
  "channel": { "type": "HTTP", "version": "1.0.0",
    "config": { "uri": "https://eu-1.hooks.tessel.dev/okta" } }
}
POST /api/v1/eventHooks
{
  "name": "Tessel",
  "events": { "type": "EVENT_TYPE",
    "items": ["user.lifecycle.create", "user.lifecycle.deactivate"] },
  "channel": { "type": "HTTP", "version": "1.0.0",
    "config": { "uri": "https://eu-1.hooks.tessel.dev/okta" } }
}
POST /api/v1/eventHooks
{
  "name": "Tessel",
  "events": { "type": "EVENT_TYPE",
    "items": ["user.lifecycle.create", "user.lifecycle.deactivate"] },
  "channel": { "type": "HTTP", "version": "1.0.0",
    "config": { "uri": "https://eu-1.hooks.tessel.dev/okta" } }
}

Offboarding safety

Suspend and session actions can sit behind an approval step. A named person, plus a backup, confirms in Slack or Teams before Tessel calls Okta, and the decision is stored in the trace.

Permissions needed

Create an API service app in Okta that signs in with a private key. Grant only the scopes your workflows use. Write scopes are needed only for the create, group and suspend actions.

  • okta.users.read and okta.groups.read for lookups

  • okta.users.manage and okta.groups.manage for write actions

  • okta.eventHooks.manage to create and verify the hook

Setup

Five steps. About seven minutes.

Most of the time goes into the service app and its scopes. Tessel verifies the hook for you.

  1. Create an API service app with a public keyOkta3 min
  2. Grant the users, groups and event hook scopesOkta1 min
  3. Paste your Okta domain and client IDTessel1 min
  4. Pick events and let Tessel verify the hookTessel2 min
  5. Create a test user and watch the event arriveVerify520 ms

Access that follows people, starting today.

Connect Okta on the free plan. Up to three builders and 10,000 runs a month, no card required.

Connect Okta
Connect Okta
All integrations
All integrations

One email a month. Only what shipped.

A1

Product

C1

Layouts

D1

Company

E1

Template

F1

All systems operational
fra41 ms
iad38 ms
sin52 ms

C2

Elsewhere

XLinkedInGitHubYouTube

E2

Move across the wordmark168 blocks · iso 30°

One email a month. Only what shipped.

A1

Product

C1

Layouts

D1

Company

E1

Template

F1

All systems operational
fra41 ms
iad38 ms
sin52 ms

C2

Elsewhere

XLinkedInGitHubYouTube

E2

Move across the wordmark168 blocks · iso 30°

One email a month. Only what shipped.

A1

Product

C1

Layouts

D1

Company

E1

Template

F1

All systems operational
fra41 ms
iad38 ms
sin52 ms

C2

Elsewhere

XLinkedInGitHubYouTube

E2

Move across the wordmark168 blocks · iso 30°

Create a free website with Framer, the website builder loved by startups, designers and agencies.