Okta
Receive Okta lifecycle and group events in Tessel as typed events. Use them to run onboarding, revoke access across your stack and keep group membership in sync with HR.
Identity
Category
Events
Sync mode
p95 520 ms
Latency
7 min
Setup time
What it can do
- User createdWebhook
- User deactivatedWebhook
- Added to a groupWebhook
- Sign-in risk detectedWebhook
- Look up a userRead
- Create a userWrite
- Add to a groupWrite
- Suspend a userWrite
- Clear user sessionsWrite
Overview
The Okta connector registers an event hook in your org, so Tessel hears about lifecycle and membership changes as they happen. Each event arrives typed, with the actor, target user and outcome attached, and it appears in the trace of the run it started.
Teams use it to open laptop and account requests when a user is created, to strip access from Slack, Google Workspace and Salesforce when someone is deactivated, and to page security when Okta flags a risky sign-in.
Event coverage
user.lifecycle.create,user.lifecycle.activateanduser.lifecycle.deactivategroup.user_membership.addandgroup.user_membership.removeuser.risk.detectanduser.session.startfor security workflows
How event hooks work
Tessel creates an event hook pointed at a regional endpoint and answers Okta's one-time verification request. Okta then posts batches of events, which Tessel splits, checks against the schema and delivers in order. Duplicate deliveries are dropped by event ID.
Offboarding safety
Suspend and session actions can sit behind an approval step. A named person, plus a backup, confirms in Slack or Teams before Tessel calls Okta, and the decision is stored in the trace.
Permissions needed
Create an API service app in Okta that signs in with a private key. Grant only the scopes your workflows use. Write scopes are needed only for the create, group and suspend actions.
okta.users.readandokta.groups.readfor lookupsokta.users.manageandokta.groups.managefor write actionsokta.eventHooks.manageto create and verify the hook
Five steps. About seven minutes.
Most of the time goes into the service app and its scopes. Tessel verifies the hook for you.
- Create an API service app with a public keyOkta3 min
- Grant the users, groups and event hook scopesOkta1 min
- Paste your Okta domain and client IDTessel1 min
- Pick events and let Tessel verify the hookTessel2 min
- Create a test user and watch the event arriveVerify520 ms
Access that follows people, starting today.
Connect Okta on the free plan. Up to three builders and 10,000 runs a month, no card required.