Skip to main content
Ensure that your Okta account has API Access Administrator, Organization Administrator, or Super Administrator privileges.

Getting Your Okta Credentials

To connect Okta with StackOne using OAuth 2.0, you’ll need your Okta domain and OAuth application credentials.

1

Log in to Okta

Log in to your Okta account at https://login.okta.com/

Okta login page
2

Navigate to Okta Admin Console

From your Okta homepage, click the Admin button in the top right corner.

Okta go to admin console
3

Find Your Okta Domain

Your Okta domain can be found in the URL when logged in to Okta.

  • Given the URL https://your-org.okta.com/app/UserHome, your domain is your-org.okta.com
  • For preview environments, the domain may be your-org.oktapreview.com
Okta domain in URL
4

Create an OAuth Application

Create an OAuth application to obtain your Client ID and Client Secret.

  • In the Admin Console, navigate to Applications > Applications
  • Click Create App Integration
  • Select OIDC - OpenID Connect as the Sign-in method
  • Select Web Application as the Application type
  • Click Next
Okta init create app integration
5

Configure Application Settings

Configure your OAuth application with the appropriate settings.

  • Enter an App integration name (e.g., StackOne Integration)
  • Check Authorization Code and Refresh Token both under the Grant type
  • Set the Sign-in redirect URI to the callback URL provided by StackOne: https://api.stackone.com/connect/oauth2/okta/callback
  • Under Assignments, select Allow everyone in your organization to access or assign specific groups/users as needed
  • Click Save
Okta create app integration
6

Copy Client Credentials

After saving, copy your OAuth credentials.

  • Client ID is displayed on the application’s General tab
  • Client Secret is also on the General tab (click the eye icon to reveal)
  • Store these credentials securely as you’ll need them for the connection
Okta copy credentials
7

Configure API Scopes

Enables actions: Activate Device, Activate Policy, Activate Policy Rule, Add User To Group, Clone An Existing Policy, Create A Policy Simulation, Create Group, Create Policy, Create Policy Rule, Create Realm, Create User, Create User Type, Deactivate Device, Deactivate Policy, Deactivate Policy Rule, Delete Device, Delete Group, Delete Policy, Delete Policy Rule, Delete Realm, Delete User, Delete User Type, Get Device, Get Group, Get Policy, Get Realm, Get User, Get User Info, Get User Type, List All Apps Mapped To A Policy, List All Policy Rules, List All Resources Mapped To A Policy, List Devices, List Group Members, List Groups, List Policies, List Realms, List User Blocks, List User Types, List Users, Remove User From Group, Replace Policy, Replace Policy Rule, Replace User, Replace User Type, Retrieve A Policy Resource Mapping, Retrieve A Policy Rule, Update Group, Update Realm, Update User, Update User Type

In the application you just created, navigate to the Okta API Scopes tab. For each required okta.* scope listed below, click the Grant button next to the scope name.
See Okta OAuth 2.0 Scopes for details.
Note that offline_access and openid are OIDC scopes — these are not shown in the Okta API Scopes tab. Instead, enter them in the Scopes field when configuring the StackOne connection.

Okta select scopes

Realm Access Configuration

Required for: Create Realm, Delete Realm, Get Realm, List Realms, Update Realm

Realm scopes require an Okta Identity Governance, Secure Partner Access, or Advanced Directory Management subscription.

1

Verify subscription eligibility

If your subscription does not include realm management, the API will return authorization errors.

  • In the Admin Console, click Settings in the left sidebar, then click Account to verify your subscription tier

Linking the Account from the Hub

1

Navigate to the Hub

Use one of the three Linking Account Methods to access the Hub.
2

Fill out the fields

Fill out the following fields using details from your provider:
  • Okta Domain
  • Client ID
  • Client Secret
  • Scopes (Optional)
  • Event Hook Name (Optional)
3

Connect

  • Click Connect
  • If applicable, the provider will redirect you to a sign-in or authorization page. Complete the provider’s authorization flow.
  • Once authorization is successful, you will see a confirmation popup

If the account linking is successful, you will see the newly linked account in your Accounts page.