Connection
- Authentication: API key (API token).
- Required settings:
- Organization — The subdomain before .okta.com / .oktapreview.com / .okta-emea.com in your admin URL (e.g. “acme” from acme-admin.okta.com).
- Domain suffix — The Okta domain suffix for your org: okta.com (production), oktapreview.com (preview), or okta-emea.com (EMEA).
Sign in to the Okta Admin Console → Security → API → Tokens → Create token. Name it, copy the token (starts with 00…). The token inherits your admin role — use a dedicated API service account with the minimum required roles (Read-only Administrator for read-only, or Super Administrator for write).See Okta’s documentation.
Read actions (11)
Write actions (10)
Permissions
Every action above must be explicitly granted to an agent before it can be used. See Permissions for the grant model and Security for how credentials are protected.Last reviewed against the provider API: September 2026.