Skip to main content
Connect Okta to add users, groups, applications, and their access relationships to your Asset Map.

What it maps

These relationships help agents understand how an identity receives access to an application or AWS role.

Access required

Use an Okta API token created by an administrator with read access to the resources above. A dedicated service account keeps the connection independent of an individual employee’s account. Okta API tokens inherit their creator’s permissions. Antigen uses the token for read operations. See Okta API token permissions.

Connect Okta

1. Create an API token

Sign in to the Okta Admin Console with the account that will own the integration. Open Security → API → Tokens and create a token named Antigen. Copy the token value before closing the dialog. If you restrict the token to specific network zones, ensure those zones allow requests from Antigen.

2. Complete the connection

Open Settings → Integrations → Okta in Antigen. Enter your Okta organization URL, such as https://example.okta.com, and paste the API token. Select Connect. Antigen discovers the resources available to the token and adds them to your Asset Map.

Troubleshooting

The connection stops syncing

Check that the token’s owner is still active and has the required permissions. Okta also expires tokens after 30 days without use. See Token expiration and deactivation.

Applications or admin roles are missing

Check whether the token’s owner can view those resources in Okta. The token’s access changes when the owner’s administrative permissions change.