Skip to main content
POST
Create an Okta Credential

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Body

application/json

CreateOktaCredentialRequestData

integration_id
string
required

The ID of the Okta integration this credential belongs to

Pattern: ^okitg_[0-9a-hjkmnp-tv-z]{26}$
Example:

"okitg_01hq8xyzabc123def456ghi789"

oauth2_auth_method
enum<string>
required

The authentication method: api_token (SSWS, live import today), client_secret, or private_key_jwt (OAuth2)

Available options:
client_secret,
private_key_jwt,
api_token
oauth2_client_id
string | null

The OAuth2 client ID. Required for the OAuth2 methods; omitted for the api_token method

oauth2_client_secret
string | null

The OAuth2 client secret (client_secret method)

Pattern: ^[0-9a-zA-Z\.\-]{32,44}$
oauth2_private_key
string | null

The OAuth2 private key JWT (private_key_jwt method)

Pattern: ^[A-Za-z0-9-_=]+\.[A-Za-z0-9-_=]+\.?[A-Za-z0-9-_.+/=]*$
api_token
string | null

The Okta SSWS API token (api_token method). A 42-character token, per the Okta API client's connection rules

Pattern: ^[A-Za-z0-9_-]{42}$
notes
string

Optional notes about this credential

Maximum string length: 1000

Response

OktaCredentialDetailedResponseData

id
string
required
Example:

"okcrd_01hq8xyzabc123def456ghi789"

integration_id
string
required

The ID of the Okta integration this credential belongs to

Example:

"okitg_01hq8xyzabc123def456ghi789"

state
enum<string>
required

The current lifecycle state of the credential

Available options:
staged,
active,
expiring,
expired,
deactivated
Example:

"staged"

oauth2_auth_method
enum<string>
required

The OAuth2 authentication method

Available options:
client_secret,
private_key_jwt,
api_token
Example:

"client_secret"

oauth2_client_id
string
required

The OAuth2 client ID

oauth2_scopes
string[] | null
required

The OAuth2 scopes

notes
string | null
required

Optional notes

timestamp
TimestampStateData · object
required

The timestamps for the credential record

API hyperlinks related to the record