Skip to content

Triagic + Okta: ticket investigations over your cloud account, read-only

Look up users, their groups and app assignments, and the system log, including recent failed sign-ins. Useful for “can't log in” tickets. Nothing can be changed. Triagic connects to Okta from the desktop app on each member's machine, with a credential you configure, and shows every call it makes while it investigates a ticket. Nothing is copied out of Okta.

What you can ask

  • In Okta, find the log lines for the Lambda that handles webhook retries between 10:00 and 10:20
  • Did the error rate in Okta for the API gateway change in the last six hours?
  • Which alarms in Okta fired this week, and which are still in alarm?
  • Show me the Okta deployment that was live when ticket 4819 was filed
  • What is the dead-letter queue depth in Okta right now?

What the agent can do

These are the 12 tools Triagic exposes from the Okta MCP server. Anything else the server lists is dropped at connect time.

  • list_users
  • get_user
  • get_user_profile_attributes
  • list_user_groups
  • list_groups
  • get_group
  • list_group_users
  • list_group_apps
  • list_applications
  • get_application
  • get_logs
  • get_login_failures

Connect in three steps

  1. 1

    Mint a read-only credential in Okta

    Create a dedicated user or token that can only read. The token is requested with read scopes only, the server drops every tool those scopes don't cover, and an allowlist keeps the user, group, app and log reads.

  2. 2

    Add it in the Triagic portal

    Integrations, then Add shared data source, then Okta.

    • Org URL: Your Okta org address. The -admin console address works too; it's converted.
    • Client ID: From an API Services app integration: Applications → Create App Integration → API Services. On its General tab, set client authentication to “Public key / Private key” and turn off “Require DPoP”.
    • Key ID (kid): Shown next to the public key in the app's Public keys section.
    • Private key (PEM): The PEM Okta gave you when it generated the key pair, pasted whole. Grant the app okta.users.read, okta.groups.read, okta.apps.read and okta.logs.read on its Okta API Scopes tab, and assign it the Read-Only Administrator role on its Admin roles tab.
  3. 3

    Let a desktop pick it up

    Saving validates the shape of what you typed. The first desktop app to sync starts Okta locally and reports running or degraded with the error text.

Field-by-field setup, TLS options and the error table: Okta in the docs.

Read-only, by construction

The token is requested with read scopes only, the server drops every tool those scopes don't cover, and an allowlist keeps the user, group, app and log reads.

FAQ

Can Triagic change anything in Okta?
No. The token is requested with read scopes only, the server drops every tool those scopes don't cover, and an allowlist keeps the user, group, app and log reads. Give it a read-only credential as well, so the guarantee does not rest on one layer.
What do I need to connect Okta?
Org URL, Client ID, Key ID (kid), Private key (PEM). The desktop app on a member's machine starts the connection; the portal never holds a live process.
Does Okta cost extra?
No. Every connector is included in the seat price. Start a 14-day trial without a card.

Related integrations

Try it on your own Okta

No card. Install the desktop app, connect Okta read-only, and triage a real ticket this afternoon.