# Triagic + Okta: ticket investigations over your cloud account, read-only

> Okta in Triagic: Look up users, their groups and app assignments, and the system log, including recent failed sign-ins.

Source: https://triagic.com/integrations/okta

## What you can ask

- In Okta, find the log lines for the Lambda that handles webhook retries between 10:00 and 10:20
- Did the error rate in Okta for the API gateway change in the last six hours?
- Which alarms in Okta fired this week, and which are still in alarm?
- Show me the Okta deployment that was live when ticket 4819 was filed
- What is the dead-letter queue depth in Okta right now?

## What the agent can do

- `list_users`
- `get_user`
- `get_user_profile_attributes`
- `list_user_groups`
- `list_groups`
- `get_group`
- `list_group_users`
- `list_group_apps`
- `list_applications`
- `get_application`
- `get_logs`
- `get_login_failures`

## Connect in three steps

1. **Mint a read-only credential in Okta.** Create a dedicated user or token that can only read. The token is requested with read scopes only, the server drops every tool those scopes don't cover, and an allowlist keeps the user, group, app and log reads.
2. **Add it in the Triagic portal.** Integrations, then Add shared data source, then Okta. Fill in: Org URL (required): Your Okta org address. The -admin console address works too; it's converted.; Client ID (required): From an API Services app integration: Applications → Create App Integration → API Services. On its General tab, set client authentication to “Public key / Private key” and turn off “Require DPoP”.; Key ID (kid) (required): Shown next to the public key in the app's Public keys section.; Private key (PEM) (required): The PEM Okta gave you when it generated the key pair, pasted whole. Grant the app okta.users.read, okta.groups.read, okta.apps.read and okta.logs.read on its Okta API Scopes tab, and assign it the Read-Only Administrator role on its Admin roles tab.
3. **Let a desktop pick it up.** Saving validates the shape of what you typed. The first desktop app to sync starts Okta locally and reports running or degraded with the error text.

Setup reference: https://triagic.com/docs/integrations/cloud#okta

## Read-only, by construction

The token is requested with read scopes only, the server drops every tool those scopes don't cover, and an allowlist keeps the user, group, app and log reads.

## FAQ

**Can Triagic change anything in Okta?**
No. The token is requested with read scopes only, the server drops every tool those scopes don't cover, and an allowlist keeps the user, group, app and log reads. Give it a read-only credential as well, so the guarantee does not rest on one layer.

**What do I need to connect Okta?**
Org URL, Client ID, Key ID (kid), Private key (PEM). The desktop app on a member's machine starts the connection; the portal never holds a live process.

**Does Okta cost extra?**
No. Every connector is included in the seat price. Start a 14-day trial without a card.

## Related integrations

- [AWS CloudWatch](https://triagic.com/integrations/aws-cloudwatch)
- [AWS SQS / SNS](https://triagic.com/integrations/aws-sqs-sns)
- [Azure Monitor](https://triagic.com/integrations/azure-monitor)
- [Azure](https://triagic.com/integrations/azure)
