Documentation Index
Fetch the complete documentation index at: https://docs.leen.dev/llms.txt
Use this file to discover all available pages before exploring further.
Required Permissions
The API token inherits the permissions of the Okta user who creates it. The token creator must have a role that grants the following OAuth scopes:| Scope | Description | APIs Used |
|---|---|---|
okta.users.read | Read user profiles, credentials, group memberships, and enrolled MFA factors | List Users, List User Groups, List User MFA Factors |
okta.groups.read | Read group information and group-application assignments | List Groups, List Group Applications |
okta.apps.read | Read application configurations and user-application assignments | List Applications, List Application Users |
okta.logs.read | Read system log events | Get System Log Events |
okta.roles.read | Read administrative role assignments for users | List User Roles |
okta.policies.read | Read security policies, policy rules, and policy mappings | List Policies, Get Policy, List Policy Rules, List Policy Mappings |
Onboarding Okta Identity Provider
Follow the steps below to onboard your environment to our Okta Identity Provider integration. This integration uses the Core Okta API to interact with your Okta organization. To connect to Okta, we require:- Okta Domain
- API Token
Determine Your Okta Domain
Your Okta domain (also known as your org URL) is the URL you use to access your Okta organization. It typically looks like:
https://{your-tenant}.okta.com. Make note of this URL as you’ll need it later.
If you are on the Okta Admin console, the URL will appear as https://{your-tenant}-admin.okta.com. The the URL excluding -admin is your Okta domain.Navigate Okta Admin Console
Login to the Okta Admin Console and navigate to the API Tokens page. (Sidebar: Security -> API -> Tokens)
Create API Token
Click on the 
On the next screen, you will see the secret API token.
Create Token button. You will see the following screen.Add a name for the token(eg. leen-okta-idp), set allowable origin to Any IP and click on the Create Token button.