Skip to main content
Telara

Integrations / Okta

Okta logo

Okta

Okta identity and access management for users, groups, applications, factors, policies, and system log investigations.

OAuth 2.0
Indexes
Spend
AI estate
Actions
Events

What Telara does

Capability matrix

Before you connect

Prerequisites

An Okta org.
Super admin, or a custom admin role that can create API tokens and read the objects you care about.

Vendor setup

Get the credential

1
Open API tokens
In Okta, go to Security → API → Tokens (wording varies slightly by Okta version).
2
Create a token
Create an API token while signed in as the admin whose view Telara should inherit.
3
Paste in Telara
Settings → Integrations → Okta. Include your Okta domain if the form asks for it.

Permissions Telara requests

  • okta.users.read
    OAuth 2.0
  • okta.users.manage
    OAuth 2.0
  • okta.groups.read
    OAuth 2.0
  • okta.groups.manage
    OAuth 2.0
  • okta.apps.read
    OAuth 2.0
  • okta.apps.manage
    OAuth 2.0
  • okta.logs.read
    OAuth 2.0

In Telara

Connect in Telara

OAuth 2.0

Okta OIN API Service Integration OAuth using client credentials. Store base_url as the customer Okta org URL, for example https://company.okta.com.

In Telara, open Settings → Integrations, choose this connector, and click Connect. Telara sends you to the vendor to approve access, then returns you here. You do not create an OAuth app or paste a client secret.

Fields Telara asks for
  • Base Url
  • Scope
API key

Okta management API token. Store base_url as the Okta org URL, for example https://company.okta.com.

In Telara, open Settings → Integrations, choose this connector, and paste the key into the fields Telara shows.

Fields Telara asks for
  • API token
  • Base Url

Knowledge

What gets indexed

ResourceCoverage
UsersPartial — not every record the vendor holds is synced
GroupPartial — not every record the vendor holds is synced
ApplicationPartial — not every record the vendor holds is synced
Audit eventPartial — not every record the vendor holds is synced

Spend

What gets measured

Resolution: Aggregated buckets.

Attribution: Matched to people by email.

How far back vendor history goes is not published uniformly for this connector.

Sync

Freshness & sync

ResourceLagDeletions
UsersUp to 1 hourRemoved records disappear on the next full sync
GroupUp to 1 hourRemoved records disappear on the next full sync
ApplicationUp to 1 dayRemoved records disappear on the next full sync
Audit eventUp to 1 hourRemoved records disappear when Telara next reconciles that resource

Data handling

Permissions & data handling

The scopes above are the permissions this connector requests. They come from the catalog, not from a hand-written page.

Excluded from semantic search: Users, Group, Application, Audit event.

After connect

Verify it worked

After you save, Telara runs a read-only check against the account. The integration shows as connected when that check succeeds.

Honesty

Known limitations

The token sees what the creating admin sees. A read-only custom admin is safer and often enough.
Preview vs production Okta orgs are different domains — connecting preview does not cover production.