Integrations / Okta
Okta
Okta identity and access management for users, groups, applications, factors, policies, and system log investigations.
What Telara does
Capability matrix
Before you connect
Prerequisites
Vendor setup
Get the credential
Permissions Telara requests
- okta.users.readOAuth 2.0
- okta.users.manageOAuth 2.0
- okta.groups.readOAuth 2.0
- okta.groups.manageOAuth 2.0
- okta.apps.readOAuth 2.0
- okta.apps.manageOAuth 2.0
- okta.logs.readOAuth 2.0
In Telara
Connect in Telara
Okta OIN API Service Integration OAuth using client credentials. Store base_url as the customer Okta org URL, for example https://company.okta.com.
In Telara, open Settings → Integrations, choose this connector, and click Connect. Telara sends you to the vendor to approve access, then returns you here. You do not create an OAuth app or paste a client secret.
- Base Url
- Scope
Okta management API token. Store base_url as the Okta org URL, for example https://company.okta.com.
In Telara, open Settings → Integrations, choose this connector, and paste the key into the fields Telara shows.
- API token
- Base Url
Knowledge
What gets indexed
| Resource | Coverage |
|---|---|
| Users | Partial — not every record the vendor holds is synced |
| Group | Partial — not every record the vendor holds is synced |
| Application | Partial — not every record the vendor holds is synced |
| Audit event | Partial — not every record the vendor holds is synced |
Spend
What gets measured
Resolution: Aggregated buckets.
Attribution: Matched to people by email.
How far back vendor history goes is not published uniformly for this connector.
Sync
Freshness & sync
| Resource | Lag | Deletions |
|---|---|---|
| Users | Up to 1 hour | Removed records disappear on the next full sync |
| Group | Up to 1 hour | Removed records disappear on the next full sync |
| Application | Up to 1 day | Removed records disappear on the next full sync |
| Audit event | Up to 1 hour | Removed records disappear when Telara next reconciles that resource |
Data handling
Permissions & data handling
The scopes above are the permissions this connector requests. They come from the catalog, not from a hand-written page.
Excluded from semantic search: Users, Group, Application, Audit event.
After connect
Verify it worked
After you save, Telara runs a read-only check against the account. The integration shows as connected when that check succeeds.
Honesty

