Skip to main content
Telara

Integrations / Okta Identity Governance

Okta Identity Governance logo

Okta Identity Governance

Okta Identity Governance access certification, entitlement, grant, collection, and catalog data for access-review-aligned Telara setup proposals.

OAuth 2.0
Indexes
Actions

What Telara does

Capability matrix

Before you connect

Prerequisites

An Okta org with Identity Governance (IGA) enabled. Workforce Identity Cloud without IGA is a different connector (Okta).
Super admin, or a custom admin who can create API tokens and read IGA objects.

Vendor setup

Get the credential

1
Open API tokens
In Okta, go to Security → API → Tokens.
2
Create a token
Click Create Token while signed in as the admin whose IGA view Telara should inherit. Copy it once. If Telara’s form offers OAuth, prefer that over a token.
3
Paste in Telara
Settings → Integrations → Okta Identity Governance. Enter your Okta domain and paste the token (or finish OAuth).

Permissions Telara requests

  • okta.governance.accessCertifications.read
    OAuth 2.0
  • okta.governance.accessCertifications.manage
    OAuth 2.0
  • okta.governance.accessRequests.read
    OAuth 2.0
  • okta.governance.accessRequests.manage
    OAuth 2.0
  • okta.governance.entitlements.read
    OAuth 2.0
  • okta.governance.entitlements.manage
    OAuth 2.0
  • okta.accessRequests.catalog.read
    OAuth 2.0
  • okta.accessRequests.request.read
    OAuth 2.0
  • okta.accessRequests.request.manage
    OAuth 2.0

In Telara

Connect in Telara

OAuth 2.0

Okta OIN API Service Integration OAuth using client credentials for Identity Governance. Store base_url as the customer Okta org URL, for example https://company.okta.com.

In Telara, open Settings → Integrations, choose this connector, and click Connect. Telara sends you to the vendor to approve access, then returns you here. You do not create an OAuth app or paste a client secret.

Fields Telara asks for
  • Base Url
  • Scope
API key

Okta API token for organizations that authorize OIG API access through SSWS. Store base_url as the Okta org URL.

In Telara, open Settings → Integrations, choose this connector, and paste the key into the fields Telara shows.

Fields Telara asks for
  • API token
  • Base Url

Knowledge

What gets indexed

ResourceCoverage
CampaignPartial — not every record the vendor holds is synced
CertificationPartial — not every record the vendor holds is synced

Sync

Freshness & sync

ResourceLagDeletions
CampaignUp to 1 dayRemoved records disappear on the next full sync
CertificationUp to 1 dayRemoved records disappear on the next full sync

Data handling

Permissions & data handling

The scopes above are the permissions this connector requests. They come from the catalog, not from a hand-written page.

Excluded from semantic search: Campaign, Certification.

After connect

Verify it worked

After you save, Telara runs a read-only check against the account. The integration shows as connected when that check succeeds.

Honesty

Known limitations

This does not replace the Okta directory connector. Governance objects and users are separate Connect buttons.
Preview vs production Okta orgs are different domains.