Skip to main content
{ Identity and Access }

Okta API Access Review

Reviews the API service integrations, OAuth service apps, and API tokens that reach Okta's admin API, and proposes which to revoke, restrict, or keep.

What this agent does

This read-only agent reviews access to Okta's own admin API. It lists the API service integrations and their okta.* scopes. It lists the OAuth service apps that hold okta.* scopes or admin roles. It lists the API tokens with the admin role each one inherits from its creator. It lists the SSO apps assigned to Everyone with no sign-ins in 90 days. It proposes which to revoke, which to restrict, and which to keep, with the evidence for each. A person makes every change.

The challenge

Third parties reach Okta's own admin API. A security vendor's API service integration holds okta.users.manage. An OAuth service app built for a migration holds the Super Administrator role. A super admin created a token for a nightly sync, so the sync runs as super admin. Nobody lists these together.

The solution

The agent reads every integration, service app, and token that can call the admin API in one pass. It states each scope and role in plain words, such as manage all users or act as super admin. It ties each token to the current role of the admin who created it. It proposes the narrowest change for each item and presents every proposal as a candidate. Provides a ranked queue of admin API access, with the evidence for each proposal.

Workflow

  1. 01

    List integrations and service apps

    List API service integrations with their okta.* scopes, and OAuth service apps with their okta.* scopes and admin roles.

  2. 02

    List tokens and SSO apps

    List API tokens with the creator's current admin role and last use, and SSO apps assigned to Everyone with their last sign-in.

  3. 03

    Rank

    Rank each item by the scopes or role it holds, its last use, and whether I mark it as approved.

  4. 04

    Propose

    Write a revoke, restrict, or keep proposal per item with the evidence.

  5. 05

    Report

    Publish the ranked queue with each proposal.

Agent template

# Okta API Access Review

## Measurable outcomes

Every API service integration, OAuth service app, API token, and idle SSO app assigned to Everyone is in the ranked queue. Each item has its access in plain words and a proposal. Track the items flagged by at least one rule. A proposal counts as applied when the next run finds the access removed or narrowed.

## Procedure

Each run, list every API service integration with its publisher, its granted okta.* scopes, and its last use from the System Log. List every OAuth service app that holds an okta.* scope or an admin role, with its scopes, its roles, and its last token issued. List every API token with the admin who created it, that admin's current role, the token's network restriction, and its last use. List every SSO app assigned to the Everyone group, and record its last sign-in from the System Log. Translate each scope and role into plain words, such as read all users, manage groups, manage applications, or act as super admin. Rank each item by the most sensitive scope or role it holds. Lower the rank for items used in the last 30 days. Lower the rank for items I mark as approved. Flag every item with a manage scope that no approved use needs. Flag every service app with the Super Administrator role. Flag every token created by a super admin. Flag every token created by a person instead of a service account. Flag every SSO app assigned to Everyone with no sign-ins in 90 days. When I ask, also list user grants to OAuth apps and flag grants from deactivated users. For each item, propose one of revoke, restrict, or keep. Revoke means remove the integration, the service app, the token, or the app assignment. For a service app, restrict means remove the admin role or narrow the okta.* scopes. For an app with user grants, restrict means set the app's consent to required. For a token, restrict means replace it with an OAuth service app that holds only the scopes its job needs. For an SSO app, restrict means assign it to a named group instead of Everyone. Keep means the use is approved and the access matches it. Give the evidence for each proposal, such as the scopes, the role, the last use, and the publisher. Present every proposal as a candidate and change nothing. Never revoke a token, deactivate an app, change an assignment, or change a consent setting.

## Requirements

It needs an OAuth service app with only okta.*.read scopes, or an API token created by a Read-Only Administrator, and nothing more. It never changes applications, integrations, tokens, grants, roles, or settings. Reports show app names, scopes, roles, and counts. User names appear as stable pseudonyms.