Overview
Connect Okta with Flows360
Okta integration for Flows360 workflows.
Use the Okta connector to include its declared actions and events in Flows360 workflows without duplicating the integration logic inside each consuming system. This pinned connector version currently exposes 10 actions and 1 trigger.
Available actions
- Create User
- Activate User
- Deactivate User
- Suspend User
- Add User to Group
- Remove User from Group
- Update User
- Find User by Email
- Plus 2 additional declared actions.
Available triggers
- New Event
The capability list above is generated from the exact reviewed connector package so the public description stays aligned with the version Flows360 operates.
Technical guide
Technical reference
Package identity
- Connector: Okta
- Package:
@activepieces/piece-okta@0.2.0 - Exact artifact digest:
sha256:e263fe916c7457d66bdda6187db33671ea0b677ec98d18d37c0fbca07f570063 - Runtime: Activepieces-compatible deterministic worker
- Source: the exact reviewed Activepieces source
Authentication
CUSTOM AUTH. Connection values are tenant-specific and remain in the consuming Studio instance; CDK stores definitions and field metadata, not customer credential values.
Action contracts
- Create User (
create_user), Creates a user without credentials and sends account creation prompt via email Classification: read. - Activate User (
activate_user), Activate a previously deactivated or pending user Classification: read. - Deactivate User (
deactivate_user), Deactivate (disable) a user in Okta Classification: read. - Suspend User (
suspend_user), Temporarily suspend a user in Okta Classification: read. - Add User to Group (
add_user_to_group), Add a user to a specific Okta group Classification: read. - Remove User from Group (
remove_user_from_group), Remove a user from an Okta group Classification: read. - Update User (
update_user), Update user profile information Classification: read. - Find User by Email (
find_user_by_email), Look up an Okta user by their email address Classification: read. - Find Group by Name (
find_group_by_name), Search for an Okta group by name Classification: read. - Custom API Call (
custom_api_call), Make a custom API call to a specific endpoint Classification: read.
Trigger contracts
- New Event, webhook.
Verification
Deterministic execution evidence is recorded for the pinned artifact, including 1 exercised action entrypoint and 0 exercised trigger entrypoints.
Capability summary
Authentication
Authentication method: custom
Authentication profiles
connection · custom
- Okta Domain Required
- API Token Required · protected credential
Supported objects
| Object | Read | Write | Notes |
|---|---|---|---|
| Create User | Yes | No | Creates a user without credentials and sends account creation prompt via email |
| Activate User | Yes | No | Activate a previously deactivated or pending user |
| Deactivate User | Yes | No | Deactivate (disable) a user in Okta |
| Suspend User | Yes | No | Temporarily suspend a user in Okta |
| Add User to Group | Yes | No | Add a user to a specific Okta group |
| Remove User from Group | Yes | No | Remove a user from an Okta group |
| Update User | Yes | No | Update user profile information |
| Find User by Email | Yes | No | Look up an Okta user by their email address |
| Find Group by Name | Yes | No | Search for an Okta group by name |
| Custom API Call | Yes | No | Make a custom API call to a specific endpoint |
| New Event | Yes | No | webhook trigger declared by the pinned package. |
Supported actions
Create User · Read
Creates a user without credentials and sends account creation prompt via email
create_user · Risk: low · Retry: safe
Inputs
firstName· string · Required, User first namelastName· string · Required, User last nameemail· string · Required, User email addresslogin· string · Optional, User login (typically same as email)mobilePhone· string · Optional, User mobile phone numbersendEmail· boolean · Optional, Send account creation email to user
Activate User · Read
Activate a previously deactivated or pending user
activate_user · Risk: low · Retry: safe
Inputs
userId· string · Required, Select a usersendEmail· boolean · Optional, Send activation email to user
Deactivate User · Read
Deactivate (disable) a user in Okta
deactivate_user · Risk: low · Retry: safe
Inputs
userId· string · Required, Select a usersendEmail· boolean · Optional, Send deactivation email to user
Suspend User · Read
Temporarily suspend a user in Okta
suspend_user · Risk: low · Retry: safe
Inputs
userId· string · Required, Select a user
Add User to Group · Read
Add a user to a specific Okta group
add_user_to_group · Risk: low · Retry: safe
Inputs
userId· string · Required, Select a usergroupId· string · Required, Select a group
Remove User from Group · Read
Remove a user from an Okta group
remove_user_from_group · Risk: low · Retry: safe
Inputs
groupId· string · Required, Select a groupuserId· string · Required, Select a user
Update User · Read
Update user profile information
update_user · Risk: low · Retry: safe
Inputs
userId· string · Required, Select a userfirstName· string · Optional, Updated first namelastName· string · Optional, Updated last nameemail· string · Optional, Updated email addressmobilePhone· string · Optional, Updated mobile phone numbercustomAttributes· object · Optional, JSON object with custom profile attributes
Find User by Email · Read
Look up an Okta user by their email address
find_user_by_email · Risk: low · Retry: safe
Inputs
email· string · Required, The user email address
Find Group by Name · Read
Search for an Okta group by name
find_group_by_name · Risk: low · Retry: safe
Inputs
groupName· string · Required, The group name to search for
Custom API Call · Read
Make a custom API call to a specific endpoint
custom_api_call · Risk: low · Retry: safe
Inputs
url· object · Requiredmethod· string · Requiredheaders· object · Optional, Authorization headers are injected automatically from your connection.queryParams· object · Optional, Appended to the URL as ?key=value.body_type· string · Optionalbody· object · Optionalresponse_is_binary· boolean · Optional, Enable for files like PDFs, images, etc.failsafe· boolean · Optional, On a failed request, output the error instead of failing the step.timeout· number · Optional, Seconds to wait for a response. Empty: up to the flow limit (10 min).followRedirects· boolean · Optional, Follow 3xx redirects instead of returning them as the response.
Triggers
New Event · Webhook
Fires when a new Okta event is generated
Inputs
eventTypes· arrayhookName· string
Setup
Setup
- Add the Okta connector to the workflow in the target Flows360 Studio instance.
- Create or select the tenant-specific connection required by the connector. Connection secrets remain in the Studio connection boundary and are not copied into CDK documentation.
- Provide the connection fields declared by the pinned package:
- Okta Domain (
domain), required. - API Token (
apiToken), required; stored as a sensitive connection value.
- Select the required action or trigger and complete its declared input fields. Required and optional inputs are defined by the exact package schema.
- Test the workflow in the appropriate environment before enabling production scheduling or event delivery.
Limitations
Limitations and operational notes
- This content describes
@activepieces/piece-okta@0.2.0; provider behaviour can change independently and should be revalidated when the provider or connector version changes. - Only the 10 actions and 1 trigger declared by this pinned package are represented here.
- Tenant credentials and connection values are not stored in the public connector record.
- Provider-side permissions, account entitlements, quotas and rate limits remain subject to the connected provider account and are not inferred when the package does not declare them.
- Deterministic execution evidence is recorded for the pinned artifact, including 1 exercised action entrypoint and 0 exercised trigger entrypoints.
Troubleshooting
Why canu2019t the connector authenticate?
Check the tenant connection in Studio and confirm every required Okta connection field is present. Re-authorise OAuth-based connections if the provider token or consent has expired. Do not place credential values in CDK content or logs.
Why is an action or trigger unavailable?
Confirm that the workflow is using @activepieces/piece-okta@0.2.0 and compare the requested capability with the declared action and trigger list for this version. A capability that is not declared by the pinned package should not be presented as supported.
What should I check after a provider-side change?
Revalidate authentication, required fields, action/trigger behaviour and provider documentation before publishing refreshed connector content or moving a new package version into production.