Skip to content
← Back to documentation
Technical Reference

Okta

Okta integration for Flows360 workflows.

CategoryProductivity
Authenticationcustom
Version0.2.0
Published scopes0 published scopes
Last updatedSeptember 21, 2026

Overview

Connect Okta with Flows360

Okta integration for Flows360 workflows.

Use the Okta connector to include its declared actions and events in Flows360 workflows without duplicating the integration logic inside each consuming system. This pinned connector version currently exposes 10 actions and 1 trigger.

Available actions

  • Create User
  • Activate User
  • Deactivate User
  • Suspend User
  • Add User to Group
  • Remove User from Group
  • Update User
  • Find User by Email
  • Plus 2 additional declared actions.

Available triggers

  • New Event

The capability list above is generated from the exact reviewed connector package so the public description stays aligned with the version Flows360 operates.

Technical guide

Technical reference

Package identity

  • Connector: Okta
  • Package: @activepieces/piece-okta@0.2.0
  • Exact artifact digest: sha256:e263fe916c7457d66bdda6187db33671ea0b677ec98d18d37c0fbca07f570063
  • Runtime: Activepieces-compatible deterministic worker
  • Source: the exact reviewed Activepieces source

Authentication

CUSTOM AUTH. Connection values are tenant-specific and remain in the consuming Studio instance; CDK stores definitions and field metadata, not customer credential values.

Action contracts

  • Create User (create_user), Creates a user without credentials and sends account creation prompt via email Classification: read.
  • Activate User (activate_user), Activate a previously deactivated or pending user Classification: read.
  • Deactivate User (deactivate_user), Deactivate (disable) a user in Okta Classification: read.
  • Suspend User (suspend_user), Temporarily suspend a user in Okta Classification: read.
  • Add User to Group (add_user_to_group), Add a user to a specific Okta group Classification: read.
  • Remove User from Group (remove_user_from_group), Remove a user from an Okta group Classification: read.
  • Update User (update_user), Update user profile information Classification: read.
  • Find User by Email (find_user_by_email), Look up an Okta user by their email address Classification: read.
  • Find Group by Name (find_group_by_name), Search for an Okta group by name Classification: read.
  • Custom API Call (custom_api_call), Make a custom API call to a specific endpoint Classification: read.

Trigger contracts

  • New Event, webhook.

Verification

Deterministic execution evidence is recorded for the pinned artifact, including 1 exercised action entrypoint and 0 exercised trigger entrypoints.

Capability summary

Authenticationcustom
Supported objects11
Supported actions10
Triggers1

Authentication

Authentication method: custom

Authentication profiles

connection · custom
  • Okta Domain Required
  • API Token Required · protected credential

Supported objects

ObjectReadWriteNotes
Create User Yes No Creates a user without credentials and sends account creation prompt via email
Activate User Yes No Activate a previously deactivated or pending user
Deactivate User Yes No Deactivate (disable) a user in Okta
Suspend User Yes No Temporarily suspend a user in Okta
Add User to Group Yes No Add a user to a specific Okta group
Remove User from Group Yes No Remove a user from an Okta group
Update User Yes No Update user profile information
Find User by Email Yes No Look up an Okta user by their email address
Find Group by Name Yes No Search for an Okta group by name
Custom API Call Yes No Make a custom API call to a specific endpoint
New Event Yes No webhook trigger declared by the pinned package.

Supported actions

Create User · Read

Creates a user without credentials and sends account creation prompt via email

create_user · Risk: low · Retry: safe

Inputs

  • firstName · string · Required, User first name
  • lastName · string · Required, User last name
  • email · string · Required, User email address
  • login · string · Optional, User login (typically same as email)
  • mobilePhone · string · Optional, User mobile phone number
  • sendEmail · boolean · Optional, Send account creation email to user
Activate User · Read

Activate a previously deactivated or pending user

activate_user · Risk: low · Retry: safe

Inputs

  • userId · string · Required, Select a user
  • sendEmail · boolean · Optional, Send activation email to user
Deactivate User · Read

Deactivate (disable) a user in Okta

deactivate_user · Risk: low · Retry: safe

Inputs

  • userId · string · Required, Select a user
  • sendEmail · boolean · Optional, Send deactivation email to user
Suspend User · Read

Temporarily suspend a user in Okta

suspend_user · Risk: low · Retry: safe

Inputs

  • userId · string · Required, Select a user
Add User to Group · Read

Add a user to a specific Okta group

add_user_to_group · Risk: low · Retry: safe

Inputs

  • userId · string · Required, Select a user
  • groupId · string · Required, Select a group
Remove User from Group · Read

Remove a user from an Okta group

remove_user_from_group · Risk: low · Retry: safe

Inputs

  • groupId · string · Required, Select a group
  • userId · string · Required, Select a user
Update User · Read

Update user profile information

update_user · Risk: low · Retry: safe

Inputs

  • userId · string · Required, Select a user
  • firstName · string · Optional, Updated first name
  • lastName · string · Optional, Updated last name
  • email · string · Optional, Updated email address
  • mobilePhone · string · Optional, Updated mobile phone number
  • customAttributes · object · Optional, JSON object with custom profile attributes
Find User by Email · Read

Look up an Okta user by their email address

find_user_by_email · Risk: low · Retry: safe

Inputs

  • email · string · Required, The user email address
Find Group by Name · Read

Search for an Okta group by name

find_group_by_name · Risk: low · Retry: safe

Inputs

  • groupName · string · Required, The group name to search for
Custom API Call · Read

Make a custom API call to a specific endpoint

custom_api_call · Risk: low · Retry: safe

Inputs

  • url · object · Required
  • method · string · Required
  • headers · object · Optional, Authorization headers are injected automatically from your connection.
  • queryParams · object · Optional, Appended to the URL as ?key=value.
  • body_type · string · Optional
  • body · object · Optional
  • response_is_binary · boolean · Optional, Enable for files like PDFs, images, etc.
  • failsafe · boolean · Optional, On a failed request, output the error instead of failing the step.
  • timeout · number · Optional, Seconds to wait for a response. Empty: up to the flow limit (10 min).
  • followRedirects · boolean · Optional, Follow 3xx redirects instead of returning them as the response.

Triggers

New Event · Webhook

Fires when a new Okta event is generated

Inputs

  • eventTypes · array
  • hookName · string

Setup

Setup

  1. Add the Okta connector to the workflow in the target Flows360 Studio instance.
  2. Create or select the tenant-specific connection required by the connector. Connection secrets remain in the Studio connection boundary and are not copied into CDK documentation.
  3. Provide the connection fields declared by the pinned package:
  • Okta Domain (domain), required.
  • API Token (apiToken), required; stored as a sensitive connection value.
  1. Select the required action or trigger and complete its declared input fields. Required and optional inputs are defined by the exact package schema.
  2. Test the workflow in the appropriate environment before enabling production scheduling or event delivery.

Limitations

Limitations and operational notes

  • This content describes @activepieces/piece-okta@0.2.0; provider behaviour can change independently and should be revalidated when the provider or connector version changes.
  • Only the 10 actions and 1 trigger declared by this pinned package are represented here.
  • Tenant credentials and connection values are not stored in the public connector record.
  • Provider-side permissions, account entitlements, quotas and rate limits remain subject to the connected provider account and are not inferred when the package does not declare them.
  • Deterministic execution evidence is recorded for the pinned artifact, including 1 exercised action entrypoint and 0 exercised trigger entrypoints.

Troubleshooting

Why canu2019t the connector authenticate?

Check the tenant connection in Studio and confirm every required Okta connection field is present. Re-authorise OAuth-based connections if the provider token or consent has expired. Do not place credential values in CDK content or logs.

Why is an action or trigger unavailable?

Confirm that the workflow is using @activepieces/piece-okta@0.2.0 and compare the requested capability with the declared action and trigger list for this version. A capability that is not declared by the pinned package should not be presented as supported.

What should I check after a provider-side change?

Revalidate authentication, required fields, action/trigger behaviour and provider documentation before publishing refreshed connector content or moving a new package version into production.