Skip to content
PlainID
← Back to all integrations
Okta logo

Okta

Use Okta identity context and enrich its tokens to drive fine-grained access decisions.

About PlainID + Okta

The integration between PlainID and Okta enables organizations to apply a continuous Authentication-Authorization process. The PlainID Okta Authorizer will continue the Authentication process carried out by Okta, to provide the full adaptive access the user is entitled for.
The main objective of Okta, as an IdP (Identity provider), is to handle the authentication process, this is mostly done based on well-defined protocols such as OIDC and SAML. The outcome of the process is an authentication token. During the Authentication process, the PlainID Okta Authorizer dynamically calculates and provides a list of claims and groups based on the policies defined within PlainID. These claims and groups will be used to enrich the token-minted Okta. The objective of the token enrichment flow is to dynamically and contextually calculate and provide the list of claims (Authorizations) to Okta, as part of the login process.

Technical Information

The PlainID Okta Authorizer allows to enrich Okta's JWT as part of the login process. This is done by utilizing Okta’s webhook to obtain the relevant claims for the authenticating user from PlainID’s PDP. The Token Enrichment functionality is supported both by the PlainID Cloud-Based PDP, and the Hybrid, customer-hosted PlainID Policy Authorization Agent.

Architectures

  1. User logins to the application.
  2. The app initiates an authentication process (SSO) with Okta (IdP).
  3. As part of the authentication process, Okta sends a request to PlainID Authorizer via a webhook interface to get an enriching token.
  4. The PDP dynamically calculates the access decision, utilizing the Policy Information Point (PIP) to retrieve additional user or asset attributes from various data sources if required. PlainID Authorizer then returns access decisions with authorization claims to enrich the access token granted by Okta.
  5. Okta provides the app with an access token containing the dynamically calculated access decision.

Technology

  • Identity Providers

Capabilities

  • Manage
  • Enforce

Auth Patterns

  • Token Enrichment
  • Policy information point (PIP)

Need help integrating?

Our experts can help you architect the perfect authorization strategy for your stack.

Contact Support

Better Together

Connect Context. Centralize Policy. Enforce Everywhere.