Access
Create an API Service application with these read scopes:Collection
Application assignments and entitlement collection are bounded by the app
targets selected on the connection. Forge retains native Okta IDs and resolves
users and groups to directory identities when a safe match exists.
Setup
- Create the Okta API Service app, grant the scopes above, and add the public half of the RSA key.
- In Settings → Integrations → Okta, save the tenant domain, client ID, and private JWK.
- Run Validate and confirm each capability reports
healthyor a precise missing-permission state. - Select the Okta applications whose assignments and entitlements should be inventoried.
- Run the first inventory collection and compare record counts with Okta.
Verification
Disabling the connection stops future collection. Remove the public key or
delete the API Service app in Okta to revoke provider-side access.