Manage users, groups, apps, and MFA in Okta
Okta is a Securityintegration for Sim, the AI workspace where teams build and deploy AI agents. Sim's Okta integration provides 44 Okta tools that AI agents can use inside Sim's visual workflow builder. Okta connects with an API key. Free to start at sim.ai.
Last updated
Integrate Okta identity management into your workflow. Manage users, groups, and group rules. Run service desk actions like resetting MFA factors and clearing sessions. Review and change application assignments and admin roles. Query the System Log to audit sign-ins and admin changes.
Sign up at sim.ai in seconds. No credit card required. Your workspace is ready immediately.
Open your workspace, drag an Okta block onto the workflow builder, and paste in your Okta API key.
Pick the tool you need, wire in an AI agent for reasoning or data transformation, and run. Your Okta automation is live.
Ready-to-use templates featuring Okta. Click any to build it instantly.
44 Okta tools available in Sim
List Users
List users in your Okta organization with optional search and filtering. Users with a DEPROVISIONED status are omitted unless a search or filter expression selects them.
Get User
Get a specific user by ID or login from your Okta organization
Create User
Create a new user in your Okta organization
Update User
Update a user profile in your Okta organization
Activate User
Activate a user in your Okta organization. Can only be performed on users with STAGED or DEPROVISIONED status. Optionally sends an activation email.
Deactivate User
Deactivate a user in your Okta organization. This transitions the user to DEPROVISIONED status.
Suspend User
Suspend a user in your Okta organization. Only users with ACTIVE status can be suspended. Suspended users cannot log in but retain group and app assignments.
Unsuspend User
Unsuspend a previously suspended user in your Okta organization. Returns the user to ACTIVE status.
Reset Password
Generate a one-time token to reset a user password. Can email the reset link to the user or return it directly. Transitions the user to RECOVERY status.
Delete User
Permanently delete a user from your Okta organization. Can only be performed on DEPROVISIONED users. If the user is active, this will first deactivate them and a second call is needed to delete.
List Groups
List all groups in your Okta organization with optional search and filtering
Get Group
Get a specific group by ID from your Okta organization
Create Group
Create a new group in your Okta organization
Update Group
Update a group profile in your Okta organization. Only groups of OKTA_GROUP type can be updated. Fields left blank keep their stored value.
Delete Group
Delete a group from your Okta organization. Groups of OKTA_GROUP or APP_GROUP type can be removed.
Add User to Group
Add a user to a group in your Okta organization
Remove User from Group
Remove a user from a group in your Okta organization
List Group Members
List all members of a specific group in your Okta organization
List Group Rules
List the group rules in your Okta organization. Each rule assigns users to groups automatically based on an expression over their profile, so this shows how group membership is being driven.
Get Group Rule
Retrieve a single Okta group rule by ID, including the expression that decides which users it matches and the groups those users are assigned to.
Create Group Rule
Create a group rule that automatically assigns users matching an Okta expression to one or more groups. New rules are created INACTIVE, so run Activate Group Rule afterwards to start applying it.
Activate Group Rule
Activate a group rule so Okta starts applying it, assigning every matching user to the target groups.
Deactivate Group Rule
Deactivate a group rule so Okta stops applying it. Existing memberships the rule created are left in place. A rule must be INACTIVE before it can be edited.
Delete Group Rule
Permanently delete a group rule. Destructive and irreversible. Optionally also removes the users that this rule had assigned from those groups, which revokes any access those groups grant.
List Factors
List the MFA factors a user has enrolled, with each factor type, provider, and enrollment status. Use this before resetting a factor to confirm which one to target.
Get Factor
Retrieve a single enrolled MFA factor for a user, including its type, provider, enrollment status, and factor-specific profile.
Enroll Factor
Enroll an MFA factor for a user. The profile fields required depend on the factor type: a phone number for sms and call, an email address for email, and a question and answer for question. Factors that enroll from the user device, such as webauthn and push, need no profile fields.
Reset Factor
Unenroll one specific MFA factor for a user so they can re-enroll it. Destructive and irreversible: the existing enrollment is removed. Unenrolling a push or signed_nonce factor also unenrolls the related Okta Verify factors. Factors cannot be unenrolled from a deactivated user.
Reset All Factors
Reset every MFA factor for a user, returning all enrollments to the unenrolled state. Destructive and irreversible: the user must re-enroll each factor before they can complete MFA again. The user status stays ACTIVE.
Clear User Sessions
Revoke every active Okta session for a user, signing them out of all devices immediately. Destructive and irreversible: the user must sign in again. Optionally also revokes their OAuth and OpenID Connect tokens, and clears remembered factors.
Get Session
Retrieve an Okta session by ID, including who it belongs to, when it expires, and which authentication methods were used to establish it.
Revoke Session
Revoke a single Okta session by ID, ending that sign-in immediately. Destructive and irreversible: the affected user must sign in again on that device.
List Applications
List the applications configured in your Okta organization, with optional name search, filtering, and cursor pagination.
Get Application
Retrieve a single Okta application by ID, including its sign-on mode, status, enabled provisioning features, and configuration objects.
List Application Users
List the users assigned to an Okta application, including how each assignment was made and its provisioning sync state. Use this to audit who has access to an app.
Assign User to Application
Assign a user to an Okta application, granting them access to it. Applications that require credentials also need the username the user signs in with.
Remove User from Application
Unassign a user from an Okta application, revoking their access. Destructive and irreversible: the app profile for that user is permanently removed, and if provisioning is enabled the downstream account is deactivated.
List Application Groups
List the groups assigned to an Okta application. Every member of an assigned group inherits access to the app, so this is the starting point for an app access review.
Assign Group to Application
Assign a group to an Okta application so every member of the group inherits access to it.
Remove Group from Application
Unassign a group from an Okta application. Destructive: every member who had access only through this group loses access to the app.
List User Roles
List the administrator roles assigned to a user. Returns both standard roles and custom role bindings, so you can review who holds privileged access.
Assign User Role
Grant a user an administrator role. Use a standard role type such as USER_ADMIN or HELP_DESK_ADMIN, or CUSTOM together with a custom role ID and a resource set ID. This grants privileged access, so confirm the role is the least privilege that fits.
Remove User Role
Revoke an administrator role from a user. Destructive: the user immediately loses the admin permissions that role granted. Takes the role assignment ID, not the role type, which List User Roles returns as the role id field.
Get System Log Events
Query the Okta System Log for sign-ins, admin changes, and security events. Supports a time window, SCIM filter expressions, keyword search, and cursor pagination for audit and investigation workflows.
Sim's Okta integration adds 44 Okta tools to the AI agents you build in Sim's visual workflow builder — you build it all visually. Manage users, groups, apps, and MFA in Okta. Teams often pair Okta with Rippling and Linear in the same agent.

Build your first AI agent with Okta in minutes. Connect to every tool your team uses. Free to start, no credit card required.