Okta Mcp Server
About
The Okta MCP Server is a groundbreaking tool built by the team at Fctr that enables AI models to interact directly with your Okta environment using the Model Context Protocol (MCP). Built specifically for IAM engineers, security teams, and Okta administrators, it implements the M
Details
- License
- MIT
Explore
Have an idea or suggestion? Open a feature request on GitHub!
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
Okta Mcp ServerCommand (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
✅ Python 3.8+ installed on your machine
✅ Okta tenant with appropriate API access
✅ An MCP-compatible AI client (Claude Desktop, Microsoft Copilot Studio, etc.)
> ⚠️ Important Model Compatibility Note:
> Not all AI models work with this MCP server. Testing has only been performed with:
> - GPT-4.0
> - Claude 3.7 Sonnet
> - Google-2.5-pro
>
> You must use latest model versions that explicitly support tool calling/function calling capabilities. Older models or models without tool calling support will not be able to interact with the Okta MCP Server.
python -m venv venv
source venv/bin/activate # On Windows use: venv\Scripts\activate
pip install -r requirements.txt
> ⚠️ NOTICE: If you clone this repository anew or pull updates, always make sure to re-run pip install -r requirements.txt to ensure all dependencies are up-to-date.
Create a config file with your Okta settings:
> 📝 Note: Standalone CLI clients have been archived. For MCP host integration (Claude Desktop, VS Code, etc.), use the server directly with the JSON configuration below.
npm install -g @anthropic/mcp-remote
Claude Desktop Configuration:
{
"mcpServers": {
"okta-mcp-server": {
"command": "npx",
"args": [
"mcp-remote",
"http://localhost:3000/mcp"
],
"env": {
"OKTA_CLIENT_ORGURL": "https://dev-1606.okta.com",
"OKTA_API_TOKEN": "your_actual_api_token"
}
}
}
}
🚨 CRITICAL SECURITY WARNINGS:
- NEVER use in production environments
- NEVER expose the HTTP port (3000) to public networks
- ANYONE with network access can control your Okta tenant
- No authentication or authorization protection
- All Okta operations are exposed without restrictions
- Use only in isolated, secure development environments
- Consider this approach only if STDIO transport is absolutely not feasible
When might you need this approach:
- Testing MCP integrations that require HTTP transport
- Specific client applications that can't use STDIO
- Development scenarios requiring HTTP debugging
- NEVER for production or shared environments
The Okta MCP Server provides Docker images for all transport types, offering containerized deployment options.
STDIO Transport (Recommended):
For Claude Desktop or other MCP clients, configure to use the Docker container:
{
"mcpServers": {
"okta-mcp-server": {
"command": "docker",
"args": [
"run", "-i", "--rm",
"-e", "OKTA_CLIENT_ORGURL",
"-e", "OKTA_API_TOKEN",
"fctrid/okta-mcp-server:stdio"
],
"env": {
"OKTA_CLIENT_ORGURL": "https://your-org.okta.com",
"OKTA_API_TOKEN": "your_api_token"
}
}
}
}
Streamable HTTP Transport (Current Standard):
SSE Transport (Deprecated - Not Recommended):
Building Images Locally:
```bash
okta_list_users_make_request
okta_create_user_make_request
okta_get_user_make_request
okta_update_user_make_request
okta_delete_user_make_request
okta_list_groups_make_request
okta_create_group_make_request
okta_assign_user_to_group_make_request
okta_list_applications_make_request
okta_assign_user_to_application_make_request
okta_assign_group_to_application_make_request
okta_delete_application_make_request
okta_deactivate_application_make_request
This release introduces powerful special tools that revolutionize daily Okta administration tasks:
- 🎯 Comprehensive Access Analysis: Helps answer the most frequent question okta admns face. Can user X access app Y?
- 🛡️ Advanced Login Risk Assessment: Behavioral analysis with VPN/Tor detection and geographic impossibility checks which can help with suspicious reporting emails.
💡 Real-World Example - Access Analysis:
❓ Question: "Can user [email protected] access the application Salesforce?"
🤖 AI Response (30 seconds): "User John Smith can access Salesforce because:
1) User is ACTIVE ✅
2) User is assigned via group 'Sales Team' ✅,
3) Policy allows access with 2FA from corporate network or requires PUSH factor from external locations - user has PUSH enrolled ✅"
⏱️ Manual Process: Navigate Users → Find John → Check Status → Check App
Assignments → Check Group Memberships → Check Salesforce Assignments →
Review Access Policies → Check MFA Factors → Correlate Network Rules (10-15 min)
💡 Real-World Example - Login Risk Assessment:
❓ Question: "Is [email protected]'s recent login activity suspicious?"
🤖 AI Response (30 seconds): "LOW RISK - Dan exhibits excellent login
security patterns: consistent geographic area, same residential ISP,
stable device fingerprints, normal browser patterns, zero VPN/proxy
usage, all Okta risk scores LOW ✅"
⏱️ Manual Process: System Logs → Filter User → Check Locations → Review
IP Addresses → Cross-reference Network Zones → Analyze Device Patterns →
Check Geographic Impossibility → Review Behavioral Flags (15+ min)
- 📝 Complete Rewrite: All tools rewritten with better annotations and descriptions for AI understanding
- 🛡️ Improved Validation: Enhanced error handling and input validation across all operations
The Okta MCP Server currently provides the following tools:
Access Analysis & Troubleshooting
- analyze_user_app_access - Complete user application access evaluation with policy analysis (replaces 10-15 minutes of manual Okta Admin Console navigation)
Security & Risk Assessment
- analyze_login_risk - Comprehensive login behavior analysis with VPN/Tor detection and geographic impossibility checks (answers "Is this user compromised?" instantly)
> ⚡ Why These Matter: The two most common questions Okta admins face daily are "Why can't user X access application Y?" and "Is this login activity suspicious?". These special tools instantly provide comprehensive answers that would otherwise require extensive manual investigation across multiple Okta admin screens, policy reviews, and log analysis - transforming 15+ minute investigations into 30-second AI-powered insights.
User Management
- list_okta_users - Retrieve users with filtering, search, and pagination options
- get_okta_user - Get detailed information about a specific user by ID or login
- list_okta_user_groups - List all groups that a specific user belongs to
- list_okta_user_applications - List all application links (assigned applications) for a specific user
- list_okta_user_factors - List all authentication factors enrolled for a specific user
Group Operations
- list_okta_groups - Retrieve groups with filtering, search, and pagination options
- get_okta_group - Get detailed information about a specific group
- list_okta_group_members - List all members of a specific group
- list_okta_assigned_applications_for_group - List all applications assigned to a specific group
Application Management
- list_okta_applications - Retrieve applications with filtering, search, and pagination options
- list_okta_application_users - List all users assigned to a specific application
- list_okta_application_group_assignments - List all groups assigned to a specific application
Policy & Network Management
- list_okta_policy_rules - List all rules for a specific policy with detailed conditions and actions
- get_okta_policy_rule - Get detailed information about a specific policy rule
- list_okta_network_zones - List all network zones with IP ranges and configuration details
System Log Events
- get_okta_event_logs - Retrieve Okta system log events with time-based filtering and search options
Date & Time Utilities
- get_current_time - Get current UTC time in ISO 8601 format
- parse_relative_time - Convert natural language time expressions to ISO 8601 format
> Additional tools for applications, factors, policies, and more advanced operations are on the roadmap and will be added in future releases.
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"okta mcp server": {
"okta-mcp-server": {
"command": "python",
"args": [
"-m",
"venv",
"venv"
]
}
}
}
}
McpServers
{
"okta-mcp-server": {
"command": "python",
"args": [
"-m",
"venv",
"venv"
]
}
}
<div align="center">
<a href="https://fctr.io">
</a>
</div>
<div align="center">
<h2>Okta MCP Server (v0.1.1-BETA)</h2>
</div>
<div align="center">
<h3>🔥 ALERT!!! A brand new re-built MCP Server now available</h3>
<p><strong>A complete rewrite built on Anthropic's new MCP architecture pattern with dual-mode operation, context-engineering, enhanced security sandbox, and production-ready Docker support.</strong></p>
<p><a href="https://github.com/fctr-id/fctr-okta-mcp-server"><strong>→ Explore TAKO MCP Server</strong></a></p>
</div>
<div align="center">
The Okta MCP Server is a groundbreaking tool that enables AI models to interact directly with your Okta environment using the Model Context Protocol (MCP). Built specifically for IAM engineers, security teams, and Okta administrators, it implements the MCP specification to transform how AI assistants can help manage and analyze Okta resources.
</div>
<div align= "center" >
<p ><a href="https://github.com/fctr-id/okta-mcp-server">View on GitHub</a> | <a href="https://modelcontextprotocol.io/introduction">Learn about MCP</a> | <a href="https://github.com/fctr-id/okta-ai-agent">Okta AI Agent</a></p>
</div>
<div align="center">
<h3>Quick Demo</h3>
<p >

</p>
</div>
🎉 What's New in v0.1.1-BETA - Enterprise-Grade Special Tools!
This release introduces powerful special tools that revolutionize daily Okta administration tasks:
🔥 NEW: Special Tools - Game Changers for Okta Admins
- 🎯 Comprehensive Access Analysis: Helps answer the most frequent question okta admns face. Can user X access app Y? - 🛡️ Advanced Login Risk Assessment: Behavioral analysis with VPN/Tor detection and geographic impossibility checks which can help with suspicious reporting emails.💡 Real-World Example - Access Analysis:
❓ Question: "Can user [email protected] access the application Salesforce?"
🤖 AI Response (30 seconds): "User John Smith can access Salesforce because:
1) User is ACTIVE ✅
2) User is assigned via group 'Sales Team' ✅,
3) Policy allows access with 2FA from corporate network or requires PUSH factor from external locations - user has PUSH enrolled ✅"
⏱️ Manual Process: Navigate Users → Find John → Check Status → Check App
Assignments → Check Group Memberships → Check Salesforce Assignments →
Review Access Policies → Check MFA Factors → Correlate Network Rules (10-15 min)
💡 Real-World Example - Login Risk Assessment:
❓ Question: "Is [email protected]'s recent login activity suspicious?"
🤖 AI Response (30 seconds): "LOW RISK - Dan exhibits excellent login
security patterns: consistent geographic area, same residential ISP,
stable device fingerprints, normal browser patterns, zero VPN/proxy
usage, all Okta risk scores LOW ✅"
⏱️ Manual Process: System Logs → Filter User → Check Locations → Review
IP Addresses → Cross-reference Network Zones → Analyze Device Patterns →
Check Geographic Impossibility → Review Behavioral Flags (15+ min)
🏗️ Core Architecture
- 🚀 FastMCP 2.0: Migrated from legacy MCP package to FastMCP 2.0 for cutting-edge protocol features - 🧹 Cleaner Code: Removedtool_registry.py dependency for simpler, more maintainable codebase
- ⚡ Better Performance: Modern async patterns and optimized request handling
🛠️ Enhanced Tools
- 📝 Complete Rewrite: All tools rewritten with better annotations and descriptions for AI understanding - 🛡️ Improved Validation: Enhanced error handling and input validation across all operations🔐 Advanced Security
- 🎫 Bearer Tokens: Full JWT bearer token support withjwks_uri validation
- 🏢 Enterprise Auth: Support for enterprise authentication flows and scope-based access
🚀 Future-Ready
- 🔌 Middleware Ready: Extensible middleware system for custom processing - 📡 Protocol Evolution: Access to latest MCP features as they're developed and standardized> 📝 Note: CLI clients and AI sampling features have been moved to _Archived/ folder due to pydantic-ai dependency conflicts (security vulnerability ). See _Archived/README.md for details.
📋 Table of Contents
- 🎉 What's New in v0.1.1-BETA - Enterprise-Grade Special Tools!
- 🏗️ Core Architecture
- 🛠️ Enhanced Tools
- 🔐 Advanced Security
- 🚀 Future-Ready
- 📋 Table of Contents
- 🔍 What is the Model Context Protocol?
- ⚠️ IMPORTANT: Security \& Limitations
- 🔄 Data Flow \& Privacy
- 📊 Context Window Limitations
- 🚨 HTTP Transport Security Warning
- 🛠️ Available Tools
- 🚀 Quick Start
- Prerequisites
- 🧠 Supported AI Providers
- Currently Supported Providers:
- Installation
- Configuration \& Usage
- Supported Transports and Launching
- 1. Standard I/O (STDIO) - Recommended
- 2. Streamable HTTP Transport - Modern \& Current Standard
- 3. Remote HTTP Access - High Risk Advanced Use Only
- 4. Server-Sent Events (SSE) - Deprecated
- 5. Docker Deployment
- Running Docker Containers
- ⚠️ Good to Know
- Beta Release 🧪
- Security First 🛡️
- Current Limitations 🔍
- 🗺️ Roadmap
- 🆘 Need Help?
- 💡 Feature Requests \& Ideas
- 👥 Contributors
- ⚖️ Legal Stuff
🔍 What is the Model Context Protocol?
<div align="left">
<p>The Model Context Protocol (MCP) is an open standard that enables AI models to interact with external tools and services in a structured, secure way. It provides a consistent interface for AI systems to discover and use capabilities exposed by servers, allowing AI assistants to extend their functionality beyond their training data.</p>
<p>Think of MCP as the "USB-C of AI integration" - just as USB-C provides a universal standard that allows various devices to connect and communicate regardless of manufacturer, MCP creates a standardized way for AI models to discover and interact with different services without custom integration for each one. This "plug-and-play" approach means developers can build tools once and have them work across multiple AI assistants, while users benefit from seamless integration without worrying about compatibility issues.</p>
<p><strong>Example:</strong> "Find all locked users in our Okta tenant, and create a spreadsheet in our IT Operations folder on Google Drive with their names, email addresses, and last login dates." <em>The AI uses Okta MCP Server to query locked users, then passes this data to Google Drive MCP Server to create the spreadsheet - all without custom coding.</em></p>
<div align="left">
<a href="https://modelcontextprotocol.io/introduction">

</a>
</div>
</div>
⚠️ IMPORTANT: Security & Limitations
Please read this section carefully before using Okta MCP Server.
🔄 Data Flow & Privacy
…
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



