Who Okta is
Okta is an identity company founded in 2009 and based in San Francisco. It sells two platforms: the Okta Platform, for a company's employees, contractors and partners, and the Auth0 Platform, for the apps a company's customers use.
Companies use Okta as the one place where staff accounts live and sign in to their work apps, under the policies their IT team sets. That is why it is one of the identity providers our authentication module connects to, and a direct way to put your existing staff accounts in front of the backoffice.
What it does in your platform
Authentication
Sits behind the module as the identity provider, over OpenID Connect or SAML, when your company already runs Okta. Okta checks who the person is; the module keeps their sessions, trusted devices and the second factor on payments.
Admin backoffice
Signs your staff in to the backoffice with the Okta account they use for every other work app. The groups you manage in Okta arrive with the sign-in and decide each person's role, so access follows your directory.
How the connection works
The backoffice and the module are registered as apps in your Okta org and talk to it over OpenID Connect or SAML. Okta's event hooks, authenticated with a shared secret, tell the platform when an account changes.
An agent opens the backoffice
The backoffice sends them to your Okta sign-in page, where the policies your IT team already set apply.
Okta signs them in
Okta returns a signed token, or a SAML assertion, carrying the agent's identity and their Okta groups.
Groups become roles
The backoffice maps each Okta group to a role, so the agent sees the screens and actions their team needs, down to single fields, and nothing else.
Every action is logged
What they do in the backoffice is recorded with who did it, when and from where, in a log that cannot be edited.
Someone leaves
IT deactivates them in Okta and their next sign-in is refused. Okta's event hook tells the platform at once, so their open sessions can be signed out too.
Next to other providers
Okta can sign in your staff while customers use something else: the module's own passkey sign-in, Auth0, which is Okta's customer identity platform, or AWS Cognito. The backoffice and the customer apps each keep their own provider, and roles, sessions and the audit log stay on the platform.
Because the module speaks OpenID Connect and SAML rather than Okta's own interfaces, moving staff to another identity provider later is a configuration change, not a new release, and the audit log keeps every past action.
When Okta fits best
A strong fit when
- Your company already runs Okta for its staff and work apps.
- You want staff access managed in one directory, with joiners and leavers handled there and nowhere else.
- Contractors or partners need backoffice access under the same policies as your employees.
Also worth a look
- Microsoft Entra ID or Google Workspace, when your staff accounts already live there.
- Auth0, Okta's customer identity platform, when the job is signing in customers rather than staff.
How we get you live
The contract
We help you get your Okta account and contract in place, or connect to the Okta org your IT team already runs.
The apps and groups
We register the backoffice and the customer apps in Okta, and map the Okta groups that become backoffice roles.
The keys
Client secrets and the event hook secret go into your platform's secrets and nowhere else.
A full test run
We test sign-in, role mapping and a deactivated account end to end with test users before your team switches over.
