Okta
Okta connects through an API Services app you create in your Okta org. Governax signs in to that app with a key unique to your entity, so no secret of yours is ever pasted into Governax. It then registers an Event Hook in your Okta org for you, so there is no webhook configuration to do by hand.
Before you start#
Creating the Okta app#
Open Integrations → Okta for the entity in Governax and keep it open: the connect page shows these same steps with this entity's key filled in, and you paste the client ID back there.
Create an API Services app
Applications → Applications → Create App Integration. Choose API Services, click Next, name it
Governax, and save.Add this entity's key to the app
Governax app → General → Client Credentials → Edit. Set Client authentication to Public key / Private key. Under Public keys choose Save keys in Okta, click Add key, paste the key from the Governax connect page, then Done and Save.
The key is unique to this entity, so the app can only ever be connected to it. Leave "Require Demonstrating Proof of Possession (DPoP)" as it is: Governax works either way.
Grant the scopes
Governax app → Okta API Scopes. Click Grant next to
okta.eventHooks.manage(create, verify, health-check and remove the one Event Hook) andokta.users.read(the snapshot of active users at connect), and nothing else. Only a Super Admin can grant scopes.Assign an admin role
Governax app → Admin roles → Edit assignments. Assign Super Administrator, or a custom admin role that can manage Event Hooks and view users. Scopes alone are not enough: Okta also checks the app's role on every call. Custom-role Event Hook permissions are an Okta Early Access feature (2025.12), so check your org has it before relying on it.
Copy the client ID
Governax app → General → Client Credentials. Okta client IDs start with
0oa.
Connecting#
Enter the domain and the client ID
The domain is your org's domain, for example
your-org.okta.com, or your custom domain. The Admin Console address (ending-admin.okta.com) also works: Governax converts it to the org domain, where OAuth lives.Governax verifies and configures
Governax signs in to your app, creates an Event Hook in your Okta org, and Okta verifies that hook by calling it. All of this happens inside the one request, and nothing is saved until it works, so a setup mistake is reported to you, naming the step to fix. The initial user snapshot starts once the connection is saved and runs in the background.
The Event Hook Governax creates#
You will see a new Event Hook in your Okta admin console named after your entity. It points at a URL unique to this connection:
https://<governax>/api/webhooks/okta/<connection-id>Each connection has its own URL and its own authorisation secret, sent by Okta as a header on every delivery. Because the secret is derived per connection, a value captured from one customer cannot be replayed against another. Governax verifies it on every delivery before doing anything with the payload.
Events captured#
Governax subscribes to 24 Okta System Log event types, producing these ledger events:
Not captured: routine authentication and session events. Okta's System Log records every sign-in; recording those in a governance ledger would bury the access changes that matter.
Okta is the connector with the most complete attribution: its events carry login identifiers that are normally email addresses, so both actor and subject are usually populated.
Disconnecting#
Disconnecting deactivates and deletes the Event Hook in your Okta org through your app, then marks the connection dead. Nothing is left behind in Okta except the app itself, which you can deactivate or delete if you are revoking access properly.
Troubleshooting#
Governax checks each connection every six hours. A problem shows as "Needs attention" on the Integrations page, with the reason on the Okta page and a Reconnect button that fixes it in place, without stopping events.
General connector behaviour is covered in Connecting a tool.