Oktavf.sr

listing.by · home.legend.verified

Manage Okta users, groups, applications, policies and system logs from your assistant using natural language.

state.local.long (state.local.title)listing.badge.runs_with

listing.install

listing.local.explain

uvx okta-mcp-server

listing.local.needs listing.local.note

  • OKTA_ORG_URL Your Okta org URL, e.g. https://your-org.okta.com.
  • OKTA_CLIENT_ID Client ID of the Okta API service app used for sign-in.
  • OKTA_SCOPES Space-separated Okta API scopes to request (tools load by granted scope).

listing.share.h

listing.share.p_local

mcp.tc/i/okta

listing.about

Connects an AI assistant to the Okta Admin Management APIs through Okta's Python SDK. It supports create, read, update and delete operations on users, groups, applications, policies, device assurance policies, brands, themes, custom pages, email templates and domains, and can look up system logs. Destructive actions such as deletes and deactivations ask for confirmation through MCP elicitation.

Runs locally over stdio with uvx okta-mcp-server (Python 3.13+) or in Docker. Set OKTA_ORG_URL, OKTA_CLIENT_ID and OKTA_SCOPES. Sign in with the device authorization flow in a browser, or use a private key JWT with OKTA_PRIVATE_KEY and OKTA_KEY_ID. Tools are registered at startup only for the scopes you grant.

listing.can

  • Create, update and deactivate Okta users
  • Manage groups and group membership
  • Manage applications and policies
  • Manage device assurance policies
  • Customize brands, themes, email templates and custom pages
  • Manage custom and email domains
  • Query system logs such as failed logins
  • Confirmation prompts before destructive operations

listing.tools

listing.notools.oauth

listing.prompts

  • Create a new user and add them to the Engineering group

  • Show me all failed login attempts from the last 24 hours

  • List all applications that haven't been used in the past month

  • Deactivate the user jane.doe@example.com

listing.setup.h

listing.setup.local

Claude Code

  1. Run this in a terminal, in your project folder:
claude mcp add --transport stdio okta --env "OKTA_ORG_URL=<YOUR_OKTA_ORG_URL>" --env "OKTA_CLIENT_ID=<YOUR_OKTA_CLIENT_ID>" --env "OKTA_SCOPES=<YOUR_OKTA_SCOPES>" -- uvx okta-mcp-server
  1. Start Claude Code and type /mcp. okta should show as connected.

Add --scope user to make it available in every project. Replace the placeholders with your own values.

Claude Desktop

  1. Open Settings → Developer → Edit Config. It opens claude_desktop_config.json. Add:
claude_desktop_config.json
{
  "mcpServers": {
    "okta": {
      "command": "uvx",
      "args": [
        "okta-mcp-server"
      ],
      "env": {
        "OKTA_ORG_URL": "<YOUR_OKTA_ORG_URL>",
        "OKTA_CLIENT_ID": "<YOUR_OKTA_CLIENT_ID>",
        "OKTA_SCOPES": "<YOUR_OKTA_SCOPES>"
      }
    }
  }
}
  1. Save the file and restart Claude Desktop. Replace the placeholders with your own values.

Needs uv (Python) on your computer. The file lives in ~/Library/Application Support/Claude/ on macOS and %APPDATA%\Claude\ on Windows.

Cursor

Or add it by hand to ~/.cursor/mcp.json (all projects) or .cursor/mcp.json (this project):

mcp.json
{
  "mcpServers": {
    "okta": {
      "command": "uvx",
      "args": [
        "okta-mcp-server"
      ],
      "env": {
        "OKTA_ORG_URL": "<YOUR_OKTA_ORG_URL>",
        "OKTA_CLIENT_ID": "<YOUR_OKTA_CLIENT_ID>",
        "OKTA_SCOPES": "<YOUR_OKTA_SCOPES>"
      }
    }
  }
}

Needs uv (Python) on your computer. Replace the placeholders with your own values.

VS Code

Or from a terminal:

code --add-mcp '{"name":"okta","type":"stdio","command":"uvx","args":["okta-mcp-server"],"env":{"OKTA_ORG_URL":"<YOUR_OKTA_ORG_URL>","OKTA_CLIENT_ID":"<YOUR_OKTA_CLIENT_ID>","OKTA_SCOPES":"<YOUR_OKTA_SCOPES>"}}'

Or commit it to the repo in .vscode/mcp.json:

.vscode/mcp.json
{
  "servers": {
    "okta": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "okta-mcp-server"
      ],
      "env": {
        "OKTA_ORG_URL": "<YOUR_OKTA_ORG_URL>",
        "OKTA_CLIENT_ID": "<YOUR_OKTA_CLIENT_ID>",
        "OKTA_SCOPES": "<YOUR_OKTA_SCOPES>"
      }
    }
  }
}

Needs uv (Python) on your computer.

Devin Desktop

  1. Add it to ~/.config/devin/mcp_config.json (macOS and Linux) or %APPDATA%\devin\mcp_config.json (Windows):
mcp_config.json
{
  "mcpServers": {
    "okta": {
      "command": "uvx",
      "args": [
        "okta-mcp-server"
      ],
      "env": {
        "OKTA_ORG_URL": "<YOUR_OKTA_ORG_URL>",
        "OKTA_CLIENT_ID": "<YOUR_OKTA_CLIENT_ID>",
        "OKTA_SCOPES": "<YOUR_OKTA_SCOPES>"
      }
    }
  }
}
  1. Refresh the MCP server list in Cascade. Replace the placeholders with your own values.

Devin Desktop is the new name for Windsurf.

Codex

codex mcp add okta --env "OKTA_ORG_URL=<YOUR_OKTA_ORG_URL>" --env "OKTA_CLIENT_ID=<YOUR_OKTA_CLIENT_ID>" --env "OKTA_SCOPES=<YOUR_OKTA_SCOPES>" -- uvx okta-mcp-server

Or edit ~/.codex/config.toml directly:

config.toml
[mcp_servers.okta]
command = "uvx"
args = ["okta-mcp-server"]
env = { OKTA_ORG_URL = "<YOUR_OKTA_ORG_URL>", OKTA_CLIENT_ID = "<YOUR_OKTA_CLIENT_ID>", OKTA_SCOPES = "<YOUR_OKTA_SCOPES>" }

Needs uv (Python) on your computer. Replace the placeholders with your own values.

Gemini CLI

gemini mcp add -e "OKTA_ORG_URL=<YOUR_OKTA_ORG_URL>" -e "OKTA_CLIENT_ID=<YOUR_OKTA_CLIENT_ID>" -e "OKTA_SCOPES=<YOUR_OKTA_SCOPES>" okta uvx okta-mcp-server

This adds it to the current project. Add -s user to use it everywhere.

Any client

Most clients that start local servers accept this shape:

{
  "mcpServers": {
    "okta": {
      "command": "uvx",
      "args": [
        "okta-mcp-server"
      ],
      "env": {
        "OKTA_ORG_URL": "<YOUR_OKTA_ORG_URL>",
        "OKTA_CLIENT_ID": "<YOUR_OKTA_CLIENT_ID>",
        "OKTA_SCOPES": "<YOUR_OKTA_SCOPES>"
      }
    }
  }
}

Zed puts servers under context_servers in its settings, with the same command, args and env fields.

Needs uv (Python) on your computer. Replace the placeholders with your own values.

listing.faq

Can I paste mcp.tc/i/okta into my MCP client?

No. Okta runs on your own computer, started by your client, so it has no web address to connect to. The quick link is the page to share; the install command is uvx okta-mcp-server.

Does Okta need an API key?

No. It reads OKTA_ORG_URL, OKTA_CLIENT_ID and OKTA_SCOPES from its environment; the setup steps show where to set them.

Is Okta a remote or a local server?

Local. Your client starts it as a process on your computer with uvx okta-mcp-server, which needs uv (Python).

What can Okta do?

You can create, update and deactivate Okta users, manage groups and group membership and manage applications and policies.

Which clients can use it?

Any client that starts local servers: Claude Code, Claude Desktop, Cursor, VS Code, Devin Desktop, Codex, Gemini CLI, Zed and others. claude.ai and ChatGPT only connect to remote servers.

Who wrote this page?

mcp.tc's robot read Okta's public metadata (its package and repository pages), and an AI model drafted the text from it. A person reviews anything the checks can't confirm. The text can still be wrong, so if you spot a mistake, use Report this listing on this page.

listing.em.h

listing.em.lead_local listing.em.how

listing.em.badge

em.prev_lightem.prev_dark
Markdown
[![Okta on mcp.tc](https://mcp.tc/i/okta/badge.svg)](https://mcp.tc/i/okta)
HTML
<a href="https://mcp.tc/i/okta"><img src="https://mcp.tc/i/okta/badge.svg" alt="Okta on mcp.tc" height="20"></a>

listing.em.badge_note

listing.em.widget

HTML
<script src="https://mcp.tc/w/okta.js" async></script>

listing.em.widget_note

iframe

HTML
<iframe src="https://mcp.tc/embed/okta" title="Okta on mcp.tc" width="420" height="200" loading="lazy" allow="clipboard-write" style="border:0;border-radius:8px;max-width:100%"></iframe>

listing.em.iframe_note

JSON

listing.em.json_local

https://mcp.tc/i/okta.json

listing.em.fields

listing.disclaimer_checked