# Okta MCP server

> Manage Okta users, groups, applications, policies and system logs from your assistant using natural language.

- Listing: https://mcp.tc/i/okta
- Connect: this is a local (stdio) server; install it on your machine (see Install). The listing link is a page, not an MCP endpoint.
- Type: local (stdio)
- Auth: OAuth sign-in
- Category: [Security & Compliance](https://mcp.tc/c/security)
- Vendor: Okta
- Verified: yes, mcp.tc checked that this is the official server (https://mcp.tc/verify). It says who runs the server, not that it is safe.
- Docs: <https://github.com/okta/okta-mcp-server>
- Repository: <https://github.com/okta/okta-mcp-server>
- Package: pypi `okta-mcp-server`

## About

Connects an AI assistant to the Okta Admin Management APIs through Okta's Python SDK. It supports create, read, update and delete operations on users, groups, applications, policies, device assurance policies, brands, themes, custom pages, email templates and domains, and can look up system logs. Destructive actions such as deletes and deactivations ask for confirmation through MCP elicitation.

Runs locally over stdio with uvx okta-mcp-server (Python 3.13+) or in Docker. Set OKTA\_ORG\_URL, OKTA\_CLIENT\_ID and OKTA\_SCOPES. Sign in with the device authorization flow in a browser, or use a private key JWT with OKTA\_PRIVATE\_KEY and OKTA\_KEY\_ID. Tools are registered at startup only for the scopes you grant.

## What it can do

- Create, update and deactivate Okta users
- Manage groups and group membership
- Manage applications and policies
- Manage device assurance policies
- Customize brands, themes, email templates and custom pages
- Manage custom and email domains
- Query system logs such as failed logins
- Confirmation prompts before destructive operations

## Example prompts

- "Create a new user and add them to the Engineering group"
- "Show me all failed login attempts from the last 24 hours"
- "List all applications that haven't been used in the past month"
- "Deactivate the user jane.doe@example.com"

## Install

### Claude Code

1. Run this in a terminal, in your project folder:

```bash
claude mcp add --transport stdio okta --env "OKTA_ORG_URL=<YOUR_OKTA_ORG_URL>" --env "OKTA_CLIENT_ID=<YOUR_OKTA_CLIENT_ID>" --env "OKTA_SCOPES=<YOUR_OKTA_SCOPES>" -- uvx okta-mcp-server
```

2. Start Claude Code and type `/mcp`. **okta** should show as connected.

Add `--scope user` to make it available in every project. Replace the placeholders with your own values.

### Claude Desktop

1. Open **Settings → Developer → Edit Config**. It opens `claude_desktop_config.json`. Add:

`claude_desktop_config.json`:

```json
{
  "mcpServers": {
    "okta": {
      "command": "uvx",
      "args": [
        "okta-mcp-server"
      ],
      "env": {
        "OKTA_ORG_URL": "<YOUR_OKTA_ORG_URL>",
        "OKTA_CLIENT_ID": "<YOUR_OKTA_CLIENT_ID>",
        "OKTA_SCOPES": "<YOUR_OKTA_SCOPES>"
      }
    }
  }
}
```

2. Save the file and restart Claude Desktop. Replace the placeholders with your own values.

Needs uv (Python) on your computer. The file lives in `~/Library/Application Support/Claude/` on macOS and `%APPDATA%\Claude\` on Windows.

### Cursor

[Add to Cursor](<https://cursor.com/install-mcp?name=okta&config=eyJjb21tYW5kIjoidXZ4IiwiYXJncyI6WyJva3RhLW1jcC1zZXJ2ZXIiXSwiZW52Ijp7Ik9LVEFfT1JHX1VSTCI6IjxZT1VSX09LVEFfT1JHX1VSTD4iLCJPS1RBX0NMSUVOVF9JRCI6IjxZT1VSX09LVEFfQ0xJRU5UX0lEPiIsIk9LVEFfU0NPUEVTIjoiPFlPVVJfT0tUQV9TQ09QRVM%2BIn19>) (opens Cursor)

Or add it by hand to `~/.cursor/mcp.json` (all projects) or `.cursor/mcp.json` (this project):

`mcp.json`:

```json
{
  "mcpServers": {
    "okta": {
      "command": "uvx",
      "args": [
        "okta-mcp-server"
      ],
      "env": {
        "OKTA_ORG_URL": "<YOUR_OKTA_ORG_URL>",
        "OKTA_CLIENT_ID": "<YOUR_OKTA_CLIENT_ID>",
        "OKTA_SCOPES": "<YOUR_OKTA_SCOPES>"
      }
    }
  }
}
```

Needs uv (Python) on your computer. Replace the placeholders with your own values.

### VS Code

[Install in VS Code](<https://vscode.dev/redirect/mcp/install?name=okta&config=%7B%22type%22%3A%22stdio%22%2C%22command%22%3A%22uvx%22%2C%22args%22%3A%5B%22okta-mcp-server%22%5D%2C%22env%22%3A%7B%22OKTA_ORG_URL%22%3A%22%3CYOUR_OKTA_ORG_URL%3E%22%2C%22OKTA_CLIENT_ID%22%3A%22%3CYOUR_OKTA_CLIENT_ID%3E%22%2C%22OKTA_SCOPES%22%3A%22%3CYOUR_OKTA_SCOPES%3E%22%7D%7D>) (opens VS Code)

Or from a terminal:

```bash
code --add-mcp '{"name":"okta","type":"stdio","command":"uvx","args":["okta-mcp-server"],"env":{"OKTA_ORG_URL":"<YOUR_OKTA_ORG_URL>","OKTA_CLIENT_ID":"<YOUR_OKTA_CLIENT_ID>","OKTA_SCOPES":"<YOUR_OKTA_SCOPES>"}}'
```

Or commit it to the repo in `.vscode/mcp.json`:

`.vscode/mcp.json`:

```json
{
  "servers": {
    "okta": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "okta-mcp-server"
      ],
      "env": {
        "OKTA_ORG_URL": "<YOUR_OKTA_ORG_URL>",
        "OKTA_CLIENT_ID": "<YOUR_OKTA_CLIENT_ID>",
        "OKTA_SCOPES": "<YOUR_OKTA_SCOPES>"
      }
    }
  }
}
```

Needs uv (Python) on your computer.

### Devin Desktop

1. Add it to `~/.config/devin/mcp_config.json` (macOS and Linux) or `%APPDATA%\devin\mcp_config.json` (Windows):

`mcp_config.json`:

```json
{
  "mcpServers": {
    "okta": {
      "command": "uvx",
      "args": [
        "okta-mcp-server"
      ],
      "env": {
        "OKTA_ORG_URL": "<YOUR_OKTA_ORG_URL>",
        "OKTA_CLIENT_ID": "<YOUR_OKTA_CLIENT_ID>",
        "OKTA_SCOPES": "<YOUR_OKTA_SCOPES>"
      }
    }
  }
}
```

2. Refresh the MCP server list in Cascade. Replace the placeholders with your own values.

Devin Desktop is the new name for Windsurf.

### Codex

```bash
codex mcp add okta --env "OKTA_ORG_URL=<YOUR_OKTA_ORG_URL>" --env "OKTA_CLIENT_ID=<YOUR_OKTA_CLIENT_ID>" --env "OKTA_SCOPES=<YOUR_OKTA_SCOPES>" -- uvx okta-mcp-server
```

Or edit `~/.codex/config.toml` directly:

`config.toml`:

```toml
[mcp_servers.okta]
command = "uvx"
args = ["okta-mcp-server"]
env = { OKTA_ORG_URL = "<YOUR_OKTA_ORG_URL>", OKTA_CLIENT_ID = "<YOUR_OKTA_CLIENT_ID>", OKTA_SCOPES = "<YOUR_OKTA_SCOPES>" }
```

Needs uv (Python) on your computer. Replace the placeholders with your own values.

### Gemini CLI

```bash
gemini mcp add -e "OKTA_ORG_URL=<YOUR_OKTA_ORG_URL>" -e "OKTA_CLIENT_ID=<YOUR_OKTA_CLIENT_ID>" -e "OKTA_SCOPES=<YOUR_OKTA_SCOPES>" okta uvx okta-mcp-server
```

This adds it to the current project. Add `-s user` to use it everywhere.

### Any client

Most clients that start local servers accept this shape:

```json
{
  "mcpServers": {
    "okta": {
      "command": "uvx",
      "args": [
        "okta-mcp-server"
      ],
      "env": {
        "OKTA_ORG_URL": "<YOUR_OKTA_ORG_URL>",
        "OKTA_CLIENT_ID": "<YOUR_OKTA_CLIENT_ID>",
        "OKTA_SCOPES": "<YOUR_OKTA_SCOPES>"
      }
    }
  }
}
```

Zed puts servers under `context_servers` in its settings, with the same `command`, `args` and `env` fields.

Needs uv (Python) on your computer. Replace the placeholders with your own values.

## Details

- Server version: 1.1.7
- Last checked: 2026-10-03
- Listed: 2026-10-03
- Updated: 2026-10-03

---
Source: https://mcp.tc/i/okta (mcp.tc is an independent directory, not affiliated with this server's publisher). Corrections: https://mcp.tc/report
