Skip to content

SYSTEM Cited by 3 sources

Okta

What it is

Okta is an enterprise identity provider (IdP) — external SaaS directory + SSO + MFA + lifecycle management, commonly federated to via SAML or OIDC from applications and AWS accounts.

Why it's on this wiki

Okta appears as the upstream IdP in federated architectures where Amazon Cognito handles the AWS-application-side token issuance but employees authenticate against a centralized enterprise directory. Convera's internal customer-service apps use this shape:

User → Convera Connect App → Okta (SAML/OIDC auth)
                           → Cognito (federated identity, issues JWT)
                           → Cognito pre-token-generation Lambda
                             (enriches access token from DynamoDB)
                           → App uses enriched JWT against API Gateway

This is a canonical instance of centralized-identity-federation — identity lives in a single IdP, per-application authorization grants flow through application-specific token issuers (Cognito). (Source: sources/2026-02-05-aws-convera-verified-permissions-fine-grained-authorization)

Seen in

OIDC+device-posture access gate shape: Okta "enforce[s] policies that ensure only users on managed devices with a secure security posture are granted access." - sources/2026-09-24-zalando-agentic-platform-open-sourcing-the-agentic-identity-broker — Okta named as the step-up-authentication backend for high-risk agent transactions. In Zalando's Agentic Identity Broker roadmap, because central tool approvals invite rubber-stamping (approval fatigue), high-risk transactions should use CIBA (Client-Initiated Backchannel Authentication) in the broker, "for example to obtain an approval via Okta Verify" — the step-up authentication shape for agent actions. Zalando also names Okta among the "vendor products" it tracks for XAA-style cross-app-access features it will adopt without agents/MCP servers having to change.

  • systems/amazon-cognito — federated-to-by Cognito in this shape.
  • systems/netbird — Okta is the OIDC provider in Yelp's Netbird ZTA deployment.
  • centralized-identity-federation — the overall architecture pattern.
  • pre-token-generation-hook — runs post-federation to add application-specific authorization attributes.
  • oidc-plus-device-posture-access-gate — the identity+posture access pattern Yelp instantiated against Okta.
  • systems/zalando-identity-broker — names Okta (CIBA / Okta Verify) as the step-up-authentication backend for high-risk agent transactions.
  • concepts/step-up-authentication · concepts/human-in-the-loop
Last updated · 766 distilled / 2,225 read