Skip to main content
SCIM Provisioning for OKTA

Organizations: Configure provisioning for OKTA

Updated over a week ago

This guide provides the steps required to configure provisioning for HackerOne.com.

Features

  • Push New Users

    • New users created through OKTA will also be created in the third-party application.

  • Push Profile Updates

    • Okta will push all user profile updates to the third-party application.

  • Push User Deactivation

    • Deactivating the user or disabling the user's access to the application through OKTA will deactivate the user in the third-party application.

    • Note: In this application, deactivating a user involves revoking login access while retaining the user's HackerOne information as inactive.

  • Reactivate Users

    • You can reactivate user accounts in the application.

  • Push Groups

    • OKTA can also push newly created groups to the third-party application.

Setup

Open OKTA and navigate to your Applications

  1. Follow the steps here to set up your SAML integration.

    1. Note: If you’ve set up your SAML integration before using the HackerOne application, SCIM will not be available.
      You can follow the steps as described here and skip steps 6 and 10 - 13. Use this new application to set up SCIM provisioning.

  2. Open your HackerOne SCIM application created above.

  3. In the General tab click Edit behind App Settings.

  4. Check the Enable provisioning features box

    App settings screen
  5. Click Save

  6. Click the Provisioning tab.

  7. Click Edit.

  8. Set the Authentication Mode to HTTP HeaderPaste the URL from the SCIM credentials page into the SCIM connector base URL box.

  9. Enter your email in the Unique identifier field for users box.

  10. Enter the API Token you stored above behind Authorization.

  11. Select the provisioning actions you want to use

    SCIM connection setup
  12. Click Test Connector Configuration; if successful, a verification message appears at the top of the screen.

  13. Click Save.

  14. Select To App in the left panel, then select the Provisioning Features you want to enable.

    Provisioning to the app
  15. Click Save.

  16. You can now assign people to the app (if needed) and finish the application setup.

Troubleshooting Tips

Initial activation of Okta provisioning in HackerOne requires contacting your CSM. Please reach out with any questions during your configuration process.

Note: When Okta deactivates users, HackerOne removes them from your organization. Users lose login access but their data remains as 'inactive users.' Contact your CSM to permanently delete user data.

Did this answer your question?