Okta MCP Server
Manage an Okta org in natural language: create and update users and groups, manage applications and policies, and read system logs, with confirmation before destructive changes.
- Maintained by
- Okta
- Hosting
- Runs locally on your machine
- Authentication
- API key or credentials (environment variables)
- Last checked
Requires Python 3.13+ and an Okta app with the API scopes you want to grant; tools are enabled only for scopes you configure.
How to connect the Okta MCP server
Pick your AI client and paste the snippet. Swap the YOUR_… placeholders for your own values. New to this? Our guide to how MCP clients and servers fit together explains what each piece does.
Claude Code
claude mcp add --env OKTA_ORG_URL=https://YOUR_ORG.okta.com --env OKTA_CLIENT_ID=YOUR_CLIENT_ID --env 'OKTA_SCOPES=okta.users.read okta.groups.read' --transport stdio okta \
-- uvx okta-mcp-server Claude Desktop
{
"mcpServers": {
"okta": {
"command": "uvx",
"args": [
"okta-mcp-server"
],
"env": {
"OKTA_ORG_URL": "https://YOUR_ORG.okta.com",
"OKTA_CLIENT_ID": "YOUR_CLIENT_ID",
"OKTA_SCOPES": "okta.users.read okta.groups.read"
}
}
}
} Fully quit and reopen Claude Desktop after saving.
Full Claude Desktop setup guide →Cursor
{
"mcpServers": {
"okta": {
"command": "uvx",
"args": [
"okta-mcp-server"
],
"env": {
"OKTA_ORG_URL": "https://YOUR_ORG.okta.com",
"OKTA_CLIENT_ID": "YOUR_CLIENT_ID",
"OKTA_SCOPES": "okta.users.read okta.groups.read"
}
}
}
} VS Code
{
"servers": {
"okta": {
"type": "stdio",
"command": "uvx",
"args": [
"okta-mcp-server"
],
"env": {
"OKTA_ORG_URL": "https://YOUR_ORG.okta.com",
"OKTA_CLIENT_ID": "YOUR_CLIENT_ID",
"OKTA_SCOPES": "okta.users.read okta.groups.read"
}
}
}
} Frequently asked questions
What is the Okta MCP server?
It is a Model Context Protocol (MCP) server — a small piece of software that gives AI assistants like Claude a secure, governed connection to Okta. Manage an Okta org in natural language: create and update users and groups, manage applications and policies, and read system logs, with confirmation before destructive changes.
Is there an official Okta MCP server?
Yes. The Okta MCP server is an official integration, maintained by the vendor or the Model Context Protocol project, which makes it the safest default for business use. It is maintained by Okta.
Is the Okta MCP server hosted, or do I run it myself?
It runs locally. Your AI client starts it on your own machine with uvx, and it talks to the client over standard input and output rather than the network.
Do I need an API key for the Okta MCP server?
Yes. The local server reads OKTA_ORG_URL, OKTA_CLIENT_ID, OKTA_SCOPES from its environment, so you create those credentials first and add them to your client's config.
What can an AI assistant actually do with Okta?
Through this server an assistant can work with manage users, manage groups, manage applications, policies, system logs — reading from and acting on Okta directly instead of you copy-pasting between windows. What you allow it to do is controlled by the permissions you grant.
How do I set this up for my business?
The setup section above has copy-paste config for Claude Code, Claude Desktop, Cursor and VS Code. If you want it rolled out across a team with permissions, governance and support handled, that is what Crox's Build engagement covers.
New to MCP? Start with our plain-English guide to the Model Context Protocol or see how to connect AI to your business tools without writing code .
Want this connected to your business — with governance handled?
Crox maps your processes, connects AI to the tools you already use, and keeps it working as models change. Start with a readiness assessment or talk to us about a build.