Okta Org Configuration
Settings are stored in the server session only — never written to disk.
Authorization Code + PKCE
Redirects to your Okta org. PKCE code challenge is generated server-side.
Tokens Received
AI Agent Flow O4AI
Agent authenticates with a private JWK and exchanges a user id_token for an agent token (ID-JAG).
Token Inspector
ID-JAG tokens are issued by the org AS, so set
org as the Authorization Server ID below when introspecting one.
typ is oauth-id-jag+jwt) — they're self-contained JWTs meant to be verified locally against the issuer's public keys, the same way a resource AS validates one. Use "Verify Signature" for those.
Resource Server Connector Broker Consent STS
Exchanges an Okta access_token / id_token from the OIDC Login tab, using connector credentials, for a resource-server-specific access token.