Not configured

Okta Org Configuration

Settings are stored in the server session only — never written to disk.

If set, this is used instead of Client Secret to authenticate token requests (Authorization Code exchange, Introspect) via private_key_jwt. The OIDC app's client authentication method must be set to Public key / Private key in Okta.
Use org for the org-level AS, default for /oauth2/default, or a custom AS ID.

Authorization Code + PKCE

Redirects to your Okta org. PKCE code challenge is generated server-side.

Login with Okta

AI Agent Flow O4AI

Agent authenticates with a private JWK and exchanges a user id_token for an agent token (ID-JAG).

Skips re-entering Client ID / Private JWK below when they're the same as Config's — the server reuses the values already saved in your session, they're never sent back to the browser.
Paste the private key JSON from AI Agents > [Agent] > Credentials > Add public key.
Machine access (non-human caller — no signed-in user)

Obtains the subject access_token via client_credentials against a custom AS, on behalf of a caller (app/service/other AI agent) registered under the AI Agent's Machine access callers. Fills the Subject Token field above with the result — it does not change the exchange request itself.

Issuer URL of the resource app's authorization server (Resource Connection's custom AS).

Token Inspector

ID-JAG tokens are issued by the org AS, so set org as the Authorization Server ID below when introspecting one.
Some token types aren't tracked by Okta's introspect endpoint (e.g. ID-JAG, whose typ is oauth-id-jag+jwt) — they're self-contained JWTs meant to be verified locally against the issuer's public keys, the same way a resource AS validates one. Use "Verify Signature" for those.

Resource Server Connector Broker Consent STS

Exchanges an Okta access_token / id_token from the OIDC Login tab, using connector credentials, for a resource-server-specific access token.