ax-check.com
by Gauge
O
Okta
okta.com
ax-check.com
Checked 8 October 2026
B
68/100
Agents need your login
Okta's pricing is clear, but no quickstart or API docs were tested
Pricing lists concrete per-user rates and limits with no login wall. Docs, SDKs, and CLI setup remain unassessed — 10 of 23 checklist items unassessed, 10 pass.
4 fixes to start with
Concrete changes, backed by what we found.
Tell agents where to start and organize the links in /llms.txt.
llms.txt offers no starting guidance or navigation structure beyond flat category link lists.
Recorded coding sessions
Same task, 3 models, no okta.com account. Recorded 8 October 2026 on Pi.
3 recorded · 1m 10s
1m 10s · recorded
Session findings
Select a finding to see it in context.
›Thinking…
I need to investigate further. Let me check the details.
The user is asking for help building a simple example using Okta, wants me to explain how pricing works, and tell them whether it's easy for me to manage. They're asking me to be upfront if there's no actionable developer workflow, to stay lightweight, and not to start up a local service stack.
Let me check the environment — do I have credentials? Without an actual Okta org/API token, I can't build something. Let me quickly check the environment variables and directory.
ls -la /sandbox/repo; env | grep -i -E 'okta|OKTA' ; echo "---"; curl -s -m 5 -o /dev/null -w "%{http_code}" https://developer.okta.com/ 2>&1 || echo "no network"total 16
total 16 drwxr-xr-x 3 root root 4096 Sep 18 08:00 . drwxr-xr-x 7 root root 4096 Oct 8 04:42 .. drwxr-xr-x 8 root root 4096 Sep 24 20:05 .git -rw-r--r-- 1 root root 408 Sep 18 08:00 .gitignore --- 200
Recorded tool call
{
"type": "tool_call",
"seq": 3,
"ts": "2026-10-08T04:42:21.009Z",
"name": "bash",
"turn": 1,
"input": {
"command": "ls -la /sandbox/repo; env | grep -i -E 'okta|OKTA' ; echo \"---\"; curl -s -m 5 -o /dev/null -w \"%{http_code}\" https://developer.okta.com/ 2>&1 || echo \"no network\""
},
"run_id": "cmuz1v6xb000r0iu16l6rbc55",
"tool_id": "chatcmpl-tool-ab387d2ffefdab88",
"tool_kind": "shell"
}Recorded tool result
{
"type": "tool_result",
"seq": 5,
"ts": "2026-10-08T04:42:21.900Z",
"turn": 1,
"output": {
"content": [
{
"text": "total 16\ndrwxr-xr-x 3 root root 4096 Sep 18 08:00 .\ndrwxr-xr-x 7 root root 4096 Oct 8 04:42 ..\ndrwxr-xr-x 8 root root 4096 Sep 24 20:05 .git\n-rw-r--r-- 1 root root 408 Sep 18 08:00 .gitignore\n---\n200",
"type": "text"
}
]
},
"run_id": "cmuz1v6xb000r0iu16l6rbc55",
"tool_id": "chatcmpl-tool-ab387d2ffefdab88",
"is_error": false,
"tool_kind": "shell"
}›Thinking…
Network is working. No Okta credentials. Can't create an actual Okta org without user credentials — creating a developer org requires a signup via email verification, which I can't do. So unless the user provides an org URL + API token (and possibly a client ID/secret), I'll be blocked on the "running a live example" part.
Still, I can write the example code (SDK-based, using hosted login / API) and explain the pricing and manageability. That's reasonable. Let me check what's in the repo (it's empty). Build a minimal example: a Node.js app using the Okta SDK? Or use okta-auth-js + express? Keep it lightweight: a small Express app using OIDC redirect via openid-client, or Okta's own SDK (@okta/okta-auth-js is for SPAs). The simplest "use a hosted product via SDK/API" example: a Node script that calls the Okta Management API (list users) with @okta/okta-sdk-nodejs, or an OIDC web login example using openid-client.
I'll provide both, but keep it simple: one directory containing the OIDC login example (the typical "Okta quickstart"). Can test the parts that don't require credentials (install dependencies, syntax check) — installing npm packages should be fine, quick. Let me do that.
Pricing: Okta is per user per month (Workforce Identity Cloud): roughly $2–15/user/month depending on product (SSO around $2/user/month? Actual list prices: SSO $2, MFA $3, Adaptive SSO $6, Lifecycle Management $4, Advanced Server Access etc.). Customer Identity (Auth0, now part of Okta) is MAU-based: free up to 7,500 MAU (B2C), then tiered pricing per MAU ($23/month for up to 1,000? Actual Auth0 pricing: Free up to 7,500 MAU; B2C Essentials starts at $23/month for up to 1,000 MAU and scales). Developer orgs are free (developer.okta.com — free developer sandbox, 1,000 MAU? Historically "free up to 1,000 MAU", now a developer org with limits). I should be honest about approximate pricing and point them to okta.com/pricing.
Manageability: fine for me — API-token-driven, Terraform provider, well-documented REST APIs. However, creating an org requires a human to sign up via email verification, so that part I can't do.
Plan: write the example files, npm install and run a syntax check, and don't run the server (it's long-running — don't start it). State that I'll be blocked on live testing without credentials.
Network access works, but I have no Okta credentials or org in this environment — so I can build the example fully, but can't run it live against a real Okta tenant without you providing one. Here's the plan and the answer to your questions first:
Pricing (approximate, see okta.com/pricing for current numbers):
- Okta Workforce Identity (SSO/MFA for employees): per-user-per-month, ~$2/user/mo for SSO, ~$6–15/user/mo with MFA/Lifecycle Management bundles. Volume-tiered.
- Okta Customer Identity (Auth0-based): per monthly active user (MAU). Free up to ~7,500 MAU; paid tiers start around $23/mo for 1,000 MAU and scale with usage.
- Developer orgs are free (developer.okta.com) — that's what I'd use for an example, so cost is $0 for this.
Easy for me to manage? Yes, mostly: everything is API-driven (management APIs, OIDC endpoints, API tokens, a mature Terraform provider), so I can script provisioning of apps/users/policies. The one hard blocker: creating an org requires a human (email signup + verification). After that, I'm unblocked given an org URL + API token.
Now the example — a minimal Node.js app doing OIDC login against an Okta-hosted sign-in page, plus a management-API script. No local stacks, no long-running commands.
mkdir -p /sandbox/repo/okta-example && cd /sandbox/repo/okta-example && npm init -y >/dev/null && npm install express openid-client@^5 --no-audit --no-fund 2>&1 | tail -2
added 74 packages in 5s
added 74 packages in 5s
Recorded tool call
{
"type": "tool_call",
"seq": 10,
"ts": "2026-10-08T04:42:33.552Z",
"name": "bash",
"turn": 1,
"input": {
"command": "mkdir -p /sandbox/repo/okta-example && cd /sandbox/repo/okta-example && npm init -y >/dev/null && npm install express openid-client@^5 --no-audit --no-fund 2>&1 | tail -2"
},
"run_id": "cmuz1v6xb000r0iu16l6rbc55",
"tool_id": "chatcmpl-tool-83b50f01660458ba",
"tool_kind": "shell"
}Recorded tool result
{
"type": "tool_result",
"seq": 13,
"ts": "2026-10-08T04:42:40.018Z",
"turn": 1,
"output": {
"content": [
{
"text": "\nadded 74 packages in 5s\n",
"type": "text"
}
]
},
"run_id": "cmuz1v6xb000r0iu16l6rbc55",
"tool_id": "chatcmpl-tool-83b50f01660458ba",
"is_error": false,
"tool_kind": "shell"
}›Thinking…
I'll create the files: app.js (OIDC login using openid-client v5), manage.js (calling the management API with fetch), README, .env.example. After that, I'll run syntax checks with node --check. I won't start the server.
File edits
1 file
Writtenokta-example/app.jsView changes
/sandbox/repo/okta-example/app.js
Written content · previous contents were not recorded
// Minimal Okta OIDC example: sign in via Okta's *hosted* sign-in page.// No local auth stack — Okta hosts login, MFA, consent. This app just// speaks standard OpenID Connect using openid-client.//// Setup (in Okta Admin Console -> Applications -> Create App Integration):// 1. Type: Web, Sign-in method: OIDC// 2. Redirect URI: http://localhost:3000/callback// 3. Copy Client ID + Client Secret into .envconst express = require("express");const session = require("express-session");const { Issuer, generators } = require("openid-client");const app = express();app.use(session({secret: process.env.SESSION_SECRET || "dev-secret",resave: false,saveUninitialized: true,cookie: { secure: false },}));let client; // initialized async belowasync function getClient() {if (client) return client;const issuer = await Issuer.discover(process.env.OKTA_ISSUER);client = new issuer.Client({client_id: process.env.OKTA_CLIENT_ID,client_secret: process.env.OKTA_CLIENT_SECRET,redirect_uris: ["http://localhost:3000/callback"],response_types: ["code"],});return client;}app.get("/", (req, res) => {if (req.session.user) {res.send(`<pre>Logged in as:\n${JSON.stringify(req.session.user, null, 2)}</pre><a href="/logout">Log out</a>`);} else {res.send('<a href="/login">Log in with Okta</a>');}});app.get("/login", async (req, res) => {const c = await getClient();const code_verifier = generators.codeVerifier();req.session.code_verifier = code_verifier;const url = c.authorizationUrl({scope: "openid profile email",code_challenge: generators.codeChallenge(code_verifier),code_challenge_method: "S256",state: generators.state(),nonce: generators.nonce(),});req.session.state = new URL(url).searchParams.get("state");res.redirect(url); // user is handed off to Okta's hosted sign-in page});app.get("/callback", async (req, res) => {const c = await getClient();const tokenSet = await c.callback("http://localhost:3000/callback",c.callbackParams(req),{code_verifier: req.session.code_verifier,state: req.session.state,});const claims = tokenSet.claims();req.session.user = {sub: claims.sub,email: claims.email,name: claims.name,id_token_issued_at: claims.iat,};res.redirect("/");});app.get("/logout", (req, res) => {req.session.destroy(() => res.redirect("/"));});if (require.main === module) {if (!process.env.OKTA_ISSUER) {console.error("Missing OKTA_ISSUER — copy .env.example to .env first.");process.exit(1);}app.listen(3000, () => console.log("http://localhost:3000"));}module.exports = app;
Source: write · chatcmpl-tool-8c15aa1f8b5998a8
Recorded tool call
{
"type": "tool_call",
"seq": 16,
"ts": "2026-10-08T04:42:55.864Z",
"name": "write",
"turn": 1,
"input": {
"path": "/sandbox/repo/okta-example/app.js",
"content": "// Minimal Okta OIDC example: sign in via Okta's *hosted* sign-in page.\n// No local auth stack — Okta hosts login, MFA, consent. This app just\n// speaks standard OpenID Connect using openid-client.\n//\n// Setup (in Okta Admin Console -> Applications -> Create App Integration):\n// 1. Type: Web, Sign-in method: OIDC\n// 2. Redirect URI: http://localhost:3000/callback\n// 3. Copy Client ID + Client Secret into .env\n\nconst express = require(\"express\");\nconst session = require(\"express-session\");\nconst { Issuer, generators } = require(\"openid-client\");\n\nconst app = express();\napp.use(\n session({\n secret: process.env.SESSION_SECRET || \"dev-secret\",\n resave: false,\n saveUninitialized: true,\n cookie: { secure: false },\n })\n);\n\nlet client; // initialized async below\n\nasync function getClient() {\n if (client) return client;\n const issuer = await Issuer.discover(process.env.OKTA_ISSUER);\n client = new issuer.Client({\n client_id: process.env.OKTA_CLIENT_ID,\n client_secret: process.env.OKTA_CLIENT_SECRET,\n redirect_uris: [\"http://localhost:3000/callback\"],\n response_types: [\"code\"],\n });\n return client;\n}\n\napp.get(\"/\", (req, res) => {\n if (req.session.user) {\n res.send(`<pre>Logged in as:\\n${JSON.stringify(req.session.user, null, 2)}</pre>\n <a href=\"/logout\">Log out</a>`);\n } else {\n res.send('<a href=\"/login\">Log in with Okta</a>');\n }\n});\n\napp.get(\"/login\", async (req, res) => {\n const c = await getClient();\n const code_verifier = generators.codeVerifier();\n req.session.code_verifier = code_verifier;\n const url = c.authorizationUrl({\n scope: \"openid profile email\",\n code_challenge: generators.codeChallenge(code_verifier),\n code_challenge_method: \"S256\",\n state: generators.state(),\n nonce: generators.nonce(),\n });\n req.session.state = new URL(url).searchParams.get(\"state\");\n res.redirect(url); // user is handed off to Okta's hosted sign-in page\n});\n\napp.get(\"/callback\", async (req, res) => {\n const c = await getClient();\n const tokenSet = await c.callback(\n \"http://localhost:3000/callback\",\n c.callbackParams(req),\n {\n code_verifier: req.session.code_verifier,\n state: req.session.state,\n }\n );\n const claims = tokenSet.claims();\n req.session.user = {\n sub: claims.sub,\n email: claims.email,\n name: claims.name,\n id_token_issued_at: claims.iat,\n };\n res.redirect(\"/\");\n});\n\napp.get(\"/logout\", (req, res) => {\n req.session.destroy(() => res.redirect(\"/\"));\n});\n\nif (require.main === module) {\n if (!process.env.OKTA_ISSUER) {\n console.error(\"Missing OKTA_ISSUER — copy .env.example to .env first.\");\n process.exit(1);\n }\n app.listen(3000, () => console.log(\"http://localhost:3000\"));\n}\n\nmodule.exports = app;\n"
},
"run_id": "cmuz1v6xb000r0iu16l6rbc55",
"tool_id": "chatcmpl-tool-8c15aa1f8b5998a8",
"tool_kind": "file_edit"
}Recorded tool result
{
"type": "tool_result",
"seq": 20,
"ts": "2026-10-08T04:42:55.864Z",
"turn": 1,
"output": {
"content": [
{
"text": "Successfully wrote 2752 bytes to /sandbox/repo/okta-example/app.js",
"type": "text"
}
]
},
"run_id": "cmuz1v6xb000r0iu16l6rbc55",
"tool_id": "chatcmpl-tool-8c15aa1f8b5998a8",
"is_error": false,
"tool_kind": "file_edit"
}File edits
1 file
Writtenokta-example/manage.jsView changes
/sandbox/repo/okta-example/manage.js
Written content · previous contents were not recorded
// Minimal Okta Management API example — plain REST + fetch, no SDK needed.// Shows the workflow an agent/script can act on with just an API token:// list users, list apps, create a test user.//// Token: Okta Admin Console -> Security -> API -> Tokens -> Create Tokenconst BASE = process.env.OKTA_ORG; // e.g. https://dev-123456.okta.comconst TOKEN = process.env.OKTA_API_TOKEN;if (!BASE || !TOKEN) {console.error("Set OKTA_ORG and OKTA_API_TOKEN (see .env.example).");process.exit(1);}async function okta(path, opts = {}) {const res = await fetch(`${BASE}/api/v1${path}`, {...opts,headers: {Authorization: `SSWS ${TOKEN}`,Accept: "application/json","Content-Type": "application/json",...(opts.headers || {}),},});if (!res.ok) throw new Error(`${res.status}: ${await res.text()}`);return res.status === 204 ? null : res.json();}(async () => {const users = await okta("/users?limit=5");console.log("Users:",users.map((u) => `${u.profile.login} (${u.status})`));const apps = await okta("/apps?limit=5");console.log("Apps:", apps.map((a) => `${a.label} [${a.status}]`));// Uncomment to create a test user (deactivate/delete later to stay clean):// const created = await okta("/users?activate=false", {// method: "POST",// body: JSON.stringify({// profile: {// firstName: "Test", lastName: "User",// email: "test.user@example.com", login: "test.user@example.com",// },// }),// });// console.log("Created:", created.id);})();
Source: write · chatcmpl-tool-8d7615bd11ceb6af
Recorded tool call
{
"type": "tool_call",
"seq": 17,
"ts": "2026-10-08T04:42:55.864Z",
"name": "write",
"turn": 1,
"input": {
"path": "/sandbox/repo/okta-example/manage.js",
"content": "// Minimal Okta Management API example — plain REST + fetch, no SDK needed.\n// Shows the workflow an agent/script can act on with just an API token:\n// list users, list apps, create a test user.\n//\n// Token: Okta Admin Console -> Security -> API -> Tokens -> Create Token\n\nconst BASE = process.env.OKTA_ORG; // e.g. https://dev-123456.okta.com\nconst TOKEN = process.env.OKTA_API_TOKEN;\n\nif (!BASE || !TOKEN) {\n console.error(\"Set OKTA_ORG and OKTA_API_TOKEN (see .env.example).\");\n process.exit(1);\n}\n\nasync function okta(path, opts = {}) {\n const res = await fetch(`${BASE}/api/v1${path}`, {\n ...opts,\n headers: {\n Authorization: `SSWS ${TOKEN}`,\n Accept: \"application/json\",\n \"Content-Type\": \"application/json\",\n ...(opts.headers || {}),\n },\n });\n if (!res.ok) throw new Error(`${res.status}: ${await res.text()}`);\n return res.status === 204 ? null : res.json();\n}\n\n(async () => {\n const users = await okta(\"/users?limit=5\");\n console.log(\n \"Users:\",\n users.map((u) => `${u.profile.login} (${u.status})`)\n );\n\n const apps = await okta(\"/apps?limit=5\");\n console.log(\"Apps:\", apps.map((a) => `${a.label} [${a.status}]`));\n\n // Uncomment to create a test user (deactivate/delete later to stay clean):\n // const created = await okta(\"/users?activate=false\", {\n // method: \"POST\",\n // body: JSON.stringify({\n // profile: {\n // firstName: \"Test\", lastName: \"User\",\n // email: \"test.user@example.com\", login: \"test.user@example.com\",\n // },\n // }),\n // });\n // console.log(\"Created:\", created.id);\n})();\n"
},
"run_id": "cmuz1v6xb000r0iu16l6rbc55",
"tool_id": "chatcmpl-tool-8d7615bd11ceb6af",
"tool_kind": "file_edit"
}Recorded tool result
{
"type": "tool_result",
"seq": 22,
"ts": "2026-10-08T04:42:55.864Z",
"turn": 1,
"output": {
"content": [
{
"text": "Successfully wrote 1584 bytes to /sandbox/repo/okta-example/manage.js",
"type": "text"
}
]
},
"run_id": "cmuz1v6xb000r0iu16l6rbc55",
"tool_id": "chatcmpl-tool-8d7615bd11ceb6af",
"is_error": false,
"tool_kind": "file_edit"
}File edits
1 file
Writtenokta-example/.env.exampleView changes
/sandbox/repo/okta-example/.env.example
Written content · previous contents were not recorded
# From your free Okta developer org (https://developer.okta.com)OKTA_ORG=https://dev-123456.okta.com# Issuer = org URL + /oauth2/default (the default authorization server)OKTA_ISSUER=https://dev-123456.okta.com/oauth2/default# From Admin Console -> Applications -> your OIDC Web appOKTA_CLIENT_ID=your-client-idOKTA_CLIENT_SECRET=your-client-secret# From Admin Console -> Security -> API -> TokensOKTA_API_TOKEN=your-api-tokenSESSION_SECRET=change-me
Source: write · chatcmpl-tool-94b551e2983f7e49
Recorded tool call
{
"type": "tool_call",
"seq": 18,
"ts": "2026-10-08T04:42:55.864Z",
"name": "write",
"turn": 1,
"input": {
"path": "/sandbox/repo/okta-example/.env.example",
"content": "# From your free Okta developer org (https://developer.okta.com)\nOKTA_ORG=https://dev-123456.okta.com\n# Issuer = org URL + /oauth2/default (the default authorization server)\nOKTA_ISSUER=https://dev-123456.okta.com/oauth2/default\n# From Admin Console -> Applications -> your OIDC Web app\nOKTA_CLIENT_ID=your-client-id\nOKTA_CLIENT_SECRET=your-client-secret\n# From Admin Console -> Security -> API -> Tokens\nOKTA_API_TOKEN=your-api-token\nSESSION_SECRET=change-me\n"
},
"run_id": "cmuz1v6xb000r0iu16l6rbc55",
"tool_id": "chatcmpl-tool-94b551e2983f7e49",
"tool_kind": "file_edit"
}Recorded tool result
{
"type": "tool_result",
"seq": 21,
"ts": "2026-10-08T04:42:55.864Z",
"turn": 1,
"output": {
"content": [
{
"text": "Successfully wrote 460 bytes to /sandbox/repo/okta-example/.env.example",
"type": "text"
}
]
},
"run_id": "cmuz1v6xb000r0iu16l6rbc55",
"tool_id": "chatcmpl-tool-94b551e2983f7e49",
"is_error": false,
"tool_kind": "file_edit"
}File edits
1 file
Writtenokta-example/README.mdView changes
/sandbox/repo/okta-example/README.md
Written content · previous contents were not recorded
# Okta minimal exampleTwo small scripts, both using Okta's *hosted* services — nothing runs auth locally.| File | What it does | Auth needed ||---|---|---|| `app.js` | Express app that logs users in via Okta's hosted sign-in page (OIDC + PKCE) | Client ID/secret from an OIDC Web app || `manage.js` | Calls the Okta Management API (list users/apps) with plain `fetch` | API token |## Run1. Create a **free** developer org at https://developer.okta.com (needs human email signup).2. `cp .env.example .env` and fill in values (see comments in the file).3. OIDC login demo: `node -r dotenv/config app.js` → open http://localhost:30004. Management API demo: `node -r dotenv/config manage.js`## Notes- OIDC app setup: Admin Console → Applications → Create App Integration → Web → OIDC, redirect URI `http://localhost:3000/callback`.- API tokens: Admin Console → Security → API → Tokens.- A Terraform provider (`oktadeveloper/okta`) exists if you want infra-as-code for apps/users/policies.
Source: write · chatcmpl-tool-b48afebb943b7a9a
Recorded tool call
{
"type": "tool_call",
"seq": 19,
"ts": "2026-10-08T04:42:55.864Z",
"name": "write",
"turn": 1,
"input": {
"path": "/sandbox/repo/okta-example/README.md",
"content": "# Okta minimal example\n\nTwo small scripts, both using Okta's *hosted* services — nothing runs auth locally.\n\n| File | What it does | Auth needed |\n|---|---|---|\n| `app.js` | Express app that logs users in via Okta's hosted sign-in page (OIDC + PKCE) | Client ID/secret from an OIDC Web app |\n| `manage.js` | Calls the Okta Management API (list users/apps) with plain `fetch` | API token |\n\n## Run\n\n1. Create a **free** developer org at https://developer.okta.com (needs human email signup).\n2. `cp .env.example .env` and fill in values (see comments in the file).\n3. OIDC login demo: `node -r dotenv/config app.js` → open http://localhost:3000\n4. Management API demo: `node -r dotenv/config manage.js`\n\n## Notes\n\n- OIDC app setup: Admin Console → Applications → Create App Integration → Web → OIDC, redirect URI `http://localhost:3000/callback`.\n- API tokens: Admin Console → Security → API → Tokens.\n- A Terraform provider (`oktadeveloper/okta`) exists if you want infra-as-code for apps/users/policies.\n"
},
"run_id": "cmuz1v6xb000r0iu16l6rbc55",
"tool_id": "chatcmpl-tool-b48afebb943b7a9a",
"tool_kind": "file_edit"
}Recorded tool result
{
"type": "tool_result",
"seq": 23,
"ts": "2026-10-08T04:42:55.864Z",
"turn": 1,
"output": {
"content": [
{
"text": "Successfully wrote 1005 bytes to /sandbox/repo/okta-example/README.md",
"type": "text"
}
]
},
"run_id": "cmuz1v6xb000r0iu16l6rbc55",
"tool_id": "chatcmpl-tool-b48afebb943b7a9a",
"is_error": false,
"tool_kind": "file_edit"
}›Thinking…
I need to verify the dependencies and syntax by installing express-session and dotenv, then running syntax checks and testing the client discovery flow against Okta's public metadata endpoint to confirm the network path works without requiring credentials.
cd /sandbox/repo/okta-example && npm install express-session dotenv --no-audit --no-fund 2>&1 | tail -1 && node --check app.js && node --check manage.js && echo "syntax OK" && curl -s -m 8 https://okta.com/.well-known/openid-configuration | head -c 300; echo
added 9 packages in 2s
added 9 packages in 2s syntax OK
Recorded tool call
{
"type": "tool_call",
"seq": 26,
"ts": "2026-10-08T04:42:57.504Z",
"name": "bash",
"turn": 1,
"input": {
"command": "cd /sandbox/repo/okta-example && npm install express-session dotenv --no-audit --no-fund 2>&1 | tail -1 && node --check app.js && node --check manage.js && echo \"syntax OK\" && curl -s -m 8 https://okta.com/.well-known/openid-configuration | head -c 300; echo"
},
"run_id": "cmuz1v6xb000r0iu16l6rbc55",
"tool_id": "chatcmpl-tool-86db007c94886292",
"tool_kind": "shell"
}Recorded tool result
{
"type": "tool_result",
"seq": 30,
"ts": "2026-10-08T04:43:00.436Z",
"turn": 1,
"output": {
"content": [
{
"text": "added 9 packages in 2s\nsyntax OK\n\n",
"type": "text"
}
]
},
"run_id": "cmuz1v6xb000r0iu16l6rbc55",
"tool_id": "chatcmpl-tool-86db007c94886292",
"is_error": false,
"tool_kind": "shell"
}›Thinking…
The curl to okta.com/.well-known didn't return anything — okta.com itself might not be providing it. Let me try developer.okta.com, or use a known developer org. Actually, let me try https://developer.okta.com/.well-known/openid-configuration. Or a sample org. I'll try it quickly.
curl -s -m 8 https://developer.okta.com/.well-known/openid-configuration | head -c 200; echo; curl -s -m 8 https://okta.okta.com/.well-known/openid-configuration | head -c 200; echo
<!DOCTYPE html>
<!DOCTYPE html>
<html lang="en-US">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width,initial-scale=1">
<title>404 Page Not Found | Okta Developer</title>
{"issuer":"https://okta.okta.com","authorization_endpoint":"https://okta.okta.com/oauth2/v1/authorize","token_endpoint":"https://okta.okta.com/oauth2/v1/token","userinfo_endpoint":"https://okta.okta.c
Recorded tool call
{
"type": "tool_call",
"seq": 33,
"ts": "2026-10-08T04:43:02.566Z",
"name": "bash",
"turn": 1,
"input": {
"command": "curl -s -m 8 https://developer.okta.com/.well-known/openid-configuration | head -c 200; echo; curl -s -m 8 https://okta.okta.com/.well-known/openid-configuration | head -c 200; echo"
},
"run_id": "cmuz1v6xb000r0iu16l6rbc55",
"tool_id": "chatcmpl-tool-8c96c9b0026ec244",
"tool_kind": "shell"
}Recorded tool result
{
"type": "tool_result",
"seq": 36,
"ts": "2026-10-08T04:43:03.407Z",
"turn": 1,
"output": {
"content": [
{
"text": "<!DOCTYPE html>\n<html lang=\"en-US\">\n <head>\n <meta charset=\"utf-8\">\n <meta name=\"viewport\" content=\"width=device-width,initial-scale=1\">\n <title>404 Page Not Found | Okta Developer</title>\n \n{\"issuer\":\"https://okta.okta.com\",\"authorization_endpoint\":\"https://okta.okta.com/oauth2/v1/authorize\",\"token_endpoint\":\"https://okta.okta.com/oauth2/v1/token\",\"userinfo_endpoint\":\"https://okta.okta.c\n",
"type": "text"
}
]
},
"run_id": "cmuz1v6xb000r0iu16l6rbc55",
"tool_id": "chatcmpl-tool-8c96c9b0026ec244",
"is_error": false,
"tool_kind": "shell"
}›Thinking…
OIDC discovery has been verified against an actually existing public Okta organization (okta.okta.com), and it's been confirmed that the discovery flow in app.js works. Without credentials, there's nothing more that can be run. I'll commit with git. Let me check the git status of the repository — there's a .git and a .gitignore. I'll commit.
cd /sandbox/repo && cat .gitignore | head; git add okta-example/app.js okta-example/manage.js okta-example/README.md okta-example/.env.example okta-example/package.json okta-example/package-lock.json 2>/dev/null; git -c user.email=agent@local -c user.name=agent commit -m "Add minimal Okta OIDC + Management API example" -q && git log --oneline -1
# Keep generated and vendored files out of source diffs.
# Keep generated and vendored files out of source diffs. # Logs / OS cruft *.log .DS_Store # JavaScript / TypeScript node_modules/ .next/ dist/ 147c128 Add minimal Okta OIDC + Management API example
Recorded tool call
{
"type": "tool_call",
"seq": 39,
"ts": "2026-10-08T04:43:08.090Z",
"name": "bash",
"turn": 1,
"input": {
"command": "cd /sandbox/repo && cat .gitignore | head; git add okta-example/app.js okta-example/manage.js okta-example/README.md okta-example/.env.example okta-example/package.json okta-example/package-lock.json 2>/dev/null; git -c user.email=agent@local -c user.name=agent commit -m \"Add minimal Okta OIDC + Management API example\" -q && git log --oneline -1"
},
"run_id": "cmuz1v6xb000r0iu16l6rbc55",
"tool_id": "chatcmpl-tool-a0bd042f1c3fdf1b",
"tool_kind": "shell"
}Recorded tool result
{
"type": "tool_result",
"seq": 40,
"ts": "2026-10-08T04:43:08.090Z",
"turn": 1,
"output": {
"content": [
{
"text": "# Keep generated and vendored files out of source diffs.\n\n# Logs / OS cruft\n*.log\n.DS_Store\n\n# JavaScript / TypeScript\nnode_modules/\n.next/\ndist/\n147c128 Add minimal Okta OIDC + Management API example\n",
"type": "text"
}
]
},
"run_id": "cmuz1v6xb000r0iu16l6rbc55",
"tool_id": "chatcmpl-tool-a0bd042f1c3fdf1b",
"is_error": false,
"tool_kind": "shell"
}›Thinking…
Also, I can verify the Issuer.discover flow by pointing it at okta.okta.com — a simple node one-liner, not something that runs for a long time. This will prove that the SDK path works. Let's do it.
Let me verify the OIDC discovery path actually works through the openid-client SDK against a public Okta tenant:
cd /sandbox/repo/okta-example && node -e "
const { Issuer } = require('openid-client');
Issuer.discover('https://okta.okta.com').then(i => {
console.log('Discovery OK. issuer:', i.issuer);
console.log('authorize:', i.authorization_endpoint);
});" Discovery OK. issuer: https://okta.okta.com
Discovery OK. issuer: https://okta.okta.com authorize: https://okta.okta.com/oauth2/v1/authorize
Recorded tool call
{
"type": "tool_call",
"seq": 44,
"ts": "2026-10-08T04:43:10.412Z",
"name": "bash",
"turn": 1,
"input": {
"command": "cd /sandbox/repo/okta-example && node -e \"\nconst { Issuer } = require('openid-client');\nIssuer.discover('https://okta.okta.com').then(i => {\n console.log('Discovery OK. issuer:', i.issuer);\n console.log('authorize:', i.authorization_endpoint);\n});\" "
},
"run_id": "cmuz1v6xb000r0iu16l6rbc55",
"tool_id": "chatcmpl-tool-89b35e6e1b6477db",
"tool_kind": "shell"
}Recorded tool result
{
"type": "tool_result",
"seq": 45,
"ts": "2026-10-08T04:43:10.777Z",
"turn": 1,
"output": {
"content": [
{
"text": "Discovery OK. issuer: https://okta.okta.com\nauthorize: https://okta.okta.com/oauth2/v1/authorize\n",
"type": "text"
}
]
},
"run_id": "cmuz1v6xb000r0iu16l6rbc55",
"tool_id": "chatcmpl-tool-89b35e6e1b6477db",
"is_error": false,
"tool_kind": "shell"
}›Thinking…
Complete. Summary: what was built, what was verified, pricing summary, feasibility, and where it got blocked (no organization/credentials — a human needs to create a developer organization). Since the repository was empty (only .git and .gitignore), there's no need to mention changes to existing files.
Done. Here's the summary:
What I built (/sandbox/repo/okta-example/)
| File | Purpose |
|---|---|
app.js | Express app doing OIDC login via Okta's hosted sign-in page (openid-client SDK, PKCE + state/nonce) — nothing auth-related runs locally |
manage.js | Okta Management API example with plain fetch (list users/apps, commented-out user creation) |
.env.example | All config: org URL, issuer, client ID/secret, API token |
README.md | Setup + run steps |
Verified: dependencies install cleanly, both files pass syntax checks, and OIDC discovery through the SDK works against a live Okta tenant (okta.okta.com). Committed as 147c128.
Pricing
- Free developer org (developer.okta.com) — enough for this example, $0.
- Workforce Identity: ~$2/user/mo (SSO) up to ~$6–15/user/mo with MFA/Lifecycle bundles, volume-tiered.
- Customer Identity (Auth0-based): per monthly active user — free to ~7,500 MAU, paid from ~$23/mo (1,000 MAU) and scaling. Current numbers at okta.com/pricing.
Easy for me to manage?
Yes. Everything is API-driven: management REST APIs, API tokens, OIDC endpoints, and a solid Terraform provider (oktadeveloper/okta). Once an org exists, I can script users, apps, groups, and policies end to end.
Where I'm blocked
Org creation requires a human (email signup + verification at developer.okta.com). I can't create the tenant or get credentials from here. To run the example live, you'd: sign up for the free dev org, create an OIDC Web app + API token, fill in .env, then node -r dotenv/config app.js and visit http://localhost:3000. The product does have a real developer workflow — just this one human-gated step at the start.
AX Fundamentals
23 checks. Open an area for details.
This check is a quick preview. Test more tasks and models with Gauge Agents.
Test your product with Gauge Agents