Skip to content
Gauge

ax-check.com

Okta

okta.com

ax-check.com

Checked 8 October 2026

B

68/100

Agents need your login

Okta's pricing is clear, but no quickstart or API docs were tested

Pricing lists concrete per-user rates and limits with no login wall. Docs, SDKs, and CLI setup remain unassessed — 10 of 23 checklist items unassessed, 10 pass.

4 fixes to start with

Concrete changes, backed by what we found.

Onboarding

Give agents a clear login handoff and a way to resume setup.

Agents cannot progress through onboarding without human help. Provide an agent-accessible path through authentication and setup.

Docs

Add links to your product documentation and quickstart in /llms.txt.

llms.txt exists but is a huge link dump of Identity-101 articles, not an actionable docs index.

Docs

Tell agents where to start and organize the links in /llms.txt.

llms.txt offers no starting guidance or navigation structure beyond flat category link lists.

MCP

List every offered API, MCP, and skills surface in /llms.txt.

llms.txt never mentions Okta's API, MCP server, or SDKs despite these being offered.

Recorded coding sessions

Same task, 3 models, no okta.com account. Recorded 8 October 2026 on Pi.

3 recorded · 1m 10s

1m 10s · recorded

Session findings

Select a finding to see it in context.

piv0.84.2
modelQwen 3.8 Maxcwd/sandbox/repo
Help me build a simple example using Okta. Tell me how pricing works, and briefly tell me whether this product will be easy for you to manage. Let me know if you get blocked. If this product has no developer workflow you can act on, say so plainly and stop. Stay light: use the hosted product through its SDK or API. Do not start local service stacks or wait for long-running commands; if the quickstart requires either, say so plainly and stop.
Thinking…

I need to investigate further. Let me check the details.

The user is asking for help building a simple example using Okta, wants me to explain how pricing works, and tell them whether it's easy for me to manage. They're asking me to be upfront if there's no actionable developer workflow, to stay lightweight, and not to start up a local service stack.

Let me check the environment — do I have credentials? Without an actual Okta org/API token, I can't build something. Let me quickly check the environment variables and directory.

ls -la /sandbox/repo; env | grep -i -E 'okta|OKTA' ; echo "---"; curl -s -m 5 -o /dev/null -w "%{http_code}" https://developer.okta.com/ 2>&1 || echo "no network"
total 16
total 16
drwxr-xr-x 3 root root 4096 Sep 18 08:00 .
drwxr-xr-x 7 root root 4096 Oct  8 04:42 ..
drwxr-xr-x 8 root root 4096 Sep 24 20:05 .git
-rw-r--r-- 1 root root  408 Sep 18 08:00 .gitignore
---
200
Thinking…

Network is working. No Okta credentials. Can't create an actual Okta org without user credentials — creating a developer org requires a signup via email verification, which I can't do. So unless the user provides an org URL + API token (and possibly a client ID/secret), I'll be blocked on the "running a live example" part.

Still, I can write the example code (SDK-based, using hosted login / API) and explain the pricing and manageability. That's reasonable. Let me check what's in the repo (it's empty). Build a minimal example: a Node.js app using the Okta SDK? Or use okta-auth-js + express? Keep it lightweight: a small Express app using OIDC redirect via openid-client, or Okta's own SDK (@okta/okta-auth-js is for SPAs). The simplest "use a hosted product via SDK/API" example: a Node script that calls the Okta Management API (list users) with @okta/okta-sdk-nodejs, or an OIDC web login example using openid-client.

I'll provide both, but keep it simple: one directory containing the OIDC login example (the typical "Okta quickstart"). Can test the parts that don't require credentials (install dependencies, syntax check) — installing npm packages should be fine, quick. Let me do that.

Pricing: Okta is per user per month (Workforce Identity Cloud): roughly $2–15/user/month depending on product (SSO around $2/user/month? Actual list prices: SSO $2, MFA $3, Adaptive SSO $6, Lifecycle Management $4, Advanced Server Access etc.). Customer Identity (Auth0, now part of Okta) is MAU-based: free up to 7,500 MAU (B2C), then tiered pricing per MAU ($23/month for up to 1,000? Actual Auth0 pricing: Free up to 7,500 MAU; B2C Essentials starts at $23/month for up to 1,000 MAU and scales). Developer orgs are free (developer.okta.com — free developer sandbox, 1,000 MAU? Historically "free up to 1,000 MAU", now a developer org with limits). I should be honest about approximate pricing and point them to okta.com/pricing.

Manageability: fine for me — API-token-driven, Terraform provider, well-documented REST APIs. However, creating an org requires a human to sign up via email verification, so that part I can't do.

Plan: write the example files, npm install and run a syntax check, and don't run the server (it's long-running — don't start it). State that I'll be blocked on live testing without credentials.

Network access works, but I have no Okta credentials or org in this environment — so I can build the example fully, but can't run it live against a real Okta tenant without you providing one. Here's the plan and the answer to your questions first:

Pricing (approximate, see okta.com/pricing for current numbers):

  • Okta Workforce Identity (SSO/MFA for employees): per-user-per-month, ~$2/user/mo for SSO, ~$6–15/user/mo with MFA/Lifecycle Management bundles. Volume-tiered.
  • Okta Customer Identity (Auth0-based): per monthly active user (MAU). Free up to ~7,500 MAU; paid tiers start around $23/mo for 1,000 MAU and scale with usage.
  • Developer orgs are free (developer.okta.com) — that's what I'd use for an example, so cost is $0 for this.

Easy for me to manage? Yes, mostly: everything is API-driven (management APIs, OIDC endpoints, API tokens, a mature Terraform provider), so I can script provisioning of apps/users/policies. The one hard blocker: creating an org requires a human (email signup + verification). After that, I'm unblocked given an org URL + API token.

Now the example — a minimal Node.js app doing OIDC login against an Okta-hosted sign-in page, plus a management-API script. No local stacks, no long-running commands.

mkdir -p /sandbox/repo/okta-example && cd /sandbox/repo/okta-example && npm init -y >/dev/null && npm install express openid-client@^5 --no-audit --no-fund 2>&1 | tail -2
added 74 packages in 5s

added 74 packages in 5s
Thinking…

I'll create the files: app.js (OIDC login using openid-client v5), manage.js (calling the management API with fetch), README, .env.example. After that, I'll run syntax checks with node --check. I won't start the server.

File edits

1 file

Completed
Writtenokta-example/app.jsView changes

/sandbox/repo/okta-example/app.js

Written content · previous contents were not recorded

// Minimal Okta OIDC example: sign in via Okta's *hosted* sign-in page.
// No local auth stack — Okta hosts login, MFA, consent. This app just
// speaks standard OpenID Connect using openid-client.
//
// Setup (in Okta Admin Console -> Applications -> Create App Integration):
// 1. Type: Web, Sign-in method: OIDC
// 2. Redirect URI: http://localhost:3000/callback
// 3. Copy Client ID + Client Secret into .env
const express = require("express");
const session = require("express-session");
const { Issuer, generators } = require("openid-client");
const app = express();
app.use(
session({
secret: process.env.SESSION_SECRET || "dev-secret",
resave: false,
saveUninitialized: true,
cookie: { secure: false },
})
);
let client; // initialized async below
async function getClient() {
if (client) return client;
const issuer = await Issuer.discover(process.env.OKTA_ISSUER);
client = new issuer.Client({
client_id: process.env.OKTA_CLIENT_ID,
client_secret: process.env.OKTA_CLIENT_SECRET,
redirect_uris: ["http://localhost:3000/callback"],
response_types: ["code"],
});
return client;
}
app.get("/", (req, res) => {
if (req.session.user) {
res.send(`<pre>Logged in as:\n${JSON.stringify(req.session.user, null, 2)}</pre>
<a href="/logout">Log out</a>`);
} else {
res.send('<a href="/login">Log in with Okta</a>');
}
});
app.get("/login", async (req, res) => {
const c = await getClient();
const code_verifier = generators.codeVerifier();
req.session.code_verifier = code_verifier;
const url = c.authorizationUrl({
scope: "openid profile email",
code_challenge: generators.codeChallenge(code_verifier),
code_challenge_method: "S256",
state: generators.state(),
nonce: generators.nonce(),
});
req.session.state = new URL(url).searchParams.get("state");
res.redirect(url); // user is handed off to Okta's hosted sign-in page
});
app.get("/callback", async (req, res) => {
const c = await getClient();
const tokenSet = await c.callback(
"http://localhost:3000/callback",
c.callbackParams(req),
{
code_verifier: req.session.code_verifier,
state: req.session.state,
}
);
const claims = tokenSet.claims();
req.session.user = {
sub: claims.sub,
email: claims.email,
name: claims.name,
id_token_issued_at: claims.iat,
};
res.redirect("/");
});
app.get("/logout", (req, res) => {
req.session.destroy(() => res.redirect("/"));
});
if (require.main === module) {
if (!process.env.OKTA_ISSUER) {
console.error("Missing OKTA_ISSUER — copy .env.example to .env first.");
process.exit(1);
}
app.listen(3000, () => console.log("http://localhost:3000"));
}
module.exports = app;

File edits

1 file

Completed
Writtenokta-example/manage.jsView changes

/sandbox/repo/okta-example/manage.js

Written content · previous contents were not recorded

// Minimal Okta Management API example — plain REST + fetch, no SDK needed.
// Shows the workflow an agent/script can act on with just an API token:
// list users, list apps, create a test user.
//
// Token: Okta Admin Console -> Security -> API -> Tokens -> Create Token
const BASE = process.env.OKTA_ORG; // e.g. https://dev-123456.okta.com
const TOKEN = process.env.OKTA_API_TOKEN;
if (!BASE || !TOKEN) {
console.error("Set OKTA_ORG and OKTA_API_TOKEN (see .env.example).");
process.exit(1);
}
async function okta(path, opts = {}) {
const res = await fetch(`${BASE}/api/v1${path}`, {
...opts,
headers: {
Authorization: `SSWS ${TOKEN}`,
Accept: "application/json",
"Content-Type": "application/json",
...(opts.headers || {}),
},
});
if (!res.ok) throw new Error(`${res.status}: ${await res.text()}`);
return res.status === 204 ? null : res.json();
}
(async () => {
const users = await okta("/users?limit=5");
console.log(
"Users:",
users.map((u) => `${u.profile.login} (${u.status})`)
);
const apps = await okta("/apps?limit=5");
console.log("Apps:", apps.map((a) => `${a.label} [${a.status}]`));
// Uncomment to create a test user (deactivate/delete later to stay clean):
// const created = await okta("/users?activate=false", {
// method: "POST",
// body: JSON.stringify({
// profile: {
// firstName: "Test", lastName: "User",
// email: "test.user@example.com", login: "test.user@example.com",
// },
// }),
// });
// console.log("Created:", created.id);
})();

File edits

1 file

Completed
Writtenokta-example/.env.exampleView changes

/sandbox/repo/okta-example/.env.example

Written content · previous contents were not recorded

# From your free Okta developer org (https://developer.okta.com)
OKTA_ORG=https://dev-123456.okta.com
# Issuer = org URL + /oauth2/default (the default authorization server)
OKTA_ISSUER=https://dev-123456.okta.com/oauth2/default
# From Admin Console -> Applications -> your OIDC Web app
OKTA_CLIENT_ID=your-client-id
OKTA_CLIENT_SECRET=your-client-secret
# From Admin Console -> Security -> API -> Tokens
OKTA_API_TOKEN=your-api-token
SESSION_SECRET=change-me

File edits

1 file

Completed
Writtenokta-example/README.mdView changes

/sandbox/repo/okta-example/README.md

Written content · previous contents were not recorded

# Okta minimal example
Two small scripts, both using Okta's *hosted* services — nothing runs auth locally.
| File | What it does | Auth needed |
|---|---|---|
| `app.js` | Express app that logs users in via Okta's hosted sign-in page (OIDC + PKCE) | Client ID/secret from an OIDC Web app |
| `manage.js` | Calls the Okta Management API (list users/apps) with plain `fetch` | API token |
## Run
1. Create a **free** developer org at https://developer.okta.com (needs human email signup).
2. `cp .env.example .env` and fill in values (see comments in the file).
3. OIDC login demo: `node -r dotenv/config app.js` → open http://localhost:3000
4. Management API demo: `node -r dotenv/config manage.js`
## Notes
- OIDC app setup: Admin Console → Applications → Create App Integration → Web → OIDC, redirect URI `http://localhost:3000/callback`.
- API tokens: Admin Console → Security → API → Tokens.
- A Terraform provider (`oktadeveloper/okta`) exists if you want infra-as-code for apps/users/policies.
Thinking…

I need to verify the dependencies and syntax by installing express-session and dotenv, then running syntax checks and testing the client discovery flow against Okta's public metadata endpoint to confirm the network path works without requiring credentials.

cd /sandbox/repo/okta-example && npm install express-session dotenv --no-audit --no-fund 2>&1 | tail -1 && node --check app.js && node --check manage.js && echo "syntax OK" && curl -s -m 8 https://okta.com/.well-known/openid-configuration | head -c 300; echo
added 9 packages in 2s
added 9 packages in 2s
syntax OK

Thinking…

The curl to okta.com/.well-known didn't return anything — okta.com itself might not be providing it. Let me try developer.okta.com, or use a known developer org. Actually, let me try https://developer.okta.com/.well-known/openid-configuration. Or a sample org. I'll try it quickly.

curl -s -m 8 https://developer.okta.com/.well-known/openid-configuration | head -c 200; echo; curl -s -m 8 https://okta.okta.com/.well-known/openid-configuration | head -c 200; echo
<!DOCTYPE html>
<!DOCTYPE html>
<html lang="en-US">
  <head>
    <meta charset="utf-8">
    <meta name="viewport" content="width=device-width,initial-scale=1">
    <title>404 Page Not Found | Okta Developer</title>
 
{"issuer":"https://okta.okta.com","authorization_endpoint":"https://okta.okta.com/oauth2/v1/authorize","token_endpoint":"https://okta.okta.com/oauth2/v1/token","userinfo_endpoint":"https://okta.okta.c
Thinking…

OIDC discovery has been verified against an actually existing public Okta organization (okta.okta.com), and it's been confirmed that the discovery flow in app.js works. Without credentials, there's nothing more that can be run. I'll commit with git. Let me check the git status of the repository — there's a .git and a .gitignore. I'll commit.

cd /sandbox/repo && cat .gitignore | head; git add okta-example/app.js okta-example/manage.js okta-example/README.md okta-example/.env.example okta-example/package.json okta-example/package-lock.json 2>/dev/null; git -c user.email=agent@local -c user.name=agent commit -m "Add minimal Okta OIDC + Management API example" -q && git log --oneline -1
# Keep generated and vendored files out of source diffs.
# Keep generated and vendored files out of source diffs.

# Logs / OS cruft
*.log
.DS_Store

# JavaScript / TypeScript
node_modules/
.next/
dist/
147c128 Add minimal Okta OIDC + Management API example
Thinking…

Also, I can verify the Issuer.discover flow by pointing it at okta.okta.com — a simple node one-liner, not something that runs for a long time. This will prove that the SDK path works. Let's do it.

Let me verify the OIDC discovery path actually works through the openid-client SDK against a public Okta tenant:

cd /sandbox/repo/okta-example && node -e "
const { Issuer } = require('openid-client');
Issuer.discover('https://okta.okta.com').then(i => {
  console.log('Discovery OK. issuer:', i.issuer);
  console.log('authorize:', i.authorization_endpoint);
});" 
Discovery OK. issuer: https://okta.okta.com
Discovery OK. issuer: https://okta.okta.com
authorize: https://okta.okta.com/oauth2/v1/authorize
Thinking…

Complete. Summary: what was built, what was verified, pricing summary, feasibility, and where it got blocked (no organization/credentials — a human needs to create a developer organization). Since the repository was empty (only .git and .gitignore), there's no need to mention changes to existing files.

Done. Here's the summary:

What I built (/sandbox/repo/okta-example/)

FilePurpose
app.jsExpress app doing OIDC login via Okta's hosted sign-in page (openid-client SDK, PKCE + state/nonce) — nothing auth-related runs locally
manage.jsOkta Management API example with plain fetch (list users/apps, commented-out user creation)
.env.exampleAll config: org URL, issuer, client ID/secret, API token
README.mdSetup + run steps

Verified: dependencies install cleanly, both files pass syntax checks, and OIDC discovery through the SDK works against a live Okta tenant (okta.okta.com). Committed as 147c128.

Pricing

  • Free developer org (developer.okta.com) — enough for this example, $0.
  • Workforce Identity: ~$2/user/mo (SSO) up to ~$6–15/user/mo with MFA/Lifecycle bundles, volume-tiered.
  • Customer Identity (Auth0-based): per monthly active user — free to ~7,500 MAU, paid from ~$23/mo (1,000 MAU) and scaling. Current numbers at okta.com/pricing.

Easy for me to manage?

Yes. Everything is API-driven: management REST APIs, API tokens, OIDC endpoints, and a solid Terraform provider (oktadeveloper/okta). Once an org exists, I can script users, apps, groups, and policies end to end.

Where I'm blocked

Org creation requires a human (email signup + verification at developer.okta.com). I can't create the tenant or get credentials from here. To run the example live, you'd: sign up for the free dev org, create an OIDC Web app + API token, fill in .env, then node -r dotenv/config app.js and visit http://localhost:3000. The product does have a real developer workflow — just this one human-gated step at the start.

AX Fundamentals

23 checks. Open an area for details.

This check is a quick preview. Test more tasks and models with Gauge Agents.

Test your product with Gauge Agents

AX Check by Gauge