# AX Check: okta.com
Checked 2026-10-08.

Okta's pricing is clear, but no quickstart or API docs were tested
Pricing lists concrete per-user rates and limits with no login wall. Docs, SDKs, and CLI setup remain unassessed — 10 of 23 checklist items unassessed, 10 pass.

## Onboarding needs a login

## Coding sessions
All three independent sessions (DeepSeek V4.1 Flash, Kimi K3, Qwen 3.8 Max) completed and found clear, concrete pricing on okta.com/pricing, citing specific per-user monthly rates, tiers, and billing assumptions like annual billing and free dev orgs. None hit a login wall for pricing info.

### DeepSeek V4.1 Flash
[View public run](https://agents.withgauge.com/p/runs/86fd4b55-bec6-4bc9-8711-10957a60515c) · [Read transcript](https://www.ax-check.com/okta.com/sessions/deepseek.json)
Pricing section names concrete figures ($6/$14/$17 per user/mo, Auth0 MAU tiers) along with assumptions (Workforce vs Customer Identity platform, annual billing, free dev org for dev/test only) and tells the user to confirm current numbers at okta.com/pricing.
#### End-to-end onboarding
- **End-to-end onboarding not demonstrated**: The agent built a working Okta SDK example (client construction, listUsers/createUser method wiring, syntax validation) but never obtained real Okta credentials (org URL + API token) and never made a live authenticated call to the hosted Okta API. It explicitly stated it would not create an Okta account on the user's behalf and ran the script only to confirm it fails gracefully without credentials.
  Event 122:

  ```text
  Blocker: end-to-end execution needs a real `OKTA_ORG_URL` + `OKTA_API_TOKEN`. Neither is present in this environment, and I won't create an Okta account on your behalf.
  ```
  Event 108:

  ```text
  === no creds (expected graceful failure) ===
  Okta API call failed: Missing OKTA_ORG_URL. Set OKTA_ORG_URL and OKTA_API_TOKEN (see README.md).
  exit=1
  ```
  Event 112:

  ```text
  client OK, baseUrl = https://dev-123456.okta.com
  userApi.listUsers is function
  userApi.createUser is function
  authorizationMode = SSWS
  ```

#### Hallucinated URLs
None identified in this transcript.

#### Blockers
- **No Okta credentials available to run the example live**: The sandbox had no OKTA_ORG_URL or OKTA_API_TOKEN, and the agent correctly declined to self-provision an Okta account/org, since doing so would require human signup. This is a session/environment limitation, not a product defect — Okta requires account creation and an API token before any API call can succeed, which is normal for this type of product.
  Event 122:

  ```text
  Blocker: end-to-end execution needs a real `OKTA_ORG_URL` + `OKTA_API_TOKEN`. Neither is present in this environment, and I won't create an Okta account on your behalf.
  ```
  Event 108:

  ```text
  Okta API call failed: Missing OKTA_ORG_URL. Set OKTA_ORG_URL and OKTA_API_TOKEN (see README.md).
  ```

#### Suggested Changes
None identified in this transcript.

### Kimi K3
[View public run](https://agents.withgauge.com/p/runs/5a229676-f619-45ce-b4c1-25e041711146) · [Read transcript](https://www.ax-check.com/okta.com/sessions/kimi.json)
Pricing section cites source (okta.com/pricing, fetched seq 12) and names assumptions: per-user/month billed annually, Starter ~$6/user/mo, Essentials ~$17/user/mo, free dev org vs production billing, free 30-day trial, separate Auth0/Customer Identity MAU pricing.
#### End-to-end onboarding
- **Onboarding needs a login**: The agent never obtained Okta credentials. It wrote a working Node.js script against the official Okta SDK but the script only reached a credential-check guard clause and exited with an error because OKTA_DOMAIN and OKTA_API_TOKEN were never set. No account signup, token creation, or authenticated API call occurred — the agent explicitly states it is blocked on the manual browser-based signup/email verification step and asks the user to paste credentials.
  Event 24:

  ```text
  Missing OKTA_DOMAIN and/or OKTA_API_TOKEN. See header comments.
  exit=1
  
  ```
  Event 29:

  ```text
  Okta has no anonymous sandbox: the developer workflow starts with creating a free org at developer.okta.com/signup, which requires a browser form + email verification, and I have no `OKTA_DOMAIN`/`OKTA_API_TOKEN` in this environment.
  ```
  Event 29:

  ```text
  If you paste an org domain + API token (or set the env vars), `node okta-demo.js` will run end-to-end immediately.
  ```

#### Hallucinated URLs
None identified in this transcript.

#### Blockers
- **No self-service way to create an Okta org or token**: Okta requires a human to sign up for a developer org via a browser form with email verification, then manually generate an API token in the Admin Console. This is normal product behavior (not a defect) but it fully blocked the agent from running any authenticated API call in this session, since no credentials existed in the sandbox environment.
  Event 29:

  ```text
  Okta has no anonymous sandbox: the developer workflow starts with creating a free org at developer.okta.com/signup, which requires a browser form + email verification, and I have no `OKTA_DOMAIN`/`OKTA_API_TOKEN` in this environment.
  ```

#### Suggested Changes
None identified in this transcript.

### Qwen 3.8 Max
[View public run](https://agents.withgauge.com/p/runs/5e1cf52b-ec05-4aae-aa53-a4b62d921a92) · [Read transcript](https://www.ax-check.com/okta.com/sessions/qwen.json)
Final output gives concrete pricing (free dev org $0, Workforce Identity ~$2–15/user/mo, Customer Identity MAU tiers from ~$23/mo) tied to named plans/assumptions (free dev tier, SSO vs MFA bundles, MAU volume).
#### End-to-end onboarding
- **Onboarding needs a login**: The agent never obtained real Okta tenant credentials. It built a local Node.js example (app.js, manage.js) referencing placeholder env vars, but had no actual Okta org, client ID/secret, or API token. The only live network calls were unauthenticated OIDC discovery checks against Okta's public/demo tenant (okta.okta.com), which require no credentials and did not exercise any authenticated operation like creating a user or app. The agent explicitly states org creation requires human email signup and stops there.
  Event 47:

  ```text
  **Org creation requires a human** (email signup + verification at developer.okta.com). I can't create the tenant or get credentials from here.
  ```
  Event 45:

  ```text
  Discovery OK. issuer: https://okta.okta.com
  authorize: https://okta.okta.com/oauth2/v1/authorize
  ```
  Event 7:

  ```text
  The one hard blocker: **creating an org requires a human** (email signup + verification). After that, I'm unblocked given an org URL + API token.
  ```

#### Hallucinated URLs
None identified in this transcript.

#### Blockers
- **No self-service way to create an Okta tenant/org**: Okta requires a human to sign up for a developer org via email verification before any API token, client ID, or client secret can be obtained. This is normal product behavior (account provisioning gated behind identity verification), not a defect, but it fully prevented the agent from running any authenticated operation against a real Okta tenant in this session.
  Event 47:

  ```text
  **Org creation requires a human** (email signup + verification at developer.okta.com). I can't create the tenant or get credentials from here.
  ```
  Event 7:

  ```text
  so I can build the example fully, but can't run it live against a real Okta tenant without you providing one
  ```

#### Suggested Changes
- **Offer a self-service sandbox credential path that skips email signup for quick agent evaluation**: The agent could reach only an unauthenticated public tenant (okta.okta.com) for OIDC discovery and had no way to provision even a throwaway org or token without a human completing email verification at developer.okta.com. If a scoped, ephemeral sandbox credential were available via CLI or API, agents could demonstrate a full authenticated workflow (create user, create app) without human intervention. Check this by having an agent attempt to request a sandbox token purely through API/CLI calls and verifying it can then call something like /api/v1/users successfully.
  Event 47:

  ```text
  **Org creation requires a human** (email signup + verification at developer.okta.com). I can't create the tenant or get credentials from here.
  ```

### Task given to each agent
Help me build a simple example using Okta. Tell me how pricing works, and briefly tell me whether this product will be easy for you to manage. Let me know if you get blocked. If this product has no developer workflow you can act on, say so plainly and stop. Stay light: use the hosted product through its SDK or API. Do not start local service stacks or wait for long-running commands; if the quickstart requires either, say so plainly and stop.

No product credentials were supplied and no purchases were authorized.

## Score: B · 68/100 (provisional)
Grades come from completed site checks. Coding sessions and skipped checks do not affect the score.

### Clarity
- **Failed** — llms.txt provides an actionable documentation index

  ```text
  llms.txt exists but is a huge link dump of Identity-101 articles, not an actionable docs index.
  ```

- **Failed** — llms.txt provides navigation guidance

  ```text
  llms.txt offers no starting guidance or navigation structure beyond flat category link lists.
  ```

- **Failed** — llms.txt mentions offered API, MCP, and skills

  ```text
  llms.txt never mentions Okta's API, MCP server, or SDKs despite these being offered.
  ```

- **Pass** — Homepage answers Markdown requests

  ```text
  Homepage returned text/markdown (200) when requested with Accept: text/markdown.
  ```

- **Pass** — A compact guide representation exists

  ```text
  Homepage served text/markdown (2813 tokens) via content negotiation, a compact representation.
  ```

- **Pass** — A focused guide is directly retrievable

  ```text
  llms.txt and negotiated Markdown pages (e.g. MCP article) are directly retrievable.
  ```

- **Pass** — Equivalent instructions fit a token budget

  ```text
  Homepage Markdown is 2813 tokens, well under 8000 and below the HTML extraction.
  ```

- **Pass** — Product-docs links survive format changes

  ```text
  Markdown homepage retains product and docs links like developer.okta.com and product pages.
  ```

- **Skipped** — The compact guide is independently actionable

  ```text
  No compact agent guide fetched; llms.txt is a large link index, not an actionable workflow.
  ```

- **Pass** — Install and next-step links resolve

  ```text
  Free-trial and llms.txt-linked pages fetched successfully; no broken install or next-step links observed.
  ```


### Onboarding
- **Skipped** — Docs lead to a relevant quickstart

  ```text
  No developer docs or quickstart pages were fetched; only llms.txt and free-trial pages.
  ```

- **Skipped** — Installation commands are extractable

  ```text
  No installation or CLI guide pages were fetched in this bundle.
  ```

- **Skipped** — Code examples are available without interaction

  ```text
  No docs or code-example pages were fetched; only marketing and trial pages.
  ```

- **Skipped** — Prerequisites and auth boundaries are explicit

  ```text
  No API or auth documentation pages were fetched to show prerequisites.
  ```


### Pricing
- **Pass** — Pricing is readable without interaction

  ```text
  Okta pricing page renders plan tiers and prices as readable text without interaction.
  ```

- **Pass** — Prices are stated, not gated

  ```text
  Starter $6, Core Essentials $14, Essentials $17 per user/month stated; Enterprise contact-sales.
  ```

- **Pass** — Pricing units and limits are explicit

  ```text
  Prices per user/month, billed annually, $1,500 minimum; CI $3K/month and MAU limits.
  ```

- **Pass** — Agents identify pricing and its assumptions

  ```text
  3 of 3 sessions were judged on pricing; 0 fell short. DeepSeek V4.1 Flash: Pricing section names concrete figures ($6/$14/$17 per user/mo, Auth0 MAU tiers) along with assumptions (Workforce vs Customer Identity platform, annual billing, free dev org for dev/test only) and tells the user to confirm current numbers at okta.com/pricing. Kimi K3: Pricing section cites source (okta.com/pricing, fetched seq 12) and names assumptions: per-user/month billed annually, Starter ~$6/user/mo, Essentials ~$17/user/mo, free dev org vs production billing, free 30-day trial, separate Auth0/Customer Identity MAU pricing. Qwen 3.8 Max: Final output gives concrete pricing (free dev org $0, Workforce Identity ~$2–15/user/mo, Customer Identity MAU tiers from ~$23/mo) tied to named plans/assumptions (free dev tier, SSO vs MFA bundles, MAU volume). This behavioural item does not affect the fast grade.
  ```


### Activation
- **Skipped** — An API reference or OpenAPI spec is reachable

  ```text
  No Okta API reference or OpenAPI spec was fetched; only MCP/identity-101 articles appear.
  ```

- **Skipped** — An MCP server is documented and well-formed

  ```text
  help.okta.com MCP pages returned only 'Okta Docs' with no server details.
  ```

- **Skipped** — A CLI install path is documented

  ```text
  No Okta CLI install guide or command documentation was fetched in this sample.
  ```

- **Skipped** — SDK packages resolve on their registries

  ```text
  No Okta SDK package registry lookup result was supplied for verification.
  ```

- **Skipped** — Agent skills are published

  ```text
  No Okta agent skills documentation or repository was fetched in this sample.
  ```



[Full report data](https://www.ax-check.com/okta.com/report.json)
