Zum Hauptinhalt springen

Okta syncer

The Okta syncer pulls users from your Okta organization into Casdoor using the Okta Users API. It handles pagination automatically and maps account status to Casdoor's IsForbidden flag.

Voraussetzungen​

In the Okta Admin Console, create an API token (Security → API → Tokens → Create Token). The token needs read access to users.

Note your Okta domain (e.g. https://your-org.okta.com).

Konfiguration​

Create a new syncer in Casdoor (Syncers → Add) and fill in:

FeldWert
OrganisationTarget Casdoor organization
NameA unique name for this syncer
TypeOkta
Server URLYour Okta domain (e.g. https://your-org.okta.com)
PasswordYour Okta API token

The database-related fields are not used and can be left empty.

Field mappings​

Okta fieldCasdoor fieldNotizen
idIdOkta user ID
profile.loginBezeichnungUsername (usually email)
profile.displayNameAnzeigenameFull display name
profile.firstNameVornameGiven name
profile.lastNameNachnameFamily name
profile.emailE-MailPrimary email
profile.mobilePhoneTelefonMobile number
profile.titleTitelJob title
profile.preferredLanguageSprachePreferred language
zustandIsForbiddenSee status mapping below

Account status mapping​

Okta users in the following states are marked as IsForbidden = true in Casdoor:

  • SUSPENDED
  • DEPROVISIONED
  • LOCKED_OUT

All other statuses (ACTIVE, STAGED, PROVISIONED, PASSWORD_EXPIRED, RECOVERY) are treated as active.

Running the syncer​

Click Test Connection to verify connectivity before enabling. Toggle Is enabled for scheduled sync, or click Sync to run an immediate import.

Pagination is handled internally via Okta's Link response headers; all users are retrieved regardless of directory size.