Reference
okta Dialect
See which types this Dialect interprets and which architectural facts its Rules can establish.
On this pageOverview
Version and compatibility
Version: 0.1.0.
Provider bindings and declared compatibility
okta/okta:= 7.0.0.
Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.
okta.concept.application-configurationSource-
Claims, features, redirects, scopes, or access policy supporting an app integration.
-
Used by 13 Rules
app-access-policy-assignmentapp-featuresapp-features-lookupapp-federated-claimapp-federated-claim-lookupapp-oauth-api-scopeapp-oauth-post-logout-redirect-uriapp-oauth-redirect-uriapp-saml-app-settingsapp-sign-on-policy-rule-lookupapp-signon-policyapp-signon-policy-lookupapp-signon-policy-rule
okta.concept.authentication-configurationSource-
Authenticator, CAPTCHA, behavior, trusted-origin, or threat configuration supporting authentication.
-
Used by 18 Rules
authenticatorauthenticator-lookupauthenticator-method-webauthnauthenticator-method-webauthn-lookupauthenticator-webauthn-custom-aaguidauthenticator-webauthn-custom-aaguids-lookupbehaviorbehavior-lookupcaptchacaptcha-lookuporg-captchaorg-captcha-lookuprealm-assignmentrealm-assignment-lookupthreat-insight-settingsthreat-insight-settings-lookuptrusted-origintrusted-origin-lookup
-
An Okta custom Authorization Server that mints OAuth and OIDC tokens.
-
A claim, scope, policy, rule, or trusted-server association supporting an Authorization Server.
okta.concept.domain-configurationSource-
Certificate or verification configuration supporting an Okta custom domain.
-
Used by
domain-certificate,domain-verification. okta.concept.external-identity-providerSource-
An external OIDC, SAML, or social Identity Provider trusted by Okta.
-
Used by 6 Rules
okta.concept.hook-configurationSource-
Verification or key configuration supporting an Okta hook.
-
Used by
event-hook-verification,hook-key,hook-key-lookup. okta.concept.identity-applicationSource-
An application or relying-party client registered with an identity platform.
-
Used by 23 Rules
api-service-integrationapi-service-integration-lookupapp-access-policy-assignmentapp-auto-loginapp-basic-authapp-bookmarkapp-featuresapp-features-lookupapp-federated-claimapp-federated-claim-lookupapp-lookupapp-oauthapp-oauth-api-scopeapp-oauth-lookupapp-oauth-post-logout-redirect-uriapp-oauth-redirect-uriapp-samlapp-saml-app-settingsapp-saml-lookupapp-secure-password-storeapp-shared-credentialsapp-swaapp-three-field
okta.concept.identity-domainSource-
A custom domain exposing an Okta-hosted identity endpoint.
-
Used by 4 Rules
okta.concept.identity-event-extensionSource-
An Okta event or inline hook integrating an external callback into an identity lifecycle.
-
Used by 4 Rules
okta.concept.identity-log-streamSource-
An Okta System Log stream delivering security events to an external destination.
-
Used by
log-stream,log-stream-lookup. okta.concept.identity-realmSource-
An Okta Realm partitioning users within an organization.
-
Used by 4 Rules
okta.concept.identity-tenantSource-
An Okta organization acting as an identity tenant boundary.
-
Used by
org-configuration,org-metadata-lookup. okta.concept.network-zoneSource-
A network location boundary used by Okta authentication and access decisions.
-
Used by
network-zone,network-zone-lookup. okta.concept.provisioning-connectionSource-
An Okta application provisioning connection to an external system.
-
Used by
app-connection,app-connection-lookup. okta.concept.security-events-providerSource-
A Security Events Provider supplying shared security signals to Okta.
-
Used by
security-events-provider,security-events-provider-lookup.
Open a Rule for its declared behavior and source. Matching, emission resolution and composition define how evidence can establish it.
okta.rule.api-service-integration-lookup Source
Matches data instances of okta_api_service_integration.
Classification: okta.concept.identity-application.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
okta.rule.api-service-integration Source
Matches resource instances of okta_api_service_integration.
Classification: okta.concept.identity-application.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
okta.rule.app-access-policy-assignment Source
Matches resource instances of okta_app_access_policy_assignment.
Classification: okta.concept.application-configuration.
Contributions
- targets
okta.concept.identity-applicationthroughsource.app_id.
Conditions, identity and resolution
Contribution through source.app_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
okta.rule.app-auto-login Source
Matches resource instances of okta_app_auto_login.
Classification: okta.concept.identity-application.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
okta.rule.app-basic-auth Source
Matches resource instances of okta_app_basic_auth.
Classification: okta.concept.identity-application.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
okta.rule.app-bookmark Source
Matches resource instances of okta_app_bookmark.
Classification: okta.concept.identity-application.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
okta.rule.app-connection-lookup Source
Matches data instances of okta_app_connection.
Classification: okta.concept.provisioning-connection.
okta.rule.app-connection Source
Matches resource instances of okta_app_connection.
Classification: okta.concept.provisioning-connection.
okta.rule.app-features-lookup Source
Matches data instances of okta_app_features.
Classification: okta.concept.application-configuration.
Contributions
- targets
okta.concept.identity-applicationthroughsource.app_id.
Conditions, identity and resolution
Contribution through source.app_id
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.idmatch.strategy:"exact"
okta.rule.app-features Source
Matches resource instances of okta_app_features.
Classification: okta.concept.application-configuration.
Contributions
- targets
okta.concept.identity-applicationthroughsource.app_id.
Conditions, identity and resolution
Contribution through source.app_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
okta.rule.app-federated-claim-lookup Source
Matches data instances of okta_app_federated_claim.
Classification: okta.concept.application-configuration.
Contributions
- targets
okta.concept.identity-applicationthroughsource.app_id.
Conditions, identity and resolution
Contribution through source.app_id
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.idmatch.strategy:"exact"
okta.rule.app-federated-claim Source
Matches resource instances of okta_app_federated_claim.
Classification: okta.concept.application-configuration.
Contributions
- targets
okta.concept.identity-applicationthroughsource.app_id.
Conditions, identity and resolution
Contribution through source.app_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
okta.rule.app-oauth-api-scope Source
Matches resource instances of okta_app_oauth_api_scope.
Classification: okta.concept.application-configuration.
Contributions
- targets
okta.concept.identity-applicationthroughsource.app_id.
Conditions, identity and resolution
Contribution through source.app_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
okta.rule.app-oauth-post-logout-redirect-uri Source
Matches resource instances of okta_app_oauth_post_logout_redirect_uri.
Classification: okta.concept.application-configuration.
Contributions
- targets
okta.concept.identity-applicationthroughsource.app_id.
Conditions, identity and resolution
Contribution through source.app_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
okta.rule.app-oauth-redirect-uri Source
Matches resource instances of okta_app_oauth_redirect_uri.
Classification: okta.concept.application-configuration.
Contributions
- targets
okta.concept.identity-applicationthroughsource.app_id.
Conditions, identity and resolution
Contribution through source.app_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
okta.rule.app-oauth-lookup Source
Matches data instances of okta_app_oauth.
Classification: okta.concept.identity-application.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
okta.rule.app-oauth Source
Matches resource instances of okta_app_oauth.
Classification: okta.concept.identity-application.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
okta.rule.app-saml-app-settings Source
Matches resource instances of okta_app_saml_app_settings.
Classification: okta.concept.application-configuration.
Contributions
- targets
okta.concept.identity-applicationthroughsource.app_id.
Conditions, identity and resolution
Contribution through source.app_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
okta.rule.app-saml-lookup Source
Matches data instances of okta_app_saml.
Classification: okta.concept.identity-application.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
okta.rule.app-saml Source
Matches resource instances of okta_app_saml.
Classification: okta.concept.identity-application.
Relations
okta.relation.uses-inline-hook: targetsokta.concept.identity-event-extensionthroughsource.inline_hook_id.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
Relation through source.inline_hook_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
okta.rule.app-secure-password-store Source
Matches resource instances of okta_app_secure_password_store.
Classification: okta.concept.identity-application.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
okta.rule.app-shared-credentials Source
Matches resource instances of okta_app_shared_credentials.
Classification: okta.concept.identity-application.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
okta.rule.app-sign-on-policy-rule-lookup Source
Matches data instances of okta_app_sign_on_policy_rule.
Classification: okta.concept.application-configuration.
okta.rule.app-signon-policy-rule Source
Matches resource instances of okta_app_signon_policy_rule.
Classification: okta.concept.application-configuration.
okta.rule.app-signon-policy-lookup Source
Matches data instances of okta_app_signon_policy.
Classification: okta.concept.application-configuration.
okta.rule.app-signon-policy Source
Matches resource instances of okta_app_signon_policy.
Classification: okta.concept.application-configuration.
okta.rule.app-swa Source
Matches resource instances of okta_app_swa.
Classification: okta.concept.identity-application.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
okta.rule.app-three-field Source
Matches resource instances of okta_app_three_field.
Classification: okta.concept.identity-application.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
okta.rule.app-lookup Source
Matches data instances of okta_app.
Classification: okta.concept.identity-application.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
okta.rule.auth-server-claim-default Source
Matches resource instances of okta_auth_server_claim_default.
Classification: okta.concept.authorization-server-configuration.
Contributions
- targets
okta.concept.authorization-serverthroughsource.auth_server_id.
Conditions, identity and resolution
Contribution through source.auth_server_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
okta.rule.auth-server-claim-lookup Source
Matches data instances of okta_auth_server_claim.
Classification: okta.concept.authorization-server-configuration.
Contributions
- targets
okta.concept.authorization-serverthroughsource.auth_server_id.
Conditions, identity and resolution
Contribution through source.auth_server_id
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.idmatch.strategy:"exact"
okta.rule.auth-server-claim Source
Matches resource instances of okta_auth_server_claim.
Classification: okta.concept.authorization-server-configuration.
Contributions
- targets
okta.concept.authorization-serverthroughsource.auth_server_id.
Conditions, identity and resolution
Contribution through source.auth_server_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
okta.rule.auth-server-default Source
Matches resource instances of okta_auth_server_default.
Classification: okta.concept.authorization-server.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
okta.rule.auth-server-policy-rule Source
Matches resource instances of okta_auth_server_policy_rule.
Classification: okta.concept.authorization-server-configuration.
Contributions
- targets
okta.concept.authorization-serverthroughsource.auth_server_id.
Conditions, identity and resolution
Contribution through source.auth_server_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
okta.rule.auth-server-policy-lookup Source
Matches data instances of okta_auth_server_policy.
Classification: okta.concept.authorization-server-configuration.
Contributions
- targets
okta.concept.authorization-serverthroughsource.auth_server_id.
Conditions, identity and resolution
Contribution through source.auth_server_id
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.idmatch.strategy:"exact"
okta.rule.auth-server-policy Source
Matches resource instances of okta_auth_server_policy.
Classification: okta.concept.authorization-server-configuration.
Contributions
- targets
okta.concept.authorization-serverthroughsource.auth_server_id.
Conditions, identity and resolution
Contribution through source.auth_server_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
okta.rule.auth-server-scope Source
Matches resource instances of okta_auth_server_scope.
Classification: okta.concept.authorization-server-configuration.
Contributions
- targets
okta.concept.authorization-serverthroughsource.auth_server_id.
Conditions, identity and resolution
Contribution through source.auth_server_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
okta.rule.auth-server-lookup Source
Matches data instances of okta_auth_server.
Classification: okta.concept.authorization-server.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
okta.rule.auth-server Source
Matches resource instances of okta_auth_server.
Classification: okta.concept.authorization-server.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
okta.rule.authenticator-method-webauthn-lookup Source
Matches data instances of okta_authenticator_method_webauthn.
Classification: okta.concept.authentication-configuration.
okta.rule.authenticator-method-webauthn Source
Matches resource instances of okta_authenticator_method_webauthn.
Classification: okta.concept.authentication-configuration.
okta.rule.authenticator-webauthn-custom-aaguid Source
Matches resource instances of okta_authenticator_webauthn_custom_aaguid.
Classification: okta.concept.authentication-configuration.
okta.rule.authenticator-webauthn-custom-aaguids-lookup Source
Matches data instances of okta_authenticator_webauthn_custom_aaguids.
Classification: okta.concept.authentication-configuration.
okta.rule.authenticator-lookup Source
Matches data instances of okta_authenticator.
Classification: okta.concept.authentication-configuration.
okta.rule.authenticator Source
Matches resource instances of okta_authenticator.
Classification: okta.concept.authentication-configuration.
okta.rule.behavior-lookup Source
Matches data instances of okta_behavior.
Classification: okta.concept.authentication-configuration.
okta.rule.behavior Source
Matches resource instances of okta_behavior.
Classification: okta.concept.authentication-configuration.
okta.rule.captcha-lookup Source
Matches data instances of okta_captcha.
Classification: okta.concept.authentication-configuration.
okta.rule.captcha Source
Matches resource instances of okta_captcha.
Classification: okta.concept.authentication-configuration.
okta.rule.domain-certificate Source
Matches resource instances of okta_domain_certificate.
Classification: okta.concept.domain-configuration.
Contributions
- targets
okta.concept.identity-domainthroughsource.domain_id.
Conditions, identity and resolution
Contribution through source.domain_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
okta.rule.domain-verification Source
Matches resource instances of okta_domain_verification.
Classification: okta.concept.domain-configuration.
Contributions
- targets
okta.concept.identity-domainthroughsource.domain_id.
Conditions, identity and resolution
Contribution through source.domain_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
okta.rule.domain-lookup Source
Matches data instances of okta_domain.
Classification: okta.concept.identity-domain.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
okta.rule.domain Source
Matches resource instances of okta_domain.
Classification: okta.concept.identity-domain.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
okta.rule.event-hook-verification Source
Matches resource instances of okta_event_hook_verification.
Classification: okta.concept.hook-configuration.
Contributions
- targets
okta.concept.identity-event-extensionthroughsource.event_hook_id.
Conditions, identity and resolution
Contribution through source.event_hook_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
okta.rule.event-hook Source
Matches resource instances of okta_event_hook.
Classification: okta.concept.identity-event-extension.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
okta.rule.hook-key-lookup Source
Matches data instances of okta_hook_key.
Classification: okta.concept.hook-configuration.
okta.rule.hook-key Source
Matches resource instances of okta_hook_key.
Classification: okta.concept.hook-configuration.
okta.rule.idp-oidc-lookup Source
Matches data instances of okta_idp_oidc.
Classification: okta.concept.external-identity-provider.
okta.rule.idp-oidc Source
Matches resource instances of okta_idp_oidc.
Classification: okta.concept.external-identity-provider.
okta.rule.idp-saml-lookup Source
Matches data instances of okta_idp_saml.
Classification: okta.concept.external-identity-provider.
okta.rule.idp-saml Source
Matches resource instances of okta_idp_saml.
Classification: okta.concept.external-identity-provider.
okta.rule.idp-social-lookup Source
Matches data instances of okta_idp_social.
Classification: okta.concept.external-identity-provider.
okta.rule.idp-social Source
Matches resource instances of okta_idp_social.
Classification: okta.concept.external-identity-provider.
okta.rule.inline-hook Source
Matches resource instances of okta_inline_hook.
Classification: okta.concept.identity-event-extension.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
okta.rule.log-stream-lookup Source
Matches data instances of okta_log_stream.
Classification: okta.concept.identity-log-stream.
okta.rule.log-stream Source
Matches resource instances of okta_log_stream.
Classification: okta.concept.identity-log-stream.
okta.rule.network-zone-lookup Source
Matches data instances of okta_network_zone.
Classification: okta.concept.network-zone.
okta.rule.network-zone Source
Matches resource instances of okta_network_zone.
Classification: okta.concept.network-zone.
okta.rule.oauth-authorization-server-lookup Source
Matches data instances of okta_oauth_authorization_server.
Classification: okta.concept.authorization-server.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
okta.rule.org-captcha-lookup Source
Matches data instances of okta_org_captcha.
Classification: okta.concept.authentication-configuration.
okta.rule.org-captcha Source
Matches resource instances of okta_org_captcha.
Classification: okta.concept.authentication-configuration.
okta.rule.org-configuration Source
Matches resource instances of okta_org_configuration.
Classification: okta.concept.identity-tenant.
okta.rule.org-metadata-lookup Source
Matches data instances of okta_org_metadata.
Classification: okta.concept.identity-tenant.
okta.rule.realm-assignment-lookup Source
Matches data instances of okta_realm_assignment.
Classification: okta.concept.authentication-configuration.
Contributions
- targets
okta.concept.identity-realmthroughsource.realm_id.
Conditions, identity and resolution
Contribution through source.realm_id
on_null:"indeterminate"on_empty:"indeterminate"match.by:target.idmatch.strategy:"exact"
okta.rule.realm-assignment Source
Matches resource instances of okta_realm_assignment.
Classification: okta.concept.authentication-configuration.
Contributions
- targets
okta.concept.identity-realmthroughsource.realm_id.
Conditions, identity and resolution
Contribution through source.realm_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
okta.rule.realm-lookup Source
Matches data instances of okta_realm.
Classification: okta.concept.identity-realm.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
okta.rule.realm Source
Matches resource instances of okta_realm.
Classification: okta.concept.identity-realm.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
okta.rule.security-events-provider-lookup Source
Matches data instances of okta_security_events_provider.
Classification: okta.concept.security-events-provider.
okta.rule.security-events-provider Source
Matches resource instances of okta_security_events_provider.
Classification: okta.concept.security-events-provider.
okta.rule.threat-insight-settings-lookup Source
Matches data instances of okta_threat_insight_settings.
Classification: okta.concept.authentication-configuration.
okta.rule.threat-insight-settings Source
Matches resource instances of okta_threat_insight_settings.
Classification: okta.concept.authentication-configuration.
okta.rule.trusted-origin-lookup Source
Matches data instances of okta_trusted_origin.
Classification: okta.concept.authentication-configuration.
okta.rule.trusted-origin Source
Matches resource instances of okta_trusted_origin.
Classification: okta.concept.authentication-configuration.
okta.rule.trusted-server Source
Matches resource instances of okta_trusted_server.
Classification: okta.concept.authorization-server-configuration.
Contributions
- targets
okta.concept.authorization-serverthroughsource.auth_server_id.
Conditions, identity and resolution
Contribution through source.auth_server_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"