The DocuSign provisioning or deprovisioning flow fails with one of the following errors visible in the Okta dashboard:
- Automatic provisioning of user <user> to app DocuSign failed: The credentials used to connect to the API were invalid; please check your configuration
- FAILURE: javax.ws.rs.BadRequestException: HTTP 400 Bad Request
Admins may also receive the following User Deactivation Summary Email:
The application account failed automatic deprovisioning and needs to be manually deprovisioned.
- DocuSign
- Okta Integration Network
- Provisioning
- Deprovisioning
- Locate and record the DocuSign API account ID:
-
Sign in to the DocuSign instance with administrator permissions.
- Select Settings on the top ribbon. If Settings is unavailable, click the menu and select eSignature.
-
In the left menu below Integrations, click Apps and Keys.
-
Copy the value in the API Account ID field.
-
-
Go to Okta Admin Console and navigate to Applications > Applications > DocuSign > Provisioning > Integration > Edit.
- In the API Account ID field, enter the API account ID copied in Step 1.
Ensure the API Account ID and DocuSign administrator credentials match to avoid authentication errors. -
Generate the authentication token:
-
Click Authenticate with DocuSign.
-
Click Accept if a prompt appears.
-
If required, enter the email address and click CONTINUE.
-
If required, enter the password and click LOG IN.
-
- A message confirming the successful authentication will appear on the Provisioning page in Okta. Click Save.
- Afterward, attempt the user provisioning again. Navigate to Dashboard > Tasks. Any failed assignments should appear under Tasks.
- Confirm that the deprovisioning flow is functioning by assigning a test user and deprovisioning it.
-
After locating the failed task for the user that should be retried, click on Retry Selected.
Related References
