Okta GitHub Enterprise Cloud Organization API Integration Fails With Forbidden Error
Last Updated:
Overview
Okta generates a forbidden error during the GitHub Enterprise Cloud - Organization API integration when the authorized OAuth application lacks access on the GitHub side. Granting access to the Okta SCIM integration application in the GitHub organization settings resolves this issue. The following error appears during authentication:
Error authenticating: Forbidden. Errors reported by remote server:
The application uses Security Assertion Markup Language (SAML) Single Sign-On (SSO), and authentication occurs using an account with administrator privileges in GitHub. The administrator authorizes Okta to connect to the GitHub account as shown below:
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Integration Network (OIN)
- GitHub Enterprise Cloud - Organization
- Application Programming Interface (API) Integration
- Provisioning
Cause
The error occurs because the authorized OAuth application for the Okta System for Cross-domain Identity Management (SCIM) integration lacks access on the GitHub side.
Solution
How is the GitHub Enterprise Cloud Organization forbidden error resolved?
Grant access to the Okta SCIM integration application in the GitHub organization settings and re-authenticate the API integration in the Okta Admin Console.
- Sign in to GitHub Enterprise Cloud - Organization as an administrator.
- Navigate to the organization Settings > Applications > Authorized OAuth Apps.
- Select the OKTA SCIM Integration application.
- Locate the organizations associated with the application. If an X appears next to the organization, select Grant.
- Navigate to the Okta Admin Console and go to Applications > Applications.
- Select the GitHub Enterprise Cloud - Organization application.
- Go to the Provisioning tab and select Integration in the left settings menu.
- Select Edit.
- Select Authenticate with Github Enterprise Cloud - Organization to generate a token.
- Verify that a message appears confirming the successful authentication.
- Select Save.
NOTE: Contact GitHub support for more details and steps on how to resolve this error if the issue persists.
