How to Identify Headers Sent by Okta Access Gateway to Applications
Last Updated:
Overview
Administrators can verify the headers that Okta Access Gateway (OAG) sends to applications by creating a custom application page or using the sample header application. Verifying these headers ensures the application receives the correct data from OAG.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Access Gateway (OAG)
Solution
What steps verify the headers that Okta Access Gateway sends to applications?
Verify the headers that the application receives from OAG by creating a custom application page or using the sample header application protected URL.
- Create a custom application page to receive a header and point the protected web resource to that page.
- Use the OAG sample header application protected URL http://header.service.spgw in protected web resources for specific applications to provide the application with all the headers that OAG sends.
The following image demonstrates the protected web resource configuration using the sample header application URL.
