Creating API Tokens with a Group-Restricted Custom Admin Role in Okta
Last Updated:
Overview
A custom admin role cannot create API tokens when the Users resource set is restricted to a specific group and the admin is not assigned to that group. After assigning the admin to the same group in the Users resource set, the admin can create API tokens.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- API
- Custom Admin Roles
- Group-restricted user resource sets
Cause
A custom admin role with a Users resource set restricted to a specific group cannot create API tokens unless the admin is assigned to that same group. Okta requires the admin to belong to the group defined in the Users resource set before the admin can generate an API token.
Solution
How is API token creation resolved for a group-restricted custom admin role?
Assign the admin to the same group in the Users resource set to allow API token creation.
