<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Creating API Tokens with a Group-Restricted Custom Admin Role in Okta

Administration
Okta Classic Engine
Okta Identity Engine

Overview

A custom admin role cannot create API tokens when the Users resource set is restricted to a specific group and the admin is not assigned to that group. After assigning the admin to the same group in the Users resource set, the admin can create API tokens.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • API
  • Custom Admin Roles
  • Group-restricted user resource sets

Cause

A custom admin role with a Users resource set restricted to a specific group cannot create API tokens unless the admin is assigned to that same group. Okta requires the admin to belong to the group defined in the Users resource set before the admin can generate an API token.

Solution

How is API token creation resolved for a group-restricted custom admin role?

Assign the admin to the same group in the Users resource set to allow API token creation.

Loading
Okta Support - Creating API Tokens with a Group-Restricted Custom Admin Role in Okta