Okta Workflows Webhook Registration Failed Error Occurs When Enabling an Event-Triggered Workflow
Last Updated:
Overview
Missing permissions, missing scopes, or an unauthorized connection cause a webhook registration failure in Okta Workflows. Administrators must verify the connection authorization, scopes, and administrator roles to resolve the issue. When an administrator attempts to turn on a workflow configured to use an event card that creates a webhook, such as the Okta connector event cards, the following error messages occur:
Failed to activate webhook
Cannot activate Flow. Webhook registration failed.
Review the following images for examples of the webhook registration failure errors.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Workflows
- Connector Event Cards
Cause
The error occurs for Okta connector event cards under the following conditions:
- The Okta connection lacks authorization.
- The user who authorized the Okta connection does not have the Super Administrator role.
- The Okta connection lacks authorization with the
okta.eventHooks.readandokta.eventHooks.managescopes.
For connectors to third-party systems, the user authorizing the connection lacks sufficient permissions to create a webhook in the third-party system.
Solution
How do administrators resolve the webhook registration failure?
Verify the administrator role and ensure the Okta connection has the correct scopes by following these steps:
- Verify that the user who authorized the Okta connection has the Super Administrator role. When an administrator turns on a flow triggered by an Okta connector event card, Okta creates an event hook in the Okta org. As the Standard administrator roles and permissions - Hooks documentation states, administrators require the Super Administrator role to create and configure event hooks in Okta.
- NOTE: Reauthorizing the Okta connection after assigning the Super Administrator role is unnecessary.
- Verify that the Okta connection has authorization with the
okta.eventHooks.readandokta.eventHooks.managescopes. Administrators can grant the scopes on the Okta API Scopes tab of the Okta Workflows OAuth application. When reauthorizing the connection, select the Use default scopes option from the Permissions tab to select theokta.eventHooks.readandokta.eventHooks.managescopes by default. Review the following image for an example of the default scopes selection.
The Customize scopes (advanced) option on the Permissions tab provides more granular control over the scopes requested when authorizing the connection. See Okta Workflows Okta Connection(s) - Insufficient Scope for more details.
