<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Adding a Group Claim for a Specific Application/Client in Okta

API Access Management

Overview

When creating custom group claims on a Custom Authorization Server, it is possible to use an expression that will return different lists of matching groups based on the OpenID Connect (OIDC) application requesting tokens. For the expression, use a conditional as in the below example to return the application-specific groups within the token claim:

 

app.clientId == "0oaxxxxxxxx357" ? Groups.startsWith("OKTA", "", 100) : null

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Custom Authorization Server
  • Custom claims

Cause

Adding group expressions in the default custom authorization server or a created custom authorization server in Security > API > Authorization Servers might affect other applications/clients, as it is shown in the following screenshot:

Default claims

Solution

How to create a custom claim that returns different group membership information based on the application requesting tokens?

If it is needed for group claims to return groups for a specified application/client configured in the custom default authorization server or a custom-created authorization server, then use the following expression:

app.clientId == "0oaxxxxxxxx357" ? Groups.startsWith("OKTA", "", 100) : null

default claims

If using the org authorization server, then it is necessary to add the group claim in Applications > Applications > Sign On. Note that the expression in this section is specific to the application being configured, so no application specific conditionals need to be included in the expression.

Legacy groups claim configuration

Loading
Adding a Group Claim for a Specific Application/Client in Okta | Okta Support