How to Determine What User Account an Okta Workflows Connection Is Using or Authorized With
Last Updated:
Overview
Connections in the Workflows Console show who created the connection, but not the identity of the user/account used to authorize the connection itself, whether for the Okta Connector or another third-party Connector. This can be useful for discovering which user/account is performing the API actions for the related cards that use the connection. Administrators can discover the authorized account identity by creating a flow with a Custom Application Programming Interface (API) Action card that targets a specific endpoint.
NOTE: Not all connectors can perform this check, even if the endpoint is available. For example, a custom API Action automatically prepends part of the URL, so the direct endpoint is not reachable. Google Workspace can obtain this information via /v3/tokeninfo. However, the Google Workspace Custom API Action prepends /admin/directory to the Relative URL entered, so the GET would be against /admin/directory/v3/tokeninfo instead of /v3/tokeninfo.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Workflows Connectors
- Azure Active Directory Connector
- Excel Online Connector
- Jira Connector
- Jira Service Management Connector
- Microsoft Teams Connector
- Office 365 Calendar Connector
- Office 365 Mail Connector
- Okta Connector
- OneDrive Connector
- Salesforce Connector
- Slack Connector
Solution
How is the authorized user account identified for an Okta Workflows connection?
Identify the authorized account by creating a flow, adding a specific card, and observing the response data.
- Create a flow.
- Add a card similar to the examples below.
- Run the flow or test the card.
- Review the data in the response to view information about the account authorized for the selected connection.
- Rename the connection to include the account name for future identification.
Review the following examples to configure the appropriate card and endpoint for various connectors:
- Azure Active Directory connector
- Card: Custom API Action Method=GET
- Set Relative URL to
/me - API Reference: GRAPH API User Get
- Excel Online connector
- Card: Custom API Action Method=GET
- Set Relative URL to
/v1.0/me/drive - API Reference: GRAPH API - Get User's OneDrive (usable for Excel Online Connector)
- NOTE: Information will be under the owner object in the response.
- Jira connector
- Card: Custom API Action Method=GET
- Set Relative URL to
/rest/api/2/myself - API Reference: JIRA API Group Myself
- Jira Service Management connector
- Card: Custom API Action Method=GET
- Set Relative URL to
/api/2/myself - API Reference: JIRA API Group Myself
- Microsoft Teams connector
- Card: Custom API Action Method=GET
- Set Relative URL to
/me - API Reference: GRAPH API User Get
- Office 365 Calendar connector
- Card: Custom API Action Method=GET
- Set Relative URL to
/me - API Reference: GRAPH API User Get
- Office 365 Mail connector
- Card: Send Email
- Set To to the desired email
- NOTE: This sends an email to that address, and the sender of the email will be what the connection is authorized with.
- Okta connector
- Card: Read User
- Set ID or Login to
me - API Reference: Get Current User
- OneDrive connector
- Card: Custom API Action Method=GET
- Set Relative URL to
/me/drive - API Reference: GRAPH API - Get User's OneDrive
- NOTE: Information will be under the owner object in the response
- Salesforce Connector
- Card: Custom API Action Method=GET
- Set Relative URL to
/services/oauth2/userinfo - API Reference: Query for User Information
- Slack Connector
- Card: Custom API Action Method=GET
- Set Relative URL to
/auth.test - API Reference: Slack auth.test
- NOTE: Information will be under the owner object in the response.
