<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Access Gateway Reserved Attribute Names

Access Gateway
Okta Classic Engine
Okta Identity Engine

Overview

Okta Access Gateway (OAG) reserves specific attribute names for internal functionality, preventing their reuse in custom configurations. When an administrator attempts to use a reserved attribute name, Okta displays a warning message in the web interface.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Okta Access Gateway (OAG)
  • Header Attributes

Cause

Okta reserves specific attribute names for internal product functionality. Because an attribute name requires a unique identifier, Okta restricts these internal names from being assigned to new attributes.

Solution

What attribute names are reserved in Okta Access Gateway?

Okta displays a warning message in the web interface when an administrator attempts to configure a reserved attribute name.
Add new attribute 

The following list contains the reserved attribute names that Okta restricts from reuse.

  • UserName
  • oag_username
  • RemoteIP
  • RelayDomain
  • Remote_user
  • SESSIONID
  • creationTime
  • maxInactiveInterval
  • maxActiveInterval
  • lastAccessedTime
  • USER_AGENT
  • SourceAuthNType

Recommended content

Loading
Okta Support - Okta Access Gateway Reserved Attribute Names