Okta Access Gateway Reserved Attribute Names
Last Updated:
Overview
Okta Access Gateway (OAG) reserves specific attribute names for internal functionality, preventing their reuse in custom configurations. When an administrator attempts to use a reserved attribute name, Okta displays a warning message in the web interface. Configuring a non-reserved attribute name and adding a proxy header directive in the relevant policies resolves this issue when the backend application requires a reserved value as the header name.
Attribute must not be a reserved word
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Access Gateway (OAG)
- Header Attributes
Cause
Okta reserves specific attribute names for internal product functionality. Because an attribute name requires a unique identifier, Okta restricts these internal names from being assigned to new attributes.
Solution
What attribute names are reserved in Okta Access Gateway?
The following list contains the reserved attribute names that Okta restricts from reuse.
- UserName
- oag_username
- RemoteIP
- RelayDomain
- Remote_user
- SESSIONID
- creationTime
- maxInactiveInterval
- maxActiveInterval
- lastAccessedTime
- USER_AGENT
- SourceAuthNType
If the backend application requires a reserved value as the header name, how can OAG send it?
Change the attribute name to a non-reserved value and add a proxy header directive in the relevant policies to send a reserved value as the header name.
- Change the attribute Name value to something that's not reserved.
- Note the position of the attribute in the ordered list (for example, 1st, 2nd, 3rd, and so on).
- In all relevant policies, add a
proxy_set_headerdirective with the reserved name as the field and$_Nas the value, whereNis the position of the attribute on the attributes page.- For example, if
remote_useris the 3rd attribute configured:proxy_set_header remote_user $_3;
- For example, if
