Okta Access Gateway Reserved Attribute Names
Last Updated:
Overview
Okta Access Gateway (OAG) reserves specific attribute names for internal functionality, preventing their reuse in custom configurations. When an administrator attempts to use a reserved attribute name, Okta displays a warning message in the web interface.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Access Gateway (OAG)
- Header Attributes
Cause
Okta reserves specific attribute names for internal product functionality. Because an attribute name requires a unique identifier, Okta restricts these internal names from being assigned to new attributes.
Solution
What attribute names are reserved in Okta Access Gateway?
Okta displays a warning message in the web interface when an administrator attempts to configure a reserved attribute name.
The following list contains the reserved attribute names that Okta restricts from reuse.
- UserName
- oag_username
- RemoteIP
- RelayDomain
- Remote_user
- SESSIONID
- creationTime
- maxInactiveInterval
- maxActiveInterval
- lastAccessedTime
- USER_AGENT
- SourceAuthNType
