Okta Error Occurs When Searching for a Custom Group Attribute Named "Status"
Last Updated:
Overview
Creating a custom group attribute named status succeeds in the Okta Group Schema Editor, but searching for this attribute via the API fails because Okta reserves the status keyword in the core search parser. Recreating the attribute with a non-reserved name resolves the issue.
When calling the /api/v1/groups?search=profile.status eq "active" endpoint, Okta generates the following error:
Invalid search query: attribute "status"'s type mismatches with the value type.
NOTE: the above may apply to multiple attributes, such as id, type, lastUpdated, objectClass, etc.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Groups API
- Group Schema
- Group Attributes
Cause
The Okta Group Profile schema only formally defines name and description as base properties. The user interface and Schema API (/api/v1/meta/schemas/group/default) do not enforce the reserved keyword list on groups, which allows the creation of a custom group attribute with the variable name status. However, the /api/v1/groups?search= endpoint relies on the shared core search and System for Cross-domain Identity Management (SCIM) filter parser.
In the underlying entity index, Okta defines status platform-wide as a system property representing an internal lifecycle status enumeration. When submitting search=profile.status eq "active", the parser binds status to the platform-level reserved field rather than resolving it as the custom group profile string, which generates the error.
Okta does not explicitly document status as a reserved attribute in the Groups API or Group Schema documentation.
Solution
What resolves the group attribute search error?
Recreate the custom group attribute using a non-reserved variable name to ensure compatibility with the Group Search API.
- Rename or recreate the group attribute using a non-reserved variable name, such as
groupStatus, orcustomStatus. - Update any API calls to use the new attribute name in the search query.
