<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Permission Error When App Admins Rotate OAuth Service App Client Secrets

Okta Classic Engine
Okta Identity Engine
API Access Management

Overview

When an Application Administrator attempts to create or rotate client secrets on an OAuth service application, Okta generates a permission error. This occurs because modifying client credentials for OAuth service apps requires Super Administrator privileges. To resolve this issue, the Application Administrator must escalate the request to a Super Administrator to perform the rotation.

 

You do not have permission to perform the requested action

 

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • OAuth Service Applications
  • Application Administrator Role

Cause

The Application Administrator role does not have the necessary permissions to create or rotate client secrets for OAuth service applications. Only the Super Administrator role possesses the required permissions to modify these credentials.

Solution

How is the permission error resolved when rotating client secrets?

Modifying client credentials requires Super Administrator privileges. Escalate the request to a Super Administrator to rotate the client secrets.

  1. Identify a user in the Okta environment with the Super Administrator role.
  2. Request that the Super Administrator go to the target OAuth service application in the Admin Console.
  3. Have the Super Administrator generate or rotate the client secret on behalf of the Application Administrator.

 

Related References

Loading
Okta Support - Okta Permission Error When App Admins Rotate OAuth Service App Client Secrets