Okta Permission Error When App Admins Rotate OAuth Service App Client Secrets
Last Updated:
Overview
When an Application Administrator attempts to create or rotate client secrets on an OAuth service application, Okta generates a permission error. This occurs because modifying client credentials for OAuth service apps requires Super Administrator privileges. To resolve this issue, the Application Administrator must escalate the request to a Super Administrator to perform the rotation.
You do not have permission to perform the requested action
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- OAuth Service Applications
- Application Administrator Role
Cause
The Application Administrator role does not have the necessary permissions to create or rotate client secrets for OAuth service applications. Only the Super Administrator role possesses the required permissions to modify these credentials.
Solution
How is the permission error resolved when rotating client secrets?
Modifying client credentials requires Super Administrator privileges. Escalate the request to a Super Administrator to rotate the client secrets.
- Identify a user in the Okta environment with the Super Administrator role.
- Request that the Super Administrator go to the target OAuth service application in the Admin Console.
- Have the Super Administrator generate or rotate the client secret on behalf of the Application Administrator.
