Okta Management API Returns Error Code E0000006 Despite Correct Scopes
Last Updated:
Overview
An Okta Management API call fails with error code E0000006 despite the access token including the correct OAuth 2.0 scopes, and the API response shows the following error message:
You do not have permission to perform the requested action
As the entity using the access token lacks the required administrator roles, assign the appropriate administrator role to the service application or user to resolve the error.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Management API
- OAuth 2.0
- Client Credentials Grant
- Service Applications
Cause
This error occurs because the entity using the access token, either a user or a service application, lacks the required administrator roles to perform the specific action.
While OAuth 2.0 scopes grant the application authorization to interact with the API endpoint, the actor must also possess the specific Role-Based Access Control (RBAC) permissions necessary to execute the request. For service applications using the Client Credentials grant type, the application acts as the administrator and requires direct assignment of the relevant roles.
Solution
How are administrator roles assigned to a service application?
Navigate to the application settings in the Okta Admin Console and edit the assignments on the administrator roles tab to grant the required permissions.
- In the Okta Admin Console, go to Applications, and then select Applications.
- Select the service application that generates the access token.
- Select the Admin roles tab.
- Select Edit assignments.
- Assign the appropriate administrator role that grants permission to perform the desired action.
- Select Save Changes.
How are administrator roles assigned to a user?
Add an administrator role to the user from the security settings in the Okta Admin Console.
- In the Okta Admin Console, go to Security, and then select Administrators.
- Select the Admins tab.
- Select Add administrator.
- Select the user in the Select admin field.
- Select the required role, and then select Save.
