When Governance Engine is enabled for the Coupa Okta Identity Network application, attempts to enable provisioning will result in the error:
OAuth credentials must be authenticated first before saving.
- Okta Integration Network (OIN)
- Coupa OIN Application
- Okta Identity Governance (OIG)
- Governance Engine
The OpenID Connect (OIDC) settings in Coupa are missing the required scopes.
In the Coupa web admin portal, under Setup > OAuth2/OpenID Connect Clients, the scopes needed for Coupa + Entitlements include:
openidoffline_accesscore.user.readcore.user.writecore.common.read
