Coupa OIN Application Provisioning Error when Enabling Okta Identity Governance (OIG)
Last Updated:
Overview
When Governance Engine is enabled for the Coupa Okta Identity Network application, attempts to enable provisioning will result in the error:
OAuth credentials must be authenticated first before saving.
Applies To
- Okta Integration Network (OIN)
- Coupa OIN Application
- Okta Identity Governance (OIG)
- Governance Engine
Cause
The OpenID Connect (OIDC) settings in Coupa are missing the required scopes.
Solution
In the Coupa web admin portal, under Setup > OAuth2/OpenID Connect Clients, the scopes needed for Coupa + Entitlements include:
openidoffline_accesscore.user.readcore.user.writecore.common.read
