
po90c (po90c) asked a question.
I am trying to use custom user attributes to define roles in okta that will passed to applications. I want to add a string attribute (role type), and based on the role, restrict/allow certain features in application for that user. My question is does okta pass the attributes of a user to the app automatically, or does the app need to make a separate call to fetch a users attributes? Currently app has integrated login with okta and is authenticating with passport saml method.

Thank you for posting on our Community page.
Okta can pass any attribute to an application, as long as the app accepts it (for example those applications that support SAML and provisioning). Afterwards, in order to restrict/allow certain features in the application based on the values of the attributes, that's something that has to be done from the application.
If you need more details please don't hesitate to open a support case with us.
Thank you,
Cosmin Prahoveanu
Technical support engineer | Okta