<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00007dD0diCACOkta Classic EngineAPI Access ManagementAnswered2022-05-08T23:51:16.000Z2022-05-06T07:01:26.000Z2022-05-08T23:51:16.000Z

BrettA.35061 (Customer) asked a question.

Cannot access Create Token as Application Administrator

I've created a service account in Okta, and granted it "Application Administrator" role to two existing Applications.

The purpose of the service account is to perform automated administration of the Applications.

 

I now want to create an API Token. However when I log in as the service account user, the Security menu is missing from the dashboard. If I try to visit the URL directly (https://{mydomain}-admin.okta.com/admin/access/api/tokens) I get a 403 error.

 

As an experiment, I granted the service account broader admin rights, such as "Read-only Administrator". In this case, the service account was able to see the Security -> API -> Tokens menu and do Create Token.

 

However this is not viable - I want to limit the rights of the service account to just administer the two specific applications. I cannot grant it broader rights than that.

 

What is the solution here?

 

(I'm doing this in a development account, proving the concept before applying it to the enterprise production account).

 


This question is closed.
Loading
Cannot access Create Token as Application Administrator