Atlas / MCP servers / fctr-id / Okta

OktaBLOCK

mcp/fctr-id/okta-1

The Okta MCP Server is a groundbreaking tool built by the team at Fctr that enables AI models to interact directly with your Okta environment using the Model Context Protocol (MCP). Built specifically for IAM engineers, security teams, and Okta administrators, it implements the MCP specification to

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
4 4r · 0w · 0d
Transport
sse · streamable-http
License
Apache-2.0
Stars
38
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Okta MCP Server (v0.1.1-BETA)

🔥 ALERT!!! A brand new re-built MCP Server now available A complete rewrite built on Anthropic's new MCP architecture pattern with dual-mode operation, context-engineering, enhanced security sandbox, and production-ready Docker support. → Explore TAKO MCP Server

The Okta MCP Server is a groundbreaking tool that enables AI models to interact directly with your Okta environment using the Model Context Protocol (MCP). Built specifically for IAM engineers, security teams, and Okta administrators, it implements the MCP specification to transform how AI assistants can help manage and analyze Okta resources.

View on GitHub | Learn about MCP | Okta AI Agent

Quick Demo

🎉 What's New in v0.1.1-BETA - Enterprise-Grade Special Tools!

This release introduces powerful special tools that revolutionize daily Okta administration tasks:

🔥 NEW: Special Tools - Game Changers for Okta Admins

  • 🎯 Comprehensive Access Analysis: Helps answer the most frequent question okta admns face. Can user X access app Y?
  • 🛡️ Advanced Login Risk Assessment: Behavioral analysis with VPN/Tor detection and geographic impossibility checks which can help with suspicious reporting emails.

💡 Real-World Example - Access Analysis:

❓ 
Read from source at commit c7569d0e0a0fOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add okta-mcp-server --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env AUTH_AUDIENCE=${AUTH_AUDIENCE} --env AUTH_ISSUER=${AUTH_ISSUER} --env AUTH_JWKS_URI=${AUTH_JWKS_URI} -- uvx okta-mcp-server
claude-desktop
{
  "mcpServers": {
    "okta-mcp-server": {
      "command": "uvx",
      "args": [
        "okta-mcp-server"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "AUTH_AUDIENCE": "${AUTH_AUDIENCE}",
        "AUTH_ISSUER": "${AUTH_ISSUER}",
        "AUTH_JWKS_URI": "${AUTH_JWKS_URI}"
      }
    }
  }
}
03

Exposed tools (4)

4 read · 0 write · 0 destructive.

ToolRiskDescription
analyze_user_datareadGenerate AI-powered analysis of user data.
detect_user_anomaliesreadUse AI to detect potential anomalies or security concerns in user data.
generate_okta_scim_queryreadConvert natural language intent to Okta SCIM query using AI.
suggest_user_actionsreadSuggest relevant actions for a specific user based on their profile.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (3 observation(s))
Shell
declared (2 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (7)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
_Archived/model_provider.py:59
client = httpx.AsyncClient(verify=False, headers=custom_headers)
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
okta_mcp/tools/tool_registry.py:268
module = importlib.import_module(f"okta_mcp.tools.{name}")
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
okta_mcp/tools/tool_registry.py:305
module = importlib.import_module(import_path)
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.sample
.env.sample
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
okta_mcp/utils/logging.py:37
log_dir = os.path.abspath(os.path.join(os.path.dirname(__file__), '../../logs'))
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:177
- They open unauthenticated HTTP servers with full access to your Okta tenant
INFOInventory / provenance · inv.oversize · CWE-1104
images/mcp-server.gif
images/mcp-server.gif
Why it matters. 15599397 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha c7569d0e0a0ffull audit observations/trust-audit/mcp-server/fctr-id__okta-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08c7569d0e0a0fBLOCKD69first audit
06

Questions

What is the Okta MCP server?

The Okta MCP Server is a groundbreaking tool built by the team at Fctr that enables AI models to interact directly with your Okta environment using the Model Context Protocol (MCP). Built specifically for IAM engineers, security teams, and Okta administrators, it implements the MCP specification to

What tools does Okta expose?

4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Okta safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Okta need?

It reads ANTHROPIC_API_KEY, AUTH_AUDIENCE, AUTH_ISSUER, AUTH_JWKS_URI, AUTH_PUBLIC_KEY, AUTH_REQUIRED_SCOPES, AZURE_OPENAI_API_KEY, AZURE_OPENAI_KEY, ENABLE_AUTH, GOOGLE_APPLICATION_CREDENTIALS, OKTA_API_TOKEN and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Okta run?

It speaks sse and streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as okta-mcp-server.

How current is this page?

The grade is for one exact copy of the source (c7569d0e0a0f), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement