
Integration · Developer tools
Connect Claude & ChatGPT to Okta
Ask your AI who has access to an app, which groups a user is in, or to unlock someone who is locked out of Okta. It can search users and groups, read app assignments, create users and groups, and add people to groups and apps. It can also suspend, unsuspend and unlock users, and update profile attributes like title or department.
Free plan, no credit card. Takes about a minute.
Try asking
“Which users are locked out right now?”
The AI searches users with the expression status eq "LOCKED_OUT".
“Unlock Mette Nielsen.”
It finds Mette and unlocks her account, so she can try her password again.
“Which apps does [email protected] have access to?”
It lists the apps assigned to Jonas, as shown on his Okta dashboard.
What your AI can do
Users
Search and read users, create users, update profile attributes, and suspend, unsuspend or unlock accounts.
Groups
Search and read groups, create groups, list members, and add or remove users.
Apps and access
List apps and see who is assigned, give users or groups access, and remove a user's direct access.
“Create a user for Anna Holm and add her to the Sales group.”
It creates the user with name, email and login and adds her to the group. With activate set to true, Okta sends the activation email right away.
“Who has access to the Slack app?”
It finds the app and lists the users and groups assigned to it.
“Suspend the account of the contractor who left today.”
It suspends the user so they cannot sign in. Their apps and groups are kept, and it can be undone.
23 tools for Okta
These tools are switched on when you connect. You can switch any of them off, or require your approval before it runs.
add_user_to_groupChanges dataAdd a user to a group by `group_id` and `user_id`; they get any apps assigned to that group.assign_group_to_appChanges dataGive every member of a group access to an app by `app_id` and `group_id`.assign_user_to_appChanges dataGive a user access to an app: `app_id` and the user's ID in `id`, with optional app-specific `profile`.create_groupChanges dataCreate a group with a `profile` holding name and description.create_userChanges dataCreate a user with a `profile` (firstName, lastName, email, login), optional `group_ids` to add them to, and `activate` true to send the activation email right away.get_appGet one app by `app_id`, with its label, status and sign-on mode.get_groupGet one group by `group_id`, with its name, description and type.get_userGet one user by `user_id`, login or email (use 'me' for yourself), with profile, status and last login.list_app_groupsList the groups assigned to an app.list_app_usersList the users assigned to an app, optionally filtered with `q`.list_appsList the apps in your Okta org, optionally filtered by name with `q` or by `filter` such as 'status eq "ACTIVE"'.list_group_appsList the apps assigned to a group.list_group_membersList the users who are members of a group.list_user_appsList the apps assigned to a user, as shown on their Okta dashboard.list_user_groupsList the groups a user belongs to.remove_user_from_groupDeletesRemove a user from a group by `group_id` and `user_id`; they lose apps they only had through that group.search_groupsFind groups by name with `q`, or with a `search` expression such as 'type eq "OKTA_GROUP"'.search_usersFind users by name or email with `q`, or with an Okta `search` expression such as 'profile.department eq "Sales"' or 'status eq "LOCKED_OUT"'.suspend_userChanges dataSuspend an active user so they cannot sign in, keeping their apps and groups; undo with unsuspend_user.unassign_user_from_appDeletesRemove a user's direct access to an app by `app_id` and `user_id`; this can deprovision their account in that app.unlock_userVisible to othersUnlock a user who is locked out after too many failed sign-ins, so they can try their password again.unsuspend_userChanges dataRestore sign-in for a suspended user.update_userChanges dataUpdate a user's profile attributes by `user_id`, e.g. title, department, mobilePhone or manager; only the fields you pass change.
Set up in three steps
- 1
Pick the app
Create a free PipMCP account and choose Okta from the app list.
- 2
Paste your key
Enter your Okta org address and an API token. In the Okta Admin Console go to Security → API → Tokens and click Create token. Name it and copy the value, because Okta shows it only once. The token has the permissions of the admin who created it.
- 3
Add the link to your AI
You get a personal MCP link. Add it to Claude, ChatGPT or Cursor:
Click your name, then Settings › Connectors › Add custom connector. Paste your link as the Remote MCP server URL. Switch it on from the + menu in a chat.
Questions
What can the AI do in Okta?
The AI can search and read users, groups and apps, and list group members, a user's groups and apps, and the users and groups assigned to an app. It can create users and groups, update user profiles, add users to groups and apps, assign groups to apps, suspend, unsuspend and unlock users, and remove users from groups or apps.
Does the AI see my Okta credentials?
No. Your Okta API token is encrypted at rest and never shown to the AI. After you save it, it is not shown again, not even to you. The AI only sees the results of the tools it calls.
Can I control what the AI is allowed to do?
Yes. You choose which tools are switched on, so you can start read-only. The token has the permissions of the admin who created it, so the tool choice matters. Removing a user from a group or an app can cost them access, and those tools, like unlocking users, can require your approval before they run. Every tool call is logged.
Does it work with ChatGPT?
Yes. In ChatGPT go to Settings › Apps & Connectors › Advanced and turn on Developer mode, then add your PipMCP link. Developer mode needs a paid ChatGPT plan: Plus, Pro, Business or Enterprise. The same link also works in Claude (Settings › Connectors › Add custom connector), Cursor and other MCP clients.
What does it cost?
PipMCP has a free plan with no credit card required. Paid plans bill per completed task. You also need your own Okta account.
What happens when the AI removes someone's access?
When the AI removes a user from a group, they lose the apps they only had through that group. When it removes a user's direct access to an app, their account in that app can be deprovisioned. Keep these tools off or require approval for them. Suspending a user is the gentler option: they cannot sign in, but apps and groups are kept, and unsuspend_user restores sign-in.
Related integrations
Let your AI work in Okta today.
Start free. Your key stays encrypted, and you decide what the AI may do.
Connect Okta freePipMCP is not affiliated with Okta. Product names are trademarks of their owners.





