Auth & Identity
Okta Webhooks
Enterprise identity and single sign-on platform. Receive events for user lifecycle changes, sign-ins, and application/group membership changes via Event Hooks.
Connecting Okta to Hookbase
Create a source in Hookbase first — it gives you an ingest URL to paste into Okta. Then:
- 1Go to Okta Admin Console → Workflow → Event Hooks
- 2Click "Create Event Hook" and paste your Hookbase ingest URL as the endpoint
- 3Under "Enhance security", set an authentication header name (typically Authorization) and a secret value
- 4Add the same header name/value as a custom header on your Hookbase source
- 5Select the event types to subscribe to from the event-hook-eligible catalog
- 6Save the hook, then complete the one-time verification: Okta sends a GET request with an x-okta-verification-challenge header that your endpoint must echo back as { "verification": "<value>" } — do this once manually or via your Hookbase source test endpoint
Signature verification
Okta signs its webhooks with Shared secret in a custom header (not HMAC-signed) — Okta echoes back the exact header name/value you configure on every request in Authorization, and Hookbase has no verifier for that combination today. We would rather say so here than let a source report every event as verified while nothing was checked.
What you can do:
- Receive them on a
customsource with no signing secret. Hookbase still dedupes, retries, transforms, routes and replays them; it just does not vouch for the sender. - Set a signing secret anyway if Okta can be configured to send a hex HMAC-SHA256 of the raw body in
X-Signature,X-Webhook-SignatureorX-Hub-Signature-256— that is the one scheme the custom verifier implements. - Verify downstream: the original headers travel with the event, so your own service or a transform can check the signature itself. The key is at Admin Console → Workflow → Event Hooks → Create Event Hook → "Enhance security" → set an authentication field name and secret value.
- Narrow the blast radius with an IP allowlist and a hard-to-guess source slug.
Okta event types
8 of the events people route most often. Hookbase accepts every event Okta sends, whether or not it is listed here.
user.lifecycle.create
A new user was created
user.lifecycle.activate
A user account was activated
user.lifecycle.deactivate
A user account was deactivated
user.lifecycle.suspend
A user account was suspended
user.session.start
A user started a new session by signing in
user.account.lock
A user account was locked out (e.g. too many failed sign-in attempts)
user.mfa.factor.activate
A user activated a new MFA factor
application.user_membership.add
A user was assigned to an application
What a Okta webhook looks like
A user.session.start payload. Hookbase stores the raw body exactly as it arrived, so this is also what you get back on a replay.
{
"eventType": "com.okta.event_hook",
"eventTypeVersion": "1.0",
"cloudEventsVersion": "0.1",
"source": "https://your-org.okta.com/api/v1/eventHooks/whoo1a2b3c4d5e",
"data": {
"events": [
{
"uuid": "ec22a6d0-2837-11eb-9823-9fb8f750c5a9",
"published": "2024-01-15T10:30:00.000Z",
"eventType": "user.session.start",
"version": "0",
"severity": "INFO",
"displayMessage": "User login to Okta",
"actor": {
"id": "00u1a2b3c4d5e6f7g8h9",
"type": "User",
"alternateId": "jane.doe@example.com",
"displayName": "Jane Doe"
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0"
},
"ipAddress": "203.0.113.5",
"geographicalContext": {
"country": "United States",
"city": "Austin"
}
},
"outcome": {
"result": "SUCCESS"
},
"target": []
}
]
}
}Start receiving Okta webhooks
Create a source, paste the URL into Okta, and watch the first event arrive. The free tier includes 1,000 events a month.
Get Started Free