> ## Documentation Index
> Fetch the complete documentation index at: https://wundergraphinc-ahmet-router-592-mcp-add-structured-tool-out.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Okta (OIN version)

> Configure SCIM with Okta using the app from OIN.

### Steps to set up SCIM with Okta

<Steps>
  <Step>
    Set up the password policy (password should contain at least one number and one symbol), if using the **Classic Engine on Okta** follow the below steps**,** or if using the  **OIE engine,**follow the steps as mentioned in this  \*\*\*\*[**Okta guide**](https://help.okta.com/oie/en-us/content/topics/identity-engine/authenticators/configure-password.htm)**.**

    * Navigate to Security -> Authentication on your Okta Administrator Dashboard.

    * Click Edit and update the password policy by enabling Number and Symbol, then click on Update Policy.

    <Frame>
      <img src="https://mintcdn.com/wundergraphinc-ahmet-router-592-mcp-add-structured-tool-out/3l84hl-BrF9Nndag/images/studio/scim/authentication-policy-editing-in-okta.png?fit=max&auto=format&n=3l84hl-BrF9Nndag&q=85&s=965418bf8dc24ee3ac5db41f1b160e4e" alt="Authentication policy editing in Okta" title="Authentication policy editing in Okta" width="2304" height="1187" data-path="images/studio/scim/authentication-policy-editing-in-okta.png" />
    </Frame>
  </Step>

  <Step>
    Navigate to the Applications view within your Okta Administrator Dashboard.
  </Step>

  <Step>
    Click on **Browse App Catalog.**

    <Frame>
      <img src="https://mintcdn.com/wundergraphinc-ahmet-router-592-mcp-add-structured-tool-out/3l84hl-BrF9Nndag/images/studio/scim/browse-app-catalog-in-okta-applications.png?fit=max&auto=format&n=3l84hl-BrF9Nndag&q=85&s=12626f1e7ef5fe6aac25a935a976ca5b" alt="Browse App Catalog in Okta Applications" title="Browse App Catalog in Okta Applications" width="2304" height="1277" data-path="images/studio/scim/browse-app-catalog-in-okta-applications.png" />
    </Frame>
  </Step>

  <Step>
    Search for **Wundergraph Cosmo.**
  </Step>

  <Step>
    Click on **Add Integration**.

    <Frame>
      <img src="https://mintcdn.com/wundergraphinc-ahmet-router-592-mcp-add-structured-tool-out/3l84hl-BrF9Nndag/images/studio/scim/add-wundergraph-cosmo-integration.png?fit=max&auto=format&n=3l84hl-BrF9Nndag&q=85&s=e473223b0d07044ef33d89279eaf0eeb" alt="Add WunderGraph Cosmo integration" title="Add WunderGraph Cosmo integration" width="2304" height="1270" data-path="images/studio/scim/add-wundergraph-cosmo-integration.png" />
    </Frame>
  </Step>

  <Step>
    Now give the app a name and then click on **Next.**
  </Step>

  <Step>
    Select **Administrator sets username, user sets password** and for **Application username format** under **Credentials Details** select  **Email**and then click **Done.**

    <Frame>
      <img src="https://mintcdn.com/wundergraphinc-ahmet-router-592-mcp-add-structured-tool-out/3l84hl-BrF9Nndag/images/studio/scim/wundergraph-cosmo-sign-on-setup.png?fit=max&auto=format&n=3l84hl-BrF9Nndag&q=85&s=fb1949e7d9c7f2debaf41bbe86ed84a2" alt="WunderGraph Cosmo sign-on setup" title="WunderGraph Cosmo sign-on-setup" width="2304" height="1181" data-path="images/studio/scim/wundergraph-cosmo-sign-on-setup.png" />
    </Frame>
  </Step>

  <Step>
    Navigate to the settings page on WunderGraph Cosmo and enable **SCIM.**

    <Frame>
      <img src="https://mintcdn.com/wundergraphinc-ahmet-router-592-mcp-add-structured-tool-out/3l84hl-BrF9Nndag/images/studio/scim/generative-ai-enable-option-in-cosmo.png?fit=max&auto=format&n=3l84hl-BrF9Nndag&q=85&s=f2926384e657f16e96b47c8f60cf7ab5" alt="Generative AI enable option in Cosmo" title="Generative AI enable option in Cosmo" width="2304" height="1249" data-path="images/studio/scim/generative-ai-enable-option-in-cosmo.png" />
    </Frame>
  </Step>

  <Step>
    Once SCIM is enabled, you will be provided with a  **SCIM Server URL,**copy it**.**
  </Step>

  <Step>
    Navigate to the API Keys page on WunderGraph Cosmo and click on New API Key.
  </Step>

  <Step>
    Provide the key with a name, select **Never** for **Expires,** then select  **SCIM**under **Permissions, t**hen click on **Generate API key.**

    <Frame>
      <img src="https://mintcdn.com/wundergraphinc-ahmet-router-592-mcp-add-structured-tool-out/3l84hl-BrF9Nndag/images/studio/scim/create-scim-api-key.png?fit=max&auto=format&n=3l84hl-BrF9Nndag&q=85&s=1161b7b301a052e52b85c5b1d40db736" alt="Create SCIM API key" title="Create SCIM API key" width="1600" height="873" data-path="images/studio/scim/create-scim-api-key.png" />
    </Frame>
  </Step>

  <Step>
    Copy the API key provided.
  </Step>

  <Step>
    Navigate to the provisioning tab of the app created on okta, then click on **Configure API Integration**.

    <Frame>
      <img src="https://mintcdn.com/wundergraphinc-ahmet-router-592-mcp-add-structured-tool-out/3l84hl-BrF9Nndag/images/studio/scim/configure-api-integration-for-wundergraph-cosmo.png?fit=max&auto=format&n=3l84hl-BrF9Nndag&q=85&s=acd5e4717bb9fc44285136ecf991fb70" alt="Configure API Integration for WunderGraph Cosmo" title="Configure API Integration for WunderGraph Cosmo" width="2304" height="1264" data-path="images/studio/scim/configure-api-integration-for-wundergraph-cosmo.png" />
    </Frame>
  </Step>

  <Step>
    Check the **Enable API Integration** and then populate the  **API token**with the  **API key**copied in the previous steps.
  </Step>

  <Step>
    Click on **Test API Credentials** and once it's verified successfully, click on **Save**
  </Step>

  <Step>
    Navigate to the "**to App"** tab**, and** click on **Edit.**

    <Frame>
      <img src="https://mintcdn.com/wundergraphinc-ahmet-router-592-mcp-add-structured-tool-out/3l84hl-BrF9Nndag/images/studio/scim/test-app-to-app-provisioning-setup.png?fit=max&auto=format&n=3l84hl-BrF9Nndag&q=85&s=c99f722e60e5855f65d64e012487c9b0" alt="Test app To App provisioning setup" title="Test app To App provisioning setup" width="2304" height="1188" data-path="images/studio/scim/test-app-to-app-provisioning-setup.png" />
    </Frame>
  </Step>

  <Step>
    Enable  **Create Users, Update User Attributes, Deactivate Users**and **Sync Password.**
  </Step>

  <Step>
    Under **Sync Password** for **Password type**, select **Sync Okta Password.**

    <Frame>
      <img src="https://mintcdn.com/wundergraphinc-ahmet-router-592-mcp-add-structured-tool-out/3l84hl-BrF9Nndag/images/studio/scim/provisioning-to-app-user-setup.png?fit=max&auto=format&n=3l84hl-BrF9Nndag&q=85&s=523c00fd2c5b3f840390a5c7a7ad9e06" alt="Provisioning to App user setup" title="Provisioning to App user setup" width="1004" height="906" data-path="images/studio/scim/provisioning-to-app-user-setup.png" />
    </Frame>
  </Step>

  <Step>
    Click **save.**
  </Step>

  <Step>
    Now you can navigate the Assignments tab and assign users/groups who should have access to WunderGraph Cosmo.
  </Step>
</Steps>

<Info>
  If you are using both **SSO with OIDC** and **SCIM**, please make sure that the users assigned in both apps are the same.
</Info>
