Okta SCIM Provisioning for Upwave
Connect Okta to your Upwave workspace and let Okta manage the full user lifecycle: provisioning, entitlement assignment, and removal. Redblock sits between Okta and Upwave as a certified SCIM bridge, so Upwave behaves like any other SCIM-enabled app in your Okta org.
Setup takes about 30 minutes end to end. You'll spend most of it in two consoles: Redblock AI Studio (where a certified Upwave Agent does the heavy lifting) and your Okta Admin Console.
Every SCIM request Okta sends is executed in Upwave by a Redblock certified Agent: a pre-trained, pre-certified automation that already knows how to create accounts, assign entitlements, and remove users in Upwave. You never train anything. You connect a service account, activate a blueprint, and hand two values to Okta.
This integration is published in the Okta Integration Network (OIN) as Upwave By Redblock and runs over the standard SCIM 2.0 protocol with header authentication.
Prerequisites
What you need:
- Redblock AI Studio access. New to Redblock? Write to support@redblock.ai and our team will provision your tenant
- An Upwave service account: email, password, and your workspace login URL. If the account uses MFA, have its TOTP seed ready
- Okta admin access with permission to add applications and configure provisioning
- Entitlement Management available in your Okta org (part of Okta Identity Governance) if you want entitlement assignment through Okta
Supported Features
- Create Users: Users assigned to the application in Okta are created in Upwave
- Deactivate Users: Users unassigned or deactivated in Okta are removed from Upwave. Upwave accounts are removed, not suspended
- Entitlement Management: Upwave roles surface in Okta as entitlements, so access changes flow through Okta
- Import New Users: Existing Upwave accounts are imported into Okta and matched to Okta users for assignment
- Import Profile Updates: Attribute changes made in Upwave are reflected in Okta on each import
- Update User Attributes: Entitlement updates (role changes) from Okta to Upwave are supported. Profile attribute updates from Okta to Upwave are not supported
Not supported today: Profile attribute updates from Okta to Upwave, password sync, Import Groups, and Group Push. See Troubleshoot.
Configuration Steps
These steps follow your journey end to end: add the integration in Okta, get Redblock AI Studio access, complete the setup through the AI Studio Product Guide, then finish the provisioning configuration in Okta with the two values you collected.
Add the Upwave By Redblock integration
- In the Okta Admin Console, go to Applications → Applications and click Browse App Catalog.
- Search for Upwave By Redblock and open the SCIM integration.
Upwave By Redblock in the Okta App Integration Catalog
- Click Add Integration.
Upwave By Redblock integration page
- In General Settings, set the Application label (we recommend your Redblock activation name, so the two consoles stay easy to correlate) and paste the Redblock SCIM Base URL from your AI Studio activation. Complete setup in the AI Studio Product Guide below shows where to find it.
- Click Done.
General Settings: application label and Redblock SCIM Base URL
You can review or update the SCIM Base URL any time on the application's General tab, under App Settings.
App Settings on the General tab
Get Redblock AI Studio access
Provisioning for Upwave runs through Redblock AI Studio. If your organization does not have AI Studio yet, write to support@redblock.ai or contact your Redblock account team. They will provision your tenant and share your console URL and admin credentials.
Console URLs are specific to your activation: SaaS tenants and VPC-hosted activations use different domains, so use the address your account team shares.
Complete setup in the AI Studio Product Guide
Detailed, screenshot-by-screenshot instructions for the Upwave flow live in the AI Studio Product Guide, right inside your console:
- Sign in to your Redblock AI Studio console.
- Click your username initials at the bottom-left corner and click Product Guide.
Product Guide opens from the user menu
- Scroll down to the All Sections area and open Integrations. Follow the Upwave setup guide for Okta SCIM end to end. In about 15 minutes you will add the certified Upwave Agent, connect its identity with your Upwave service account, create the activation from the Upwave Okta SCIM Activation blueprint, run Account Aggregation once, and activate.
When you finish, you'll have the two values Okta needs:
- SCIM Base URL: shown in your activation's
Review & Activate → Activate section, in the format
https://<your-api-domain>/<activation-id>/scim/v2. Copy it exactly as your console shows it. - Access Key: generated from the Access Keys page. Copy it when it is shown and store it in your credential vault; you'll paste it into Okta as the API Token.
Verify: your activation shows Activated, and you have the SCIM Base URL and a fresh Access Key stored somewhere safe.
Back in Okta, finish the provisioning configuration with the steps below.
Enable Entitlement Management
- Open the application's General tab and click Edit.
- Set the Entitlement Management dropdown to Enabled and click Save.
Enable Entitlement Management on the General tab
Configure the SCIM connection
- Open the Provisioning tab and click Configure API Integration.
- Check Enable API Integration.
- Set the API Token to the Access Key you generated in AI Studio.
- Uncheck Import Groups.
- Click Test API Credentials and confirm the connection succeeds, then click Save.
Verify entitlements
- Open the application's Governance section.
- Confirm the Upwave roles populated automatically. Redblock aggregates them from your workspace, so what you see in Okta matches what exists in Upwave.
Map attributes and import users
- Open the application's Profile Editor.
- Click Add Attribute, select Display Name, and save the changes.
-
Go to Mappings:
-
Map
displayNamein both directions:- App User → Okta User
- Okta User → App User
- Confirm that the
userNamemapping exists for App User → Okta User. Add it if it is missing. - Click Save Mappings and apply the updates.
-
Map
- Return to the application, open the Import tab, and click Import Now.
- Review the imported Upwave accounts, select the assignments you want, and click Confirm Assignments.
Verify: Test API Credentials passes, imported Upwave users show Okta assignment matches, and Upwave roles are visible under Governance.
Test the Integration
Before rolling out to real users, push one test user through the full loop.
- In Okta, assign a test user to the application (Assign → Assign to People), selecting an entitlement.
- Give the provisioning event a minute to process. Behind the scenes, the Agent signs in to Upwave and creates the account for you.
- In Redblock AI Studio, open your activation's Logs tab. You'll see the SCIM request and the resulting operation, with full execution detail.
- Confirm the user exists in Upwave with the expected role.
Verify: the test user appears in Upwave with the role you assigned, and the activation Logs show the completed operation.
Common Operations
| To do this in Okta | Do this |
|---|---|
| Add a user | On the application, click Assign → Assign to People, pick the user and entitlement, and save. |
| Change a user's entitlements | On the Assignments tab, open the user's ⋮ menu → View access details → Manage access → Customize entitlements, pick the new value, and save. |
| Remove a user | On the Assignments tab, open the user's ⋮ menu and select Unassign. |
Change a user's entitlements works only for Active users. If you try it for pending-invite users, it fails because Upwave does not allow changing the role for those users.
It could take up to 4 to 6 minutes for user creation, deactivation, and role changes to reflect in Upwave.
Troubleshoot
Profile updates from Okta do not appear in Upwave. Profile attribute updates from Okta to Upwave are not supported today: after an account is created, attribute changes pushed from Okta are not applied in Upwave. Entitlement updates (role changes) do flow from Okta to Upwave. For profile attributes, make the change in Upwave directly; it reflects in Okta on the next import.
Test API Credentials fails. Check three things: the SCIM
Base URL on the General tab must end in /scim/v2 (Okta appends
resource paths itself), the API Token must be a current Access Key, and the
activation must show Activated in AI Studio. Keys also expire
on the schedule you set; confirm yours is Active on the
Access Keys page.
A user provisions in Okta but never appears in Upwave. Open the activation's Logs tab in AI Studio. If the SCIM request arrived but the operation failed, the log shows where. A common cause is an Agent identity that has stopped validating; check the Agent's Authentication Status.
401 Unauthorized on SCIM calls. Your Access Key was revoked, expired, or pasted with extra characters. Generate a fresh key in AI Studio, update the Okta API Token, and re-test.
Support
Stuck, or setting up at scale? Write to
support@redblock.ai and include your
activation ID (the act-… value from the Activations page). Our
team can read the activation's audit trail end to end and pinpoint where a
request stopped.