Okta SCIM Provisioning for Upwave

Connect Okta to your Upwave workspace and let Okta manage the full user lifecycle: provisioning, entitlement assignment, and removal. Redblock sits between Okta and Upwave as a certified SCIM bridge, so Upwave behaves like any other SCIM-enabled app in your Okta org.

Setup takes about 30 minutes end to end. You'll spend most of it in two consoles: Redblock AI Studio (where a certified Upwave Agent does the heavy lifting) and your Okta Admin Console.

Okta
Redblock SCIM Endpoint
Certified Upwave Agent
Upwave

Every SCIM request Okta sends is executed in Upwave by a Redblock certified Agent: a pre-trained, pre-certified automation that already knows how to create accounts, assign entitlements, and remove users in Upwave. You never train anything. You connect a service account, activate a blueprint, and hand two values to Okta.

This integration is published in the Okta Integration Network (OIN) as Upwave By Redblock and runs over the standard SCIM 2.0 protocol with header authentication.

Prerequisites

What you need:

  • Redblock AI Studio access. New to Redblock? Write to support@redblock.ai and our team will provision your tenant
  • An Upwave service account: email, password, and your workspace login URL. If the account uses MFA, have its TOTP seed ready
  • Okta admin access with permission to add applications and configure provisioning
  • Entitlement Management available in your Okta org (part of Okta Identity Governance) if you want entitlement assignment through Okta

Supported Features

  • Create Users: Users assigned to the application in Okta are created in Upwave
  • Deactivate Users: Users unassigned or deactivated in Okta are removed from Upwave. Upwave accounts are removed, not suspended
  • Entitlement Management: Upwave roles surface in Okta as entitlements, so access changes flow through Okta
  • Import New Users: Existing Upwave accounts are imported into Okta and matched to Okta users for assignment
  • Import Profile Updates: Attribute changes made in Upwave are reflected in Okta on each import
  • Update User Attributes: Entitlement updates (role changes) from Okta to Upwave are supported. Profile attribute updates from Okta to Upwave are not supported

Not supported today: Profile attribute updates from Okta to Upwave, password sync, Import Groups, and Group Push. See Troubleshoot.

Configuration Steps

These steps follow your journey end to end: add the integration in Okta, get Redblock AI Studio access, complete the setup through the AI Studio Product Guide, then finish the provisioning configuration in Okta with the two values you collected.

Add the Upwave By Redblock integration

  1. In the Okta Admin Console, go to Applications → Applications and click Browse App Catalog.
  2. Search for Upwave By Redblock and open the SCIM integration.
Okta App Integration Catalog search showing Upwave By Redblock

Upwave By Redblock in the Okta App Integration Catalog

  1. Click Add Integration.
Upwave By Redblock catalog page with the Add Integration button

Upwave By Redblock integration page

  1. In General Settings, set the Application label (we recommend your Redblock activation name, so the two consoles stay easy to correlate) and paste the Redblock SCIM Base URL from your AI Studio activation. Complete setup in the AI Studio Product Guide below shows where to find it.
  2. Click Done.
Add Upwave By Redblock wizard with Application label and Redblock SCIM Base URL fields

General Settings: application label and Redblock SCIM Base URL

You can review or update the SCIM Base URL any time on the application's General tab, under App Settings.

Upwave By Redblock General tab showing the Redblock SCIM Base URL setting

App Settings on the General tab

Get Redblock AI Studio access

Provisioning for Upwave runs through Redblock AI Studio. If your organization does not have AI Studio yet, write to support@redblock.ai or contact your Redblock account team. They will provision your tenant and share your console URL and admin credentials.

Console URLs are specific to your activation: SaaS tenants and VPC-hosted activations use different domains, so use the address your account team shares.

Complete setup in the AI Studio Product Guide

Detailed, screenshot-by-screenshot instructions for the Upwave flow live in the AI Studio Product Guide, right inside your console:

  1. Sign in to your Redblock AI Studio console.
  2. Click your username initials at the bottom-left corner and click Product Guide.
User menu with the Product Guide option

Product Guide opens from the user menu

  1. Scroll down to the All Sections area and open Integrations. Follow the Upwave setup guide for Okta SCIM end to end. In about 15 minutes you will add the certified Upwave Agent, connect its identity with your Upwave service account, create the activation from the Upwave Okta SCIM Activation blueprint, run Account Aggregation once, and activate.

When you finish, you'll have the two values Okta needs:

  • SCIM Base URL: shown in your activation's Review & Activate → Activate section, in the format https://<your-api-domain>/<activation-id>/scim/v2. Copy it exactly as your console shows it.
  • Access Key: generated from the Access Keys page. Copy it when it is shown and store it in your credential vault; you'll paste it into Okta as the API Token.

Verify: your activation shows Activated, and you have the SCIM Base URL and a fresh Access Key stored somewhere safe.

Back in Okta, finish the provisioning configuration with the steps below.

Enable Entitlement Management

  1. Open the application's General tab and click Edit.
  2. Set the Entitlement Management dropdown to Enabled and click Save.
Entitlement management dropdown set to Enabled

Enable Entitlement Management on the General tab

Configure the SCIM connection

  1. Open the Provisioning tab and click Configure API Integration.
  2. Check Enable API Integration.
  3. Set the API Token to the Access Key you generated in AI Studio.
  4. Uncheck Import Groups.
  5. Click Test API Credentials and confirm the connection succeeds, then click Save.

Verify entitlements

  1. Open the application's Governance section.
  2. Confirm the Upwave roles populated automatically. Redblock aggregates them from your workspace, so what you see in Okta matches what exists in Upwave.

Map attributes and import users

  1. Open the application's Profile Editor.
  2. Click Add Attribute, select Display Name, and save the changes.
  3. Go to Mappings:
    1. Map displayName in both directions:
      • App User → Okta User
      • Okta User → App User
    2. Confirm that the userName mapping exists for App User → Okta User. Add it if it is missing.
    3. Click Save Mappings and apply the updates.
  4. Return to the application, open the Import tab, and click Import Now.
  5. Review the imported Upwave accounts, select the assignments you want, and click Confirm Assignments.

Verify: Test API Credentials passes, imported Upwave users show Okta assignment matches, and Upwave roles are visible under Governance.

Test the Integration

Before rolling out to real users, push one test user through the full loop.

  1. In Okta, assign a test user to the application (Assign → Assign to People), selecting an entitlement.
  2. Give the provisioning event a minute to process. Behind the scenes, the Agent signs in to Upwave and creates the account for you.
  3. In Redblock AI Studio, open your activation's Logs tab. You'll see the SCIM request and the resulting operation, with full execution detail.
  4. Confirm the user exists in Upwave with the expected role.

Verify: the test user appears in Upwave with the role you assigned, and the activation Logs show the completed operation.

Common Operations

To do this in OktaDo this
Add a user On the application, click Assign → Assign to People, pick the user and entitlement, and save.
Change a user's entitlements On the Assignments tab, open the user's menu → View access detailsManage accessCustomize entitlements, pick the new value, and save.
Remove a user On the Assignments tab, open the user's menu and select Unassign.
Note

Change a user's entitlements works only for Active users. If you try it for pending-invite users, it fails because Upwave does not allow changing the role for those users.

Note

It could take up to 4 to 6 minutes for user creation, deactivation, and role changes to reflect in Upwave.

Troubleshoot

Profile updates from Okta do not appear in Upwave. Profile attribute updates from Okta to Upwave are not supported today: after an account is created, attribute changes pushed from Okta are not applied in Upwave. Entitlement updates (role changes) do flow from Okta to Upwave. For profile attributes, make the change in Upwave directly; it reflects in Okta on the next import.

Test API Credentials fails. Check three things: the SCIM Base URL on the General tab must end in /scim/v2 (Okta appends resource paths itself), the API Token must be a current Access Key, and the activation must show Activated in AI Studio. Keys also expire on the schedule you set; confirm yours is Active on the Access Keys page.

A user provisions in Okta but never appears in Upwave. Open the activation's Logs tab in AI Studio. If the SCIM request arrived but the operation failed, the log shows where. A common cause is an Agent identity that has stopped validating; check the Agent's Authentication Status.

401 Unauthorized on SCIM calls. Your Access Key was revoked, expired, or pasted with extra characters. Generate a fresh key in AI Studio, update the Okta API Token, and re-test.

Support

Stuck, or setting up at scale? Write to support@redblock.ai and include your activation ID (the act-… value from the Activations page). Our team can read the activation's audit trail end to end and pinpoint where a request stopped.