---
title: Okta
slug: okta
docTags: 
createdAt: 2021-09-29T02:09:13.000Z
---

The **Okta** app automatically updates your Okta profiles with ChartHop source data. You can configure both Okta profile fields and group memberships. Optionally, you can set the app to create Okta profiles when people are added to ChartHop.

When you install Okta, you'll need to make decisions about how you want to handle Okta profiles, whether you set a default location, and what fields you want to include in your sync.

| **Field**                        | **Description**                                                                                                                       |
| -------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------- |
| Okta profiles                    | - Automatically create new Okta profiles from ChartHop on sync
- Don’t create new profiles only update existing Okta profiles on sync |
| Sync new hires before start date | The number of days before a start date to begin syncing new hires                                                                     |

## Obtain Okta API credentials

You will need to obtain API access from Okta before you can install the app. To obtain an Okta API key, follow the steps outlined in their help document [here](https://support.okta.com/help/s/article/How-do-I-create-an-API-token?language=en_US).

:::hint{type="info"}
- To connect Okta to ChartHop, you must be an *Okta administrator*.
- Once you've received the API token from Okta, do not share this information with anyone outside of your organization.
:::

## Install the Okta app

To install the **Okta** app, follow the steps below.

1. From the left sidebar, select **Apps & Bundles**.
2. From the sub-menu, select **Apps**.
3. Select the **Availible Apps** tab.
4. Locate and select the **Okta** app.
5. Select **Install**.
6. Follow the steps outlined in the setup wizard to connect the Okta app to ChartHop.

## &#x20;Configure Lifecycle & Provisioning Settings

Once the app is installed, you must configure how ChartHop handles new hires, re-hires, and departures. These settings determine when an Okta profile is created and when access is revoked.

### Basic Settings

Access these by selecting **Edit** under the **Basic Settings** section of the Okta app.

| **Setting**                                   | **Description**                                                                                                                                               |
| --------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Create Okta profiles for new hires**        | When enabled, ChartHop automatically creates an Okta record for any new person added to the platform.                                                         |
| **Re-activate Okta profiles for re-hires**    | When enabled, ChartHop identifies returning employees and re-activates their existing (inactive) Okta profile rather than creating a duplicate.               |
| **De-activate Okta profiles on departures**   | Automates the de-activation of Okta accounts based on the termination date in ChartHop.                                                                       |
| **De-activate same-day voluntary departures** | If checked, you can set a specific **deactivation Time** (e.g., 11:00 PM). This allows voluntary leavers to maintain access until the end of their final day. |
| **Send email and activate upon creation**     | Determines if the account is immediately activated or remains in a "staged" state. *Note: Test this to ensure it aligns with your onboarding workflow.*       |

## Automated De-activation Logic

ChartHop performs a daily sync to manage departures based on the following rules:

- **Past Departures:** Any employee terminated **yesterday** (voluntary or involuntary) who remains active in Okta will be deactivated during the morning sync.
- **Involuntary Departures:** If event-based sync is active, these users are typically deactivated immediately upon the termination being entered.
- **Voluntary Departures:** These users are deactivated once per day at the designated cutoff time (e.g., 11:00 PM ET) to ensure they have access for their full final shift.

## Run a single, on-demand sync to Okta

Any ChartHop user with sufficient permissions can trigger an on-demand sync to Okta at any time. To sync your data for the first time, or subsequently, on-demand at any time, follow the steps below.

1. From the left sidebar, select **Apps & Bundles**.
2. From the sub-menu, select **Apps**.
3. Select the **Installed Apps** tab.
4. Locate and select the **Okta** app in the list of installed apps.
5. At the top of the page, select **Run one-time sync**.
6. Select **Run sync&#x20;**&#x74;o perform the sync.&#x20;

### Export dry runs

Any ChartHop user with sufficient permissions can trigger a test integration between Okta and ChartHop at any time.&#x20;

1. From the left sidebar, select **Apps & Bundles**.
2. From the sub-menu, select **Apps**.
3. Select the **Installed Apps** tab.
4. Locate and select the **Okta** app in the list of available apps.
5. At the top of the page, select **Run one-time sync**.
6. Select **Export dry run** to test the integration.
7. When the integration is complete, select **Download** to recieve the test results file.

### Create sync groups

You can create and populate Okta groups from the app config page by following the steps below.

1. From the left sidebar, select **Apps & Bundles**.
2. From the sub-menu, select **Apps**.
3. Select the **Installed Apps** tab.
4. Locate and select the **Okta** app in the list of available apps.
5. Under the **Advanced Settings** section, select **Edit**.&#x20;
6. Under the **Sync Groups&#x20;**&#x73;ection, select **+ Add group.**
7. Enter a name for the group in the **Group Name** field.
8. Enter a corresponding Carrot query in the **Include People Matching** field, or use the filter controls to the left.
9. Select **test** to confirm your query. It should open the Data Sheet in a new tab with your query applied.
10. Select **Save** at the bottom of the page.

### Create sync profile fields

For each custom Okta profile field, you may define a ChartHop field or expression to be synced. To do this, follow the steps below.

1. From the left sidebar, select **Apps & Bundles**.
2. From the sub-menu, select **Apps**.
3. Select the **Installed Apps** tab.
4. Locate and select the **Okta** app in the list of available apps.
5. Under the **Advanced Settings** section, select **Edit**.&#x20;
6. Under the **Sync Profile Fields&#x20;**&#x73;ection, select + **Add field**.
7. Enter the name of a custom Okta profile field that you wish to populate with data.
8. Enter the corresponding query or field that you wish to copy from ChartHop.
9. Select **Save** at the bottom of the page

**Common Expression Examples**

Use these common expressions to map ChartHop data to Okta fields:

| **Okta Field Name** | **ChartHop Expression** | **Description**                                                                      |
| ------------------- | ----------------------- | ------------------------------------------------------------------------------------ |
| managerEmail        | manager.email           | Pulls the primary email of the employee's direct manager.                            |
| deptCode            | department.code         | Syncs the short-hand code for the department (e.g., "ENG" instead of "Engineering"). |
| costCenter          | custom.cost\_center     | Pulls a custom field value defined in your ChartHop instance.                        |
| isManager           | is\_manager             | A boolean (true/false) based on whether the person has direct reports.               |

### Supported Attributes

The following SAML attributes are supported:

| **Attribute name** | **Name format** | **Value**                  |
| ------------------ | --------------- | -------------------------- |
| org                | unspecified     | `{org-slug-from-ChartHop}` |
| email              | unspecified     | `user.email`               |
| first\_name        | unspecified     | `user.firstName`           |
| last\_name         | unspecified     | `user.lastName`            |

:::hint{type="info"}
[Modules](https://www.charthop.com/pricing/)**:&#x20;**<font color="#000000">**HRIS** | </font>Engagement | Goals | Performance | <font color="#000000">Compensation Reviews | </font>Headcount Planning
:::

