Use standard private-app boundaries
Okta documents OIDC and SAML for sign-in and SCIM for automated identity lifecycle. AI Gateway HQ keeps those functions explicit so enabling single sign-on does not silently enable directory mutation.
Owner-managed OIDC or SAML 2.0 sign-in, exact Okta group-to-built-in-role rules, and connection-bound SCIM 2.0 user/group lifecycle with optional active-user login enforcement; live Okta conformance remains planned.
Beta connections require customer validation against the exact model, payload, streaming mode, region, and provider account before production use.
AIGHQ_BASE_URL=https://api.aigatewayhq.com/v1
AIGHQ_API_KEY=from-your-workspace
AIGHQ_MODEL=company-approved-fastApplications keep a stable gateway URL and model alias while an administrator changes eligible provider accounts and models.
An organization owner creates a private Okta application connection, validates the issuer or signed SAML metadata, maps exact Okta groups to built-in roles, and separately enables the connection-bound SCIM bearer. Live Okta conformance remains a planned gate.
Compatibility is bounded to the provider's current published interface. Review the provider documentation before approving a production model.