Identity · Identity + SCIM

Connect Okta without creating a second permission model.

Owner-managed OIDC or SAML 2.0 sign-in, exact Okta group-to-built-in-role rules, and connection-bound SCIM 2.0 user/group lifecycle with optional active-user login enforcement; live Okta conformance remains planned.

How the connection works

Provider access stays separate from application control.

01

Use standard private-app boundaries

Okta documents OIDC and SAML for sign-in and SCIM for automated identity lifecycle. AI Gateway HQ keeps those functions explicit so enabling single sign-on does not silently enable directory mutation.

02

Map exact groups to fixed roles

An organization owner chooses the external group values that map to built-in gateway roles. Access is evaluated through that reviewed connection rather than granting broad permissions from a partial group or email match.

03

State what remains unproved

The owner-managed protocol path is implemented, while live Okta conformance and a public Okta Integration Network listing remain unproved. Customers can evaluate a private integration without treating Beta evidence as third-party validation.

Current shared controls

Status determines what can be configured.

Write-only, encrypted BYOK for implemented provider connections Stable model aliases and protocol-eligible route targets Organization and key budgets, RPM, TPM, and concurrency hard limits Observe, Shadow, Enforce, reason codes, and metadata-only evidence

Beta connections require customer validation against the exact model, payload, streaming mode, region, and provider account before production use.

Client boundary
AIGHQ_BASE_URL=https://api.aigatewayhq.com/v1
AIGHQ_API_KEY=from-your-workspace
AIGHQ_MODEL=company-approved-fast

Applications keep a stable gateway URL and model alias while an administrator changes eligible provider accounts and models.

Implemented boundary

Only documented protocols become eligible.

An organization owner creates a private Okta application connection, validates the issuer or signed SAML metadata, maps exact Okta groups to built-in roles, and separately enables the connection-bound SCIM bearer. Live Okta conformance remains a planned gate.

OIDC or SAML 2.0 sign-in SCIM 2.0 Users and Groups Exact group-to-built-in-role rules

Compatibility is bounded to the provider's current published interface. Review the provider documentation before approving a production model.