Skip to main content
POST
Create app

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Body

application/json

Information needed to create an app. Currently supports only Push-only apps (CUSTOM) and Custom Connector apps (CUSTOM_CONNECTOR).

name
string
required

The name of the app.

Example:

"My Push-only App"

description
string
required

A description of the app.

Example:

"Bookkeeping app for internal tools."

admin_owner_id
string<uuid>
required

The ID of the owner of the app.

Example:

"7c86c85d-0651-43e2-a748-d69d658418e8"

app_type
enum<string>
required

The type of the app. Must be CUSTOM (Push-only App) or CUSTOM_CONNECTOR.

Available options:
ACTIVE_DIRECTORY,
ANTHROPIC,
AZURE_AD,
AWS,
AWS_SSO,
CLICKHOUSE,
COUPA,
CURSOR,
CUSTOM,
CONFLUENCE,
CUSTOM_CONNECTOR,
DATABRICKS,
DATASTAX_ASTRA,
ALICLOUD,
DEVIN,
DOCUSIGN,
DUO,
GCP,
GIT_HUB,
GIT_LAB,
GOOGLE_GROUPS,
GOOGLE_WORKSPACE,
GRAFANA,
HUBSPOT,
ILEVEL,
INCIDENTIO,
JIRA,
LDAP,
LINEAR,
MARIADB,
MONGO,
MONGO_ATLAS,
MYSQL,
NETSUITE,
DATADOG,
OKTA_CIAM,
OKTA_DIRECTORY,
OPENAI_PLATFORM,
OPAL,
ORACLE_FUSION,
PAGERDUTY,
POSTGRES,
ROOTLY,
SALESFORCE,
SNOWFLAKE,
SLACK,
TABLEAU,
TAILSCALE,
TELEPORT,
TWINGATE,
VAULT,
WORKDAY,
ZENDESK,
ZOOM,
RAMP,
WRIKE,
VERCEL,
AXIOM
Example:

"OKTA_DIRECTORY"

visibility
enum<string>

The visibility of the app. Defaults to GLOBAL when omitted.

Available options:
GLOBAL,
LIMITED
Example:

"GLOBAL"

visibility_group_ids
string<uuid>[]

The IDs of groups that can see this app when visibility is LIMITED.

import_visibility
enum<string>

The visibility of imported items. Defaults to GLOBAL when omitted.

Available options:
GLOBAL,
LIMITED
Example:

"GLOBAL"

custom_connector
object

Required when app_type is CUSTOM_CONNECTOR. Must not be set when app_type is CUSTOM.

Response

200 - application/json

The app that was created.

App Object

Description

The App object is used to represent an app to an application.

Usage Example

List from the GET Apps endpoint.

app_id
string<uuid>
required

The ID of the app.

Example:

"f454d283-ca87-4a8a-bdbb-df212eca5353"

name
string
required

The name of the app.

Example:

"Okta Org"

description
string
required

A description of the app.

Example:

"Okta directory for the engineering team."

admin_owner_id
string<uuid>
required

The ID of the owner of the app.

Example:

"7c86c85d-0651-43e2-a748-d69d658418e8"

app_type
enum<string>
required

The type of an app.

Available options:
ACTIVE_DIRECTORY,
ANTHROPIC,
AZURE_AD,
AWS,
AWS_SSO,
CLICKHOUSE,
COUPA,
CURSOR,
CUSTOM,
CONFLUENCE,
CUSTOM_CONNECTOR,
DATABRICKS,
DATASTAX_ASTRA,
ALICLOUD,
DEVIN,
DOCUSIGN,
DUO,
GCP,
GIT_HUB,
GIT_LAB,
GOOGLE_GROUPS,
GOOGLE_WORKSPACE,
GRAFANA,
HUBSPOT,
ILEVEL,
INCIDENTIO,
JIRA,
LDAP,
LINEAR,
MARIADB,
MONGO,
MONGO_ATLAS,
MYSQL,
NETSUITE,
DATADOG,
OKTA_CIAM,
OKTA_DIRECTORY,
OPENAI_PLATFORM,
OPAL,
ORACLE_FUSION,
PAGERDUTY,
POSTGRES,
ROOTLY,
SALESFORCE,
SNOWFLAKE,
SLACK,
TABLEAU,
TAILSCALE,
TELEPORT,
TWINGATE,
VAULT,
WORKDAY,
ZENDESK,
ZOOM,
RAMP,
WRIKE,
VERCEL,
AXIOM
Example:

"OKTA_DIRECTORY"

visibility
enum<string>

The visibility level of the entity.

Available options:
GLOBAL,
LIMITED
Example:

"GLOBAL"

validations
object[]

Validation checks of an apps' configuration and permissions.

custom_connector
object

Configuration for a Custom Connector app. Does not include the signing secret; secrets are write-only and never returned by the API.

Last modified on October 5, 2026