> For the complete documentation index, see [llms.txt](https://docs.lithnet.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lithnet.io/okta-ma/authentication/api-token.md).

# API token

Create an Okta API token and configure it in MIM.

## Step 1: Choose the Okta account

An API token inherits the Okta permissions of the account that creates it, and stops working if that account is deactivated. Use a dedicated account rather than an administrator's personal account, so that the connector's access isn't tied to a specific person.

Give the account administrative access covering the users, groups, and operations MIM will manage.

## Step 2: Create the token

1. Sign in to the Okta Admin Console as that account.
2. Open **Security** > **API** > **Tokens**.
3. Select **Create token**.
4. Name it after the MIM server and management agent, for example `MIM01 - Corporate Okta MA`.
5. Copy the token and store it securely. Okta will not show it again.

![Creating a named API token in the Okta Admin Console.](https://2206708376-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0u5rDWCokdBire3bUPyS%2Fuploads%2Fgit-blob-816b5c6afb2b03c759b625036dbedaf8502da55c%2Fokta-create-api-token.png?alt=media)

Okta's [API token documentation](https://help.okta.com/en-us/Content/Topics/Security/API.htm) covers token expiry and network zone restrictions, both of which can silently break the connector later.

## Step 3: Configure MIM

On the management agent Connectivity page:

1. Set **Authentication method** to **API token**.
2. Paste the token into **API key**.
3. Enter your Okta org URL in **Tenant URL**, for example `https://example.okta.com`. Don't use the `-admin` hostname.
4. Set the log file path and log level.
5. Save the page.

![Connectivity settings for API-token authentication.](https://2206708376-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0u5rDWCokdBire3bUPyS%2Fuploads%2Fgit-blob-f5c9508f107a001114ded768456c773e722c9c70%2Fmim-connectivity-api-token.png?alt=media)

The Connectivity page shows the fields for all three authentication methods at once. With **API token** selected, only **API key** and **Tenant URL** are used. Leave **OAuth client ID**, **Private JWK file path**, and **Certificate thumbprint** empty.

{% hint style="warning" %}
MIM stores the token as an encrypted parameter and clears it whenever anything else on the Connectivity page changes. Keep the token somewhere you can retrieve it, as you'll be asked for it again every time you edit and save this page.
{% endhint %}

See [Connectivity settings](/okta-ma/configuration/connectivity-settings.md) for the full field reference.

## Step 4: Retrieve the schema

Retrieve the management agent schema. It will show the full `user` and `group` schema, because a token carries no scope information the connector can read. Select only the object types and attributes the token's account is permitted to use.

If schema retrieval fails, see [API token troubleshooting](/okta-ma/administration/troubleshooting.md#api-token).

Then continue with [Creating the management agent](/okta-ma/configuration/creating-the-management-agent.md).

## Replacing the token

1. Create the replacement token in Okta.
2. Enter it on the Connectivity page and save.
3. Run a controlled import to confirm it works.
4. Revoke the old token in Okta.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.lithnet.io/okta-ma/authentication/api-token.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
