> For the complete documentation index, see [llms.txt](https://docs.lithnet.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lithnet.io/okta-ma/authentication/oauth-with-a-private-jwk.md).

# OAuth with a private JWK

Authenticate to Okta with a private JWK held in a file on the MIM server.

The management agent signs its OAuth client assertions with a private JWK read from a file on the MIM server. Okta holds only the matching public JWK.

If you need the private key to be non-exportable or held in hardware, use [an X.509 certificate](/okta-ma/authentication/oauth-with-an-x509-certificate.md) instead.

## Step 1: Get a key pair

The easiest option is to let Okta generate one for you. Go to [Creating the OAuth service app](/okta-ma/authentication/creating-the-oauth-service-app.md), choose **Generate new key** at the key step, and save the private JWK when Okta shows it. Okta generates a 2048-bit RSA pair and displays the private key exactly once.

Bring your own key pair instead if you need an EC key, a larger RSA key, or you have an existing key-generation process. Register only the public JWK in Okta.

Either way, the private JWK must meet the following requirements:

| Key type                 | Algorithm                    |
| ------------------------ | ---------------------------- |
| RSA, 2048 bits or larger | `RS256`, `RS384`, or `RS512` |
| EC P-256                 | `ES256`                      |
| EC P-384                 | `ES384`                      |
| EC P-521                 | `ES512`                      |

The file must contain a single JWK object, not a JWKS document with a `keys` array, and that object must have:

* The private key values, so it can sign
* A non-empty `kid` matching the public JWK in Okta
* A supported `alg`
* `"use": "sig"`, if `use` is present at all
* `sign` among its `key_ops`, if `key_ops` is present at all

## Step 2: Put the key on the MIM server

Save the private JWK as UTF-8 JSON at a stable, fully qualified path. For example:

```
C:\ProgramData\Lithnet\Okta Management Agent\oauth-private.jwk.json
```

Grant the MIM Synchronization Service account read access to the file, and nothing more. The file must be under 65,536 bytes, although a single JWK won't come anywhere near that limit.

If you haven't created the Okta app yet, work through [Creating the OAuth service app](/okta-ma/authentication/creating-the-oauth-service-app.md) now, and come back here once the app has its public key, scopes, and admin role.

## Step 3: Configure MIM

On the management agent Connectivity page:

1. Set **Authentication method** to **OAuth 2.0 (private JWK)**.
2. Enter the app's client ID in **OAuth client ID**.
3. Enter the full path to the private JWK in **Private JWK file path**.
4. Enter your Okta org URL in **Tenant URL**, for example `https://example.okta.com`. Don't use the `-admin` hostname.
5. Set the log file path and log level.
6. Save the page.

![Connectivity settings for private-JWK authentication.](https://2206708376-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0u5rDWCokdBire3bUPyS%2Fuploads%2Fgit-blob-8cd67a0e52c5b1e52d2cb397e9783c05bea4365f%2Fmim-connectivity-private-jwk.png?alt=media)

The field takes a path, not the key itself. Do not paste the JWK JSON into it.

The Connectivity page shows the fields for all three authentication methods at once. With this method selected, only **OAuth client ID**, **Private JWK file path**, and **Tenant URL** are used. Leave **API key** and **Certificate thumbprint** empty.

## Step 4: Retrieve the schema

Retrieve the management agent schema. The object types and attribute directions MIM shows should match the scopes granted to the service app.

If it fails, see [private JWK troubleshooting](/okta-ma/administration/troubleshooting.md#private-jwk).

Then continue with [Creating the management agent](/okta-ma/configuration/creating-the-management-agent.md).

## Replacing the key

See [Key and certificate rotation](/okta-ma/authentication/key-and-certificate-rotation.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.lithnet.io/okta-ma/authentication/oauth-with-a-private-jwk.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
