> For the complete documentation index, see [llms.txt](https://docs.lithnet.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lithnet.io/okta-ma/configuration/connectivity-settings.md).

# Connectivity settings

Field reference for the management agent Connectivity page.

The Connectivity page shows the fields for all three authentication methods at once. Fill in the ones your method uses and leave the rest empty.

| Setting                       | When required      | Default     | Description                                                                                                                  |
| ----------------------------- | ------------------ | ----------- | ---------------------------------------------------------------------------------------------------------------------------- |
| Log file                      | Always             | None        | Full path to the management agent log file. The MIM Synchronization Service account must be able to write to this directory. |
| Log level                     | Always             | `Info`      | Minimum level logged: `Trace`, `Debug`, `Info`, `Warn`, `Error`, or `Fatal`.                                                 |
| Number of days to retain logs | Optional           | `30`        | Number of daily log files kept.                                                                                              |
| Authentication method         | Always             | `API token` | `API token`, `OAuth 2.0 (private JWK)`, or `OAuth 2.0 (X.509 certificate)`.                                                  |
| API key                       | API token          | None        | The Okta API token. MIM stores it as an encrypted parameter.                                                                 |
| OAuth client ID               | Both OAuth methods | None        | Client ID of the Okta API Services app.                                                                                      |
| Private JWK file path         | Private JWK        | None        | Fully qualified path to a file holding one private JWK.                                                                      |
| Certificate thumbprint        | X.509 certificate  | None        | Thumbprint of the signing certificate. Spaces are stripped, so pasting from the certificate dialog is fine.                  |
| Tenant URL                    | Always             | None        | Okta org URL, such as `https://example.okta.com`.                                                                            |
| HTTP client timeout (seconds) | Optional           | `120`       | Timeout for a single Okta API request.                                                                                       |

## Tenant URL

This is the root URL of your Okta org:

```
https://example.okta.com
```

Use HTTPS, with nothing after the hostname. The `-admin` hostname is rejected, and with either OAuth method, a path, query string, or fragment is rejected as well.

## Log file

Use a stable local path and grant the MIM Synchronization Service account write access to the directory. Run at the `Info` level for day-to-day use, and drop to `Debug` or `Trace` only while reproducing a problem.

## Re-entering the API token

MIM clears encrypted parameters whenever the page they appear on is saved. Every time you edit and save the Connectivity page, you'll be asked for the API token again, so keep it somewhere you can retrieve it.

## Validation

Saving the page checks that the fields required by the selected method are filled in, and that the tenant URL is a URL.

Everything else is checked when the connector first connects, which is when you retrieve the schema: the client ID, the signing key or certificate, whether the service account can use the private key, and which scopes Okta granted. Retrieve the schema before you build joins or attribute flows, so MIM is showing you the object types and attribute directions you'll actually have.

An OAuth service app needs `okta.schemas.read` plus at least one user or group scope before the schema can be retrieved at all. See [Creating the OAuth service app](/okta-ma/authentication/creating-the-oauth-service-app.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.lithnet.io/okta-ma/configuration/connectivity-settings.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
