> ## Documentation Index
> Fetch the complete documentation index at: https://wundergraphinc-auto-improve-queries-with-defer.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Okta (OIN version)

> Configure SCIM with Okta using the app from OIN.

### Steps to set up SCIM with Okta

<Steps>
  <Step>
    Set up the password policy (password should contain at least one number and one symbol), if using the **Classic Engine on Okta** follow the below steps**,** or if using the  **OIE engine,**follow the steps as mentioned in this  \*\*\*\*[**Okta guide**](https://help.okta.com/oie/en-us/content/topics/identity-engine/authenticators/configure-password.htm)**.**

    * Navigate to Security -> Authentication on your Okta Administrator Dashboard.

    * Click Edit and update the password policy by enabling Number and Symbol, then click on Update Policy.

    <Frame>
      <img src="https://mintcdn.com/wundergraphinc-auto-improve-queries-with-defer/lkonUAgtUmzaMhJ9/images/studio/scim/authentication-policy-editing-in-okta.png?fit=max&auto=format&n=lkonUAgtUmzaMhJ9&q=85&s=759ee9f607cd4bbd7211652285e8c5ab" alt="Authentication policy editing in Okta" title="Authentication policy editing in Okta" width="2304" height="1187" data-path="images/studio/scim/authentication-policy-editing-in-okta.png" />
    </Frame>
  </Step>

  <Step>
    Navigate to the Applications view within your Okta Administrator Dashboard.
  </Step>

  <Step>
    Click on **Browse App Catalog.**

    <Frame>
      <img src="https://mintcdn.com/wundergraphinc-auto-improve-queries-with-defer/lkonUAgtUmzaMhJ9/images/studio/scim/browse-app-catalog-in-okta-applications.png?fit=max&auto=format&n=lkonUAgtUmzaMhJ9&q=85&s=9f191b4dda64bec9277930861fd8df65" alt="Browse App Catalog in Okta Applications" title="Browse App Catalog in Okta Applications" width="2304" height="1277" data-path="images/studio/scim/browse-app-catalog-in-okta-applications.png" />
    </Frame>
  </Step>

  <Step>
    Search for **Wundergraph Cosmo.**
  </Step>

  <Step>
    Click on **Add Integration**.

    <Frame>
      <img src="https://mintcdn.com/wundergraphinc-auto-improve-queries-with-defer/lkonUAgtUmzaMhJ9/images/studio/scim/add-wundergraph-cosmo-integration.png?fit=max&auto=format&n=lkonUAgtUmzaMhJ9&q=85&s=ea93684a395d7aa9128eea2515f2450b" alt="Add WunderGraph Cosmo integration" title="Add WunderGraph Cosmo integration" width="2304" height="1270" data-path="images/studio/scim/add-wundergraph-cosmo-integration.png" />
    </Frame>
  </Step>

  <Step>
    Now give the app a name and then click on **Next.**
  </Step>

  <Step>
    Select **Administrator sets username, user sets password** and for **Application username format** under **Credentials Details** select  **Email**and then click **Done.**

    <Frame>
      <img src="https://mintcdn.com/wundergraphinc-auto-improve-queries-with-defer/lkonUAgtUmzaMhJ9/images/studio/scim/wundergraph-cosmo-sign-on-setup.png?fit=max&auto=format&n=lkonUAgtUmzaMhJ9&q=85&s=0033a660723c3610886aa67184449fec" alt="WunderGraph Cosmo sign-on setup" title="WunderGraph Cosmo sign-on-setup" width="2304" height="1181" data-path="images/studio/scim/wundergraph-cosmo-sign-on-setup.png" />
    </Frame>
  </Step>

  <Step>
    Navigate to the settings page on WunderGraph Cosmo and enable **SCIM.**

    <Frame>
      <img src="https://mintcdn.com/wundergraphinc-auto-improve-queries-with-defer/lkonUAgtUmzaMhJ9/images/studio/scim/generative-ai-enable-option-in-cosmo.png?fit=max&auto=format&n=lkonUAgtUmzaMhJ9&q=85&s=685775ac346a80383377d4e56b50d996" alt="Generative AI enable option in Cosmo" title="Generative AI enable option in Cosmo" width="2304" height="1249" data-path="images/studio/scim/generative-ai-enable-option-in-cosmo.png" />
    </Frame>
  </Step>

  <Step>
    Once SCIM is enabled, you will be provided with a  **SCIM Server URL,**copy it**.**
  </Step>

  <Step>
    Navigate to the API Keys page on WunderGraph Cosmo and click on New API Key.
  </Step>

  <Step>
    Provide the key with a name, select **Never** for **Expires,** then select  **SCIM**under **Permissions, t**hen click on **Generate API key.**

    <Frame>
      <img src="https://mintcdn.com/wundergraphinc-auto-improve-queries-with-defer/lkonUAgtUmzaMhJ9/images/studio/scim/create-scim-api-key.png?fit=max&auto=format&n=lkonUAgtUmzaMhJ9&q=85&s=9768b6e7eed35eae9d9133b3f033a2c7" alt="Create SCIM API key" title="Create SCIM API key" width="1600" height="873" data-path="images/studio/scim/create-scim-api-key.png" />
    </Frame>
  </Step>

  <Step>
    Copy the API key provided.
  </Step>

  <Step>
    Navigate to the provisioning tab of the app created on okta, then click on **Configure API Integration**.

    <Frame>
      <img src="https://mintcdn.com/wundergraphinc-auto-improve-queries-with-defer/lkonUAgtUmzaMhJ9/images/studio/scim/configure-api-integration-for-wundergraph-cosmo.png?fit=max&auto=format&n=lkonUAgtUmzaMhJ9&q=85&s=41b763fc44b5e704f74470dedb95ec7e" alt="Configure API Integration for WunderGraph Cosmo" title="Configure API Integration for WunderGraph Cosmo" width="2304" height="1264" data-path="images/studio/scim/configure-api-integration-for-wundergraph-cosmo.png" />
    </Frame>
  </Step>

  <Step>
    Check the **Enable API Integration** and then populate the  **API token**with the  **API key**copied in the previous steps.
  </Step>

  <Step>
    Click on **Test API Credentials** and once it's verified successfully, click on **Save**
  </Step>

  <Step>
    Navigate to the "**to App"** tab**, and** click on **Edit.**

    <Frame>
      <img src="https://mintcdn.com/wundergraphinc-auto-improve-queries-with-defer/lkonUAgtUmzaMhJ9/images/studio/scim/test-app-to-app-provisioning-setup.png?fit=max&auto=format&n=lkonUAgtUmzaMhJ9&q=85&s=9d271faa708ffaf067d19c815e7d1408" alt="Test app To App provisioning setup" title="Test app To App provisioning setup" width="2304" height="1188" data-path="images/studio/scim/test-app-to-app-provisioning-setup.png" />
    </Frame>
  </Step>

  <Step>
    Enable  **Create Users, Update User Attributes, Deactivate Users**and **Sync Password.**
  </Step>

  <Step>
    Under **Sync Password** for **Password type**, select **Sync Okta Password.**

    <Frame>
      <img src="https://mintcdn.com/wundergraphinc-auto-improve-queries-with-defer/lkonUAgtUmzaMhJ9/images/studio/scim/provisioning-to-app-user-setup.png?fit=max&auto=format&n=lkonUAgtUmzaMhJ9&q=85&s=80150cac10708932e4e0fb2648a9c34c" alt="Provisioning to App user setup" title="Provisioning to App user setup" width="1004" height="906" data-path="images/studio/scim/provisioning-to-app-user-setup.png" />
    </Frame>
  </Step>

  <Step>
    Click **save.**
  </Step>

  <Step>
    Now you can navigate the Assignments tab and assign users/groups who should have access to WunderGraph Cosmo.
  </Step>
</Steps>

<Info>
  If you are using both **SSO with OIDC** and **SCIM**, please make sure that the users assigned in both apps are the same.
</Info>
