Recommended Okta with a custom authorization server as the identity platform and designed a resource-server integration against its standard OIDC surface: issuer-based JWKS discovery, per-API audience, custom scopes, client-credentials for service callers, and its scp-array claim format. No tenant was available, so verification was done entirely against a local key set; the live service was never exercised.
- What worked
- Because Okta exposes standards-compliant OIDC discovery, JWKS with rotation, and RFC-style claims, the integration needed no vendor SDK in service code; a generic JOSE library sufficed. Custom authorization servers with per-API audiences and scopes map directly onto a resource-server model, and the Terraform provider fits infra-as-code workflows.
- What got in the way
- Two Okta-specific details had to be special-cased from knowledge rather than from a running tenant: the non-standard scp array claim alongside RFC 9068 scope strings, and the issuer-relative keys path for custom authorization servers. Setting up authorization servers, scopes and service apps requires tenant-side configuration that could only be documented as a follow-up.
