Skip to main content

A project powered by SpecterOps - Creators of BloodHound

Okta collector for OpenHound

Slack SpecterOps on Reddit Sponsored by SpecterOps

@SpecterOps on Twitter Connect on LinkedIn Connect on Mastodon


About

OpenHound is a standardized framework for building and running OpenGraph collectors and converters. It is built in Python and powered by the Data Load Tool (DLT) library, giving you a consistent workflow to collect, process, and convert data from any source into BloodHound-compatible graphs.

The openhound-okta extension collects Okta resources and transforms these into usable nodes and edges for BloodHound.

Python Version

Getting Started

Follow the OpenHound docs to get started:

OAuth app authentication behavior

When the collector uses Okta OAuth app credentials, it shares one bearer token across endpoint clients and refreshes that token before it expires. Long-running collections can therefore continue across the Okta access-token lifetime without failing active resource pagination. If a transient proactive refresh fails while the current token is still valid, the collector temporarily keeps using that token and suppresses repeated refresh attempts for a short cooldown. If Okta rejects a bearer token with HTTP 401, the collector retries once for stale, invalid, or unknown token responses while preserving the current token for known non-token authorization failures. Classic SSWS API token authentication remains static.

Rate-limit behavior

The collector coordinates requests by Okta API endpoint family. It limits concurrent requests, observes X-Rate-Limit-Remaining and X-Rate-Limit-Reset on successful responses, and paces later requests before a bucket is exhausted. HTTP 429 responses retry the same request and pagination cursor until a bounded elapsed-time budget is reached. Transport failures and HTTP 5xx responses retain DLT's retry coverage.

Fan-out resources use explicit page sizes where Okta documents safe maxima. Application-user collection requests 500 rows per page, group-push mapping collection requests 1,000 rows per page, and identity-provider user collection requests 200 rows per page. Rows stream to DLT; an exhausted required request fails the collection so DLT does not publish an incomplete replacement.

The defaults can be adjusted with DLT source configuration environment variables:

Environment variable Default Purpose
SOURCES__SOURCE__OKTA__APPLICATION_USERS_PAGE_SIZE 500 Application users per page, from 1 through 500
SOURCES__SOURCE__OKTA__GROUP_PUSH_MAPPINGS_PAGE_SIZE 1000 Group push mappings per page, from 1 through 1,000
SOURCES__SOURCE__OKTA__IDENTITY_PROVIDER_USERS_PAGE_SIZE 200 Identity-provider users per page, from 1 through 200
SOURCES__SOURCE__OKTA__ENDPOINT_CONCURRENCY 2 Maximum simultaneous requests per endpoint family
SOURCES__SOURCE__OKTA__RATE_LIMIT_MAX_ELAPSED_SECONDS 900 Maximum elapsed retry window for an individual 429 request
SOURCES__SOURCE__OKTA__RATE_LIMIT_REMAINING_RESERVE 1 Requests held in reserve when pacing against a rate-limit window

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

openhound_okta-0.2.4.tar.gz (3.6 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

openhound_okta-0.2.4-py3-none-any.whl (104.9 kB view details)

Uploaded Python 3

File details

Details for the file openhound_okta-0.2.4.tar.gz.

File metadata

  • Download URL: openhound_okta-0.2.4.tar.gz
  • Upload date:
  • Size: 3.6 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: uv/0.12.3 {"installer":{"name":"uv","version":"0.12.3","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for openhound_okta-0.2.4.tar.gz
Algorithm Hash digest
SHA256 d5bc74bc08aa91e1d0cb7d5a8efd740665a7830c3a3d10355be186aa5be2430e
MD5 b4ebb01bde1948116639e72cd8c64bed
BLAKE2b-256 e1a0891ef30e1608b4adcbe88a7aa3382a7e3ecb19aedc4864d3bd1f9add8b0b

See more details on using hashes here.

File details

Details for the file openhound_okta-0.2.4-py3-none-any.whl.

File metadata

  • Download URL: openhound_okta-0.2.4-py3-none-any.whl
  • Upload date:
  • Size: 104.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: uv/0.12.3 {"installer":{"name":"uv","version":"0.12.3","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for openhound_okta-0.2.4-py3-none-any.whl
Algorithm Hash digest
SHA256 5b49c89cf14efb4aeafb63d88aaf44349c555271a665d559ca350053a4c3fd2b
MD5 72d2e9d1e3eea971cd9b854fdddfbe11
BLAKE2b-256 c0b834e6c6763645861f42768c3f8cae7e583628251904ced2a403b08aa9ff0e

See more details on using hashes here.

Release history Release notifications | RSS feed

0.3.0

2 files

0.2.8

2 files

0.2.7

2 files

0.2.6

2 files

0.2.5

2 files

This release

0.2.4 This release

2 files

0.2.3

2 files

0.2.2

2 files

0.2.1

2 files

0.1.6

2 files

0.1.5

2 files

0.1.4

2 files

0.1.3

2 files

0.1.2

2 files

0.1.1

2 files

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page