Skip to main content

A project powered by SpecterOps - Creators of BloodHound

Okta collector for OpenHound

Slack SpecterOps on Reddit Sponsored by SpecterOps

@SpecterOps on Twitter Connect on LinkedIn Connect on Mastodon


About

OpenHound is a standardized framework for building and running OpenGraph collectors and converters. It is built in Python and powered by the Data Load Tool (DLT) library, giving you a consistent workflow to collect, process, and convert data from any source into BloodHound-compatible graphs.

The openhound-okta extension collects Okta resources and transforms these into usable nodes and edges for BloodHound.

Python Version

Getting Started

Follow the OpenHound docs to get started:

OAuth app authentication behavior

When the collector uses Okta OAuth app credentials, it shares one bearer token across endpoint clients and refreshes that token before it expires. Long-running collections can therefore continue across the Okta access-token lifetime without failing active resource pagination. If a transient proactive refresh fails while the current token is still valid, the collector temporarily keeps using that token and suppresses repeated refresh attempts for a short cooldown. If Okta rejects a bearer token with HTTP 401, the collector retries once for stale, invalid, or unknown token responses while preserving the current token for known non-token authorization failures. Classic SSWS API token authentication remains static.

Rate-limit behavior

The collector coordinates requests by Okta API endpoint family. It limits concurrent requests, observes X-Rate-Limit-Remaining and X-Rate-Limit-Reset on successful responses, and paces later requests before a bucket is exhausted. HTTP 429 responses retry the same request and pagination cursor until a bounded elapsed-time budget is reached. Transport failures and HTTP 5xx responses retain DLT's retry coverage.

Fan-out resources use explicit page sizes where Okta documents safe maxima. Application-user collection requests 500 rows per page, group-push mapping collection requests 1,000 rows per page, and identity-provider user collection requests 200 rows per page. Rows stream to DLT; an exhausted required request fails the collection so DLT does not publish an incomplete replacement.

The defaults can be adjusted with DLT source configuration environment variables:

Environment variable Default Purpose
SOURCES__SOURCE__OKTA__APPLICATION_USERS_PAGE_SIZE 500 Application users per page, from 1 through 500
SOURCES__SOURCE__OKTA__GROUP_PUSH_MAPPINGS_PAGE_SIZE 1000 Group push mappings per page, from 1 through 1,000
SOURCES__SOURCE__OKTA__IDENTITY_PROVIDER_USERS_PAGE_SIZE 200 Identity-provider users per page, from 1 through 200
SOURCES__SOURCE__OKTA__ENDPOINT_CONCURRENCY 2 Maximum simultaneous requests per endpoint family
SOURCES__SOURCE__OKTA__RATE_LIMIT_MAX_ELAPSED_SECONDS 900 Maximum elapsed retry window for an individual 429 request
SOURCES__SOURCE__OKTA__RATE_LIMIT_REMAINING_RESERVE 1 Requests held in reserve when pacing against a rate-limit window

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

openhound_okta-0.2.7.tar.gz (3.6 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

openhound_okta-0.2.7-py3-none-any.whl (105.2 kB view details)

Uploaded Python 3

File details

Details for the file openhound_okta-0.2.7.tar.gz.

File metadata

  • Download URL: openhound_okta-0.2.7.tar.gz
  • Upload date:
  • Size: 3.6 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: uv/0.12.5 {"installer":{"name":"uv","version":"0.12.5","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for openhound_okta-0.2.7.tar.gz
Algorithm Hash digest
SHA256 e6786228ebd5a26b1e0864dfaccbc6c8cea69dcfa4de62a592c70d06e291d2a8
MD5 1dceb73eb24e0a8e4290cd1385c0531b
BLAKE2b-256 fd7054d6ecc051bfe972c70d7ff63e29dd19336f4d5513a2cd615cbb5c141102

See more details on using hashes here.

File details

Details for the file openhound_okta-0.2.7-py3-none-any.whl.

File metadata

  • Download URL: openhound_okta-0.2.7-py3-none-any.whl
  • Upload date:
  • Size: 105.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: uv/0.12.5 {"installer":{"name":"uv","version":"0.12.5","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for openhound_okta-0.2.7-py3-none-any.whl
Algorithm Hash digest
SHA256 7e195075a5d82f9588fef1442e599e18a8fb35eb14c8eea1656fd9c971ff1d79
MD5 1198a6d73bbf01f09af84364f4fb4568
BLAKE2b-256 dd1953f93e62e62e1c4d454c82b12638ffc903afd28122ef958e75affcfdd0c4

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page