This image has an empty alt attribute; its file name is cpIyQ5AgpOquJfixKFjsvLF3ySKVi9JYmPVqZodzTAQljU6hZt5xn9p64F74W1AmOUDNfk5LOaIEzRi5as4aaZZf9JLK_9Alb_-OtWNvRlHDxmTovgxkamPnvkXzD9q5JpHJy-fl
Last Updated21 March 2022
Document Tagtch-research-next-gen-authz
Authorsimonm@thecyberhut.com
Part of Research ProductNext Generation Authorization Technology

Okta typically provides monthly releases to their SaaS offering.  The following is a list of authorization related capabilities they have released since 2019.

2019 (9 updates)

DateFeatureDetails
Feb 2019OAuth2 Token Inline HooksAbility to add custom attributes, perhaps by third party call out, into access and id tokens
March 2019Enable Role Assignment to Every Member of a GroupAbility to perform bulk role assignments via API
March 2019OAuth2 PKCE for OAuth2 ClientsSupport for Proof Key Code Exchange for OAuth2 clients
May 2019Token Inline Hooks Can Remove ClaimsAbility to change or entirely remove claims issued by Okta OAuth2 AS
June 2019OAuth2 Refresh Token Expiration Extended to 5 YearsRefresh tokens can now live for up to 5 years
Sept 2019Separate Rate Limits Applied to OAuth2 Public EndpointAbility to have separate rate limits on each endpoint
Oct 2019OAuth2 Scope Naming RestrictionsScopes can’t have the word “okta” as a prefix within the scope name
Dec 2019SAML Inline Hook AvailabilitySAML assertions now have an API hook that can allow for the addition and modification of attributes that go into the SAML assertion.
Dec 2019OAuth2 Clear Sessions Endpoint AvailableAn endpoint available for per-user session clear down.

2020 (4 updates)

DateFeatureDetails
Feb 2020OAuth2 Added to Policy APIThe central policy and rule API can now operate against OAuth2 operations
Aug 2020OAuth2 Auth Code Length IncreaseOAuth2 authorization code length increased to 256bits of entropy
Oct 2020Groups API Extended Search in EAThe groups API has extended search capabilities added to the early access version
Dec 2020One Time Use Refresh Tokens Now in EAOne time use refresh tokens (token rotation) for OAuth2 now available in early access version

2021 (8 updates)

DateFeatureDetails
Jan 2021New Apps API in EAApps API in early access for the ability to manage applications and user/groups to application relations
April 2021OAuth2 Authorization Code Lifetime IncreasesIncreased in time from 1 min to 5 mins
June 2021OAuth2 Flexible Consent Option in GAFlexible Consent option now available – except for client credentials flow
Aug 2021Addition of Risk Events and Risk Providers API not EANew APIs for the use of third party risk signals such as IP addressing
Aug 2021Device Authorization Grant now EAOAuth2 Device Grant for IoT style projects now early access
Sept 2021OAuth2 Issuer URL Can be DynamicIssuer URL can be configurable based on domain/sub-domain/custom-domain etc
Nov 2021OAuth2 Device Grant in GAOAuth2 Device Grant for IoT style projects now generally available
Nov 2021OAuth2 Device Authorization Grant now GAOAuth2 Device Authorization Grant now generally available

2022 (3 updates)

DateFeatureDetails
Jan 2022Custom Permissions for Admin RolesAdmin roles can now have custom permissions
Feb 2022Role Assignment ImprovementsAssigning roles to groups has been improved by retaining the existing role Id where possible
March 2022Authentication Timestamp Added to Access TokensAuth_time claim added to OAuth2 access tokens, that contains authentication time in Unix timestamp format.

Categories:

Signup for New Content Updates