{"id":45678,"date":"2026-08-06T08:58:00","date_gmt":"2026-08-06T06:58:00","guid":{"rendered":"https:\/\/www.dbi-services.com\/blog\/?p=45678"},"modified":"2026-08-05T17:27:37","modified_gmt":"2026-08-05T15:27:37","slug":"mongodb-oidc-authentication-with-okta","status":"publish","type":"post","link":"https:\/\/www.dbi-services.com\/blog\/mongodb-oidc-authentication-with-okta\/","title":{"rendered":"MongoDB OIDC Authentication with Okta"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Since <strong>version 7.0.11<\/strong>, MongoDB natively supports <strong>OpenID Connect (OIDC) authentication<\/strong>. This move was part of MongoDB\u2019s cloud strategy, since cloud environments use OIDC a lot for authentication and authorization. In version 8.0, MongoDB <a href=\"https:\/\/www.mongodb.com\/docs\/v8.0\/core\/LDAP-deprecation\/#std-label-ldap-deprecation\" target=\"_blank\" rel=\"noreferrer noopener\">deprecated LDAP authentication and authorization<\/a>, making it clear that OIDC is the future for MongoDB authentication. In this blog, I will present how to set up OIDC authentication for MongoDB in a self-managed environment with Okta.<\/p>\n\n\n\n<h2 id=\"h-what-is-openid-connect-oidc\" class=\"wp-block-heading\">What is OpenID Connect (OIDC) ?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">OpenID Connect (OIDC) is an <strong>authentication protocol<\/strong> built on top of the OAuth 2.0 framework. It allows clients (like <code>mongosh<\/code>) to check the identity of the user based on the authentication performed by an authorization server (like Okta). It also provides a standardized way of obtaining user profile information, resolving the authorization part of the connection.<\/p>\n\n\n\n<h2 id=\"h-oidc-use-cases-in-mongodb\" class=\"wp-block-heading\">OIDC use cases in MongoDB<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">MongoDB supports OIDC authentication for both:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Users : <strong><em>Workforce Identity Federation<\/em><\/strong><\/li>\n\n\n\n<li>Applications : <strong><em>Workload Identity Federation<\/em><\/strong><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">In this blog, I will focus on the first use case.<\/p>\n\n\n\n<h2 id=\"h-prerequisites\" class=\"wp-block-heading\">Prerequisites<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Before setting up OIDC authentication for MongoDB, you will need the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>MongoDB Enterprise Edition<\/strong>. OIDC authentication is only available in the Enterprise Edition of MongoDB. Alternatively, you can use Percona Server for MongoDB, which also supports OIDC authentication.<\/li>\n\n\n\n<li><strong>Version 7.0.11 or later<\/strong> of MongoDB.<\/li>\n\n\n\n<li>A working <strong>Okta tenant<\/strong>. A 30-day trial can be obtained <a href=\"https:\/\/www.okta.com\/free-trial\/\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a>.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Throughout this blog, I will use very generic names (dbiapp, dbiauth, etc.) to make sure you are not missing on configuration aspects. Some of these names will be used when configuring OIDC in MongoDB.<\/p>\n\n\n\n<h2 id=\"h-configure-oidc-in-okta\" class=\"wp-block-heading\">Configure OIDC in Okta<\/h2>\n\n\n\n<h3 id=\"h-create-an-application-in-okta\" class=\"wp-block-heading\">Create an application in Okta<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Start by creating an application in Okta. From the Admin Console (available at <a href=\"https:\/\/trial-1234567-admin.okta.com\/admin\/dashboard\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/trial-1234567-admin.okta.com\/admin\/dashboard<\/a>), navigate to Applications &gt; Applications and click on <em><strong>Create App Integration<\/strong><\/em>. Then, select <strong><em>OIDC &#8211; OpenID Connect<\/em><\/strong> as the sign-in method and <em><strong>Native<\/strong><\/em> as the application type. Click on <em><strong>Next<\/strong><\/em>.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"704\" height=\"984\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_applications_panel.png\" alt=\"\" class=\"wp-image-45684\" style=\"width:500px\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_applications_panel.png 704w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_applications_panel-215x300.png 215w\" sizes=\"auto, (max-width: 704px) 100vw, 704px\" \/><\/figure>\n<\/div>\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"447\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_applications_screen-1024x447.png\" alt=\"\" class=\"wp-image-45685\" style=\"width:500px\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_applications_screen-1024x447.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_applications_screen-300x131.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_applications_screen-768x335.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_applications_screen.png 1110w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"806\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_create_new_app-1024x806.png\" alt=\"\" class=\"wp-image-45687\" style=\"width:800px\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_create_new_app-1024x806.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_create_new_app-300x236.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_create_new_app-768x604.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_create_new_app-1536x1209.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_create_new_app.png 1850w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<h3 id=\"h-configuring-the-application\" class=\"wp-block-heading\">Configuring the application<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In the application configuration screen, fill in an application name (mine will be called <code>dbiapp<\/code>), and select <em><strong>Grant types<\/strong><\/em> among these three choices:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Authorization Code<\/strong>: Activated by default, cannot be deactivated.<\/li>\n\n\n\n<li><strong>Device Authorization<\/strong>: Required if you have no browser access when using <code>mongosh<\/code>. The shell will display a URL with which you will authenticate.<\/li>\n\n\n\n<li><strong>Refresh Token<\/strong>: If enabled, the MongoDB driver caches the refresh token and renews the access token when it expires.<\/li>\n<\/ul>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"470\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_new_native_app_refresh-1024x470.png\" alt=\"\" class=\"wp-image-45688\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_new_native_app_refresh-1024x470.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_new_native_app_refresh-300x138.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_new_native_app_refresh-768x353.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_new_native_app_refresh-1536x706.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_new_native_app_refresh.png 1820w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Then fill in the <em><strong>Sign-in redirect URIs<\/strong><\/em> with the following URL : <a href=\"http:\/\/localhost:27097\/redirect\" target=\"_blank\" rel=\"noreferrer noopener\">http:\/\/localhost:27097\/redirect<\/a><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"194\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_new_native_app_signin_url-1024x194.png\" alt=\"\" class=\"wp-image-45689\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_new_native_app_signin_url-1024x194.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_new_native_app_signin_url-300x57.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_new_native_app_signin_url-768x146.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_new_native_app_signin_url-1536x292.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_new_native_app_signin_url.png 1748w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Finally, in the Assignments section, you can choose between multiple <em><strong>Controlled access<\/strong><\/em> options:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Allow everyone in your organization to access<\/li>\n\n\n\n<li>Limit access to selected groups<\/li>\n\n\n\n<li>Skip group assignment for now<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">In this blog, I will choose <em><strong>Allow everyone in your organization to access<\/strong><\/em>. In production environments, you might choose something else. Make sure <strong><em>Enable immediate access with&nbsp;Federation Broker Mode<\/em><\/strong> is enabled, and click on <strong><em>Save<\/em><\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"389\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_new_native_app_access-1024x389.png\" alt=\"\" class=\"wp-image-45690\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_new_native_app_access-1024x389.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_new_native_app_access-300x114.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_new_native_app_access-768x291.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_new_native_app_access-1536x583.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_new_native_app_access.png 1750w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">You should now land on the newly created application page. Copy the Client ID displayed on the screen, you will need it later.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"802\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_app_client_id-1-1024x802.png\" alt=\"\" class=\"wp-image-45692\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_app_client_id-1-1024x802.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_app_client_id-1-300x235.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_app_client_id-1-768x601.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_app_client_id-1.png 1494w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<h3 id=\"h-authorization-server-configuration\" class=\"wp-block-heading\">Authorization server configuration<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In the navigation panel, click on <em><strong>Security &gt; API<\/strong><\/em>, and <strong><em>Add Authorization Server<\/em><\/strong>.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"592\" height=\"670\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_api_auth_srv.png\" alt=\"\" class=\"wp-image-45693\" style=\"width:400px\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_api_auth_srv.png 592w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_api_auth_srv-265x300.png 265w\" sizes=\"auto, (max-width: 592px) 100vw, 592px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Choose a name for the Authorization Server (mine will be named <code>dbiauth<\/code>), and paste the <em><strong>Client ID<\/strong><\/em> retrieved earlier in the <em><strong>Audience<\/strong><\/em> field.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"465\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_add_auth_srv-1-1024x465.png\" alt=\"\" class=\"wp-image-45695\" style=\"width:600px\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_add_auth_srv-1-1024x465.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_add_auth_srv-1-300x136.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_add_auth_srv-1-768x349.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_add_auth_srv-1.png 1364w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">From the newly created authorization server, copy the Issuer Metadata URI, from <code>https<\/code> until <code>.well-known<\/code> (excluded). You should have something like <code>https:\/\/trial-1234567.okta.com\/oauth2\/aus27qkm93wcRptbz412<\/code>.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"700\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_auth_srv_issuer_metadata_uri-1024x700.png\" alt=\"\" class=\"wp-image-45696\" style=\"width:700px\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_auth_srv_issuer_metadata_uri-1024x700.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_auth_srv_issuer_metadata_uri-300x205.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_auth_srv_issuer_metadata_uri-768x525.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_auth_srv_issuer_metadata_uri.png 1494w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<h3 id=\"h-add-a-group-claim\" class=\"wp-block-heading\">Add a group claim<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Staying on the authorization server summary, click on the <em><strong>Claims<\/strong><\/em> tab, and then on <em><strong>Add Claim<\/strong><\/em>.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"492\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_auth_claims_add_claim-1024x492.png\" alt=\"\" class=\"wp-image-45698\" style=\"width:600px\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_auth_claims_add_claim-1024x492.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_auth_claims_add_claim-300x144.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_auth_claims_add_claim-768x369.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_auth_claims_add_claim.png 1086w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">You can choose any name for the claim. I will call it <code>dbiclaim<\/code>. The rest of the claim should be configured as follows, with the <em><strong>Filter<\/strong><\/em> set to <strong><em>Matches regex<\/em><\/strong>, using <code>.*<\/code> as filter.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>WARNING<\/em><\/strong>: Make sure the filter is <code>.*<\/code>, not <code>*.*<\/code> or <code>*.<\/code> ! Otherwise, it could lead to <code>MongoServerError: Authentication failed.<\/code> errors.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"682\" height=\"548\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/Screenshot-2026-07-25-at-17.06.42.png\" alt=\"\" class=\"wp-image-45722\" style=\"width:700px\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/Screenshot-2026-07-25-at-17.06.42.png 682w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/Screenshot-2026-07-25-at-17.06.42-300x241.png 300w\" sizes=\"auto, (max-width: 682px) 100vw, 682px\" \/><\/figure>\n<\/div>\n\n\n<h3 id=\"h-configure-an-access-policy\" class=\"wp-block-heading\">Configure an access policy<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Now, in the <strong><em>Access Policies<\/em><\/strong> tab of the authorization server, click on <strong><em>Add Policy<\/em><\/strong>.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_auth_access_policies-1024x573.png\" alt=\"\" class=\"wp-image-45704\" style=\"width:600px\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_auth_access_policies-1024x573.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_auth_access_policies-300x168.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_auth_access_policies-768x430.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_auth_access_policies.png 1490w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">You can choose the name of the policy that you want (mine is called <code>dbipolicy<\/code>), and you must add a <strong><em>Description<\/em><\/strong>. Set <em><strong>Assign to<\/strong><\/em> to <em><strong>All clients<\/strong><\/em>.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"557\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_add_policy-1024x557.png\" alt=\"\" class=\"wp-image-45705\" style=\"width:500px\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_add_policy-1024x557.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_add_policy-300x163.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_add_policy-768x418.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_add_policy.png 1258w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">After creating the policy, click on <em><strong>Add rule<\/strong><\/em>.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"454\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_dbipolicy-1024x454.png\" alt=\"\" class=\"wp-image-45708\" style=\"width:700px\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_dbipolicy-1024x454.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_dbipolicy-300x133.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_dbipolicy-768x341.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_dbipolicy-1536x682.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_dbipolicy.png 1938w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">This is the part where you should be customizing the rule based on your internal security policies. I will name my rule <code>dbirule<\/code>, and keep everything default except for the <em><strong>Refresh token<\/strong><\/em> lifetime, which is set to <em><strong>Unlimited<\/strong><\/em>.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"870\" height=\"1024\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_dbirule-870x1024.png\" alt=\"\" class=\"wp-image-45710\" style=\"width:600px\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_dbirule-870x1024.png 870w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_dbirule-255x300.png 255w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_dbirule-768x904.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_dbirule.png 1216w\" sizes=\"auto, (max-width: 870px) 100vw, 870px\" \/><\/figure>\n<\/div>\n\n\n<h3 id=\"h-create-a-group-and-a-user\" class=\"wp-block-heading\">Create a group and a user<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you already use Okta, you should have existing groups and users. But for the purpose of the blog, let\u2019s create a group and a user. Navigate on the left to <strong><em>Directory &gt; Groups<\/em><\/strong>, and click on <em><strong>Add Group<\/strong><\/em>.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"522\" height=\"538\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_groups_tab.png\" alt=\"\" class=\"wp-image-45711\" style=\"width:300px\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_groups_tab.png 522w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_groups_tab-291x300.png 291w\" sizes=\"auto, (max-width: 522px) 100vw, 522px\" \/><\/figure>\n<\/div>\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"248\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_groups_add_group-1024x248.png\" alt=\"\" class=\"wp-image-45712\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_groups_add_group-1024x248.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_groups_add_group-300x73.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_groups_add_group-768x186.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_groups_add_group-1536x372.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_groups_add_group.png 1848w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">MongoDB names the group <code>OIDC<\/code>, without stating whether it is the only name supported or not. But you can choose your own name. I will call the group <code>dbigroup<\/code>.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1230\" height=\"444\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_add_group_dbigroup.png\" alt=\"\" class=\"wp-image-45725\" style=\"width:500px\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_add_group_dbigroup.png 1230w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_add_group_dbigroup-300x108.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_add_group_dbigroup-1024x370.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_add_group_dbigroup-768x277.png 768w\" sizes=\"auto, (max-width: 1230px) 100vw, 1230px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">After creating the group, add a user in the <em><strong>Directory &gt; People<\/strong><\/em> section, clicking on <strong><em>Add Person<\/em><\/strong>.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"518\" height=\"452\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_people_tab.png\" alt=\"\" class=\"wp-image-45714\" style=\"width:300px\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_people_tab.png 518w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_people_tab-300x262.png 300w\" sizes=\"auto, (max-width: 518px) 100vw, 518px\" \/><\/figure>\n<\/div>\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"841\" height=\"1024\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_add_person_dbigroups-841x1024.png\" alt=\"\" class=\"wp-image-45726\" style=\"width:600px\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_add_person_dbigroups-841x1024.png 841w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_add_person_dbigroups-246x300.png 246w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_add_person_dbigroups-768x935.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_add_person_dbigroups.png 1224w\" sizes=\"auto, (max-width: 841px) 100vw, 841px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">There are two important aspects here:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Use an email for the <em><strong>Username<\/strong><\/em> field.<\/li>\n\n\n\n<li>Add the <code>dbigroup<\/code> group to the <strong><em>Groups<\/em><\/strong>.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Before continuing, <strong>make sure the user is activated<\/strong> following the procedure received by email<\/p>\n\n\n\n<h2 id=\"h-configure-mongodb-for-oidc-authentication\" class=\"wp-block-heading\">Configure MongoDB for OIDC authentication<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Stop<\/strong> your MongoDB 7.0.11+ Enterprise Edition instance, and <strong>edit the configuration file<\/strong> by adding the following <code>setParameter<\/code> section:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>authenticationMechanisms<\/code>: set it to <code>MONGODB-OIDC<\/code> if you want to enable only OIDC authentication, or <code>MONGODB-OIDC,SCRAM-SHA-256<\/code> if you want to keep authentication with password for previous users.<\/li>\n\n\n\n<li><code>issuer<\/code>: use the <em><strong>Issuer Metadata URI<\/strong><\/em> copied after creating the authorization server (<code>https:\/\/trial-1234567.okta.com\/oauth2\/aus27qkm93wcRptbz412<\/code>)<\/li>\n\n\n\n<li><code>audience<\/code> and <code>clientId<\/code>: for both fields, use the <em><strong>Client ID<\/strong><\/em> associated with the application created at the very beginning (<code>0oa89cvj16d4WFKrX307<\/code>, for instance)<\/li>\n\n\n\n<li><code>authNamePrefix<\/code>: <code>okta-issuer<\/code><\/li>\n\n\n\n<li><code>authorizationClaim<\/code>: use the name of the claim created on the authorization server. In my case, it is <code>dbiclaim<\/code>.<\/li>\n<\/ul>\n\n\n<div class=\"wp-block-syntaxhighlighter-code \"><pre class=\"brush: plain; title: ; notranslate\" title=\"\">\n# Paste this at the end of your MongoDB configuration file\nsetParameter:\n   authenticationMechanisms: &quot;MONGODB-OIDC&quot;\n   oidcIdentityProviders: &#039;&#x5B; {\n      &quot;issuer&quot;: &quot;https:\/\/trial-1234567.okta.com\/oauth2\/aus27qkm93wcRptbz412&quot;,\n      &quot;audience&quot;: &quot;0oa89cvj16d4WFKrX307&quot;,\n      &quot;authNamePrefix&quot;: &quot;okta-issuer&quot;,\n      &quot;authorizationClaim&quot;: &quot;dbiclaim&quot;,\n      &quot;clientId&quot;: &quot;0oa89cvj16d4WFKrX307&quot;\n   } ]&#039;\n<\/pre><\/div>\n\n\n<p class=\"wp-block-paragraph\">After changing the configuration file, you can <strong>restart your MongoDB instance<\/strong>. If <code>security.authorization<\/code> is not <code>enabled<\/code> yet, you should set it now and make sure you have a user able to create roles.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Log in with a privileged user to your MongoDB instance, and create a new role for OIDC authentication. The role name should be based on <code>authNamePrefix<\/code> (<code>okta-issuer<\/code>) and the group name (<code>dbigroup<\/code>). In this blog, I will create the <code>okta-issuer\/dbigroup<\/code> role.<\/p>\n\n\n<div class=\"wp-block-syntaxhighlighter-code \"><pre class=\"brush: plain; title: ; notranslate\" title=\"\">\nuse admin\ndb.createRole( {\n   role: &quot;okta-issuer\/dbigroup&quot;,\n   privileges: &#x5B; ],\n   roles: &#x5B; &quot;readWriteAnyDatabase&quot; ]\n} )\n<\/pre><\/div>\n\n\n<p class=\"wp-block-paragraph\">Now, any member of the <code>dbigroup<\/code> group should be able to log in with <code>mongosh<\/code> or any other connection tool, with the following parameters:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>--authenticationMechanism<\/code> flag set to <code>MONGODB-OIDC<\/code>. This parameter value is the official MongoDB parameter.<\/li>\n\n\n\n<li><code>--oidcFlows<\/code> flag set to <code>device-auth<\/code>. This can be used in environments where <code>mongosh<\/code> will not be able to launch a browser.<\/li>\n<\/ul>\n\n\n<div class=\"wp-block-syntaxhighlighter-code \"><pre class=\"brush: plain; title: ; notranslate\" title=\"\">\n# Change the MONGO_URI accordingly\nMONGO_URI=&quot;mongodb:\/\/127.0.0.1:27017&quot;\nmongosh &quot;$MONGO_URI&quot; --authenticationMechanism MONGODB-OIDC --oidcFlows=device-auth\n<\/pre><\/div>\n\n\n<p class=\"wp-block-paragraph\">After a few seconds, you will receive the URL to complete authentication:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>mongodb@mongodb-lab-01:\/home\/mongodb\/ &#091;mdb02] mongosh \"$MONGO_URI\" --authenticationMechanism MONGODB-OIDC --oidcFlows=device-auth\nCurrent Mongosh Log ID:\t6a64a98717240b2e9d9df8a2\nConnecting to:\t\tmongodb:\/\/127.0.0.1:27017\/?directConnection=true&amp;serverSelectionTimeoutMS=2000&amp;authMechanism=MONGODB-OIDC&amp;appName=mongosh+2.9.2\n\nVisit the following URL to complete authentication: https:\/\/trial-1234567.okta.com\/activate\nEnter the following code on that page: RQXFMWTF\nWaiting...<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">You can now open the link given (<code>https:\/\/trial-1234567.okta.com\/activate<\/code>), and it will ask for the activation code (<code>RQXFMWTF<\/code>).<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"397\" height=\"417\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/Screenshot-2026-07-25-at-17.09.30.png\" alt=\"\" class=\"wp-image-45727\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/Screenshot-2026-07-25-at-17.09.30.png 397w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/Screenshot-2026-07-25-at-17.09.30-286x300.png 286w\" sizes=\"auto, (max-width: 397px) 100vw, 397px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Once the device is activated, the <code>mongosh<\/code> prompt will succeed:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>mongodb@mongodb-lab-01:\/home\/mongodb\/ &#091;mdb02] mongosh \"$MONGO_URI\" --authenticationMechanism MONGODB-OIDC --oidcFlows=device-auth\nCurrent Mongosh Log ID:\t6a64a98717240b2e9d9df8a2\nConnecting to:\t\tmongodb:\/\/127.0.0.1:27017\/?directConnection=true&amp;serverSelectionTimeoutMS=2000&amp;authMechanism=MONGODB-OIDC&amp;appName=mongosh+2.9.2\n\nVisit the following URL to complete authentication: https:\/\/trial-1234567.okta.com\/activate\nEnter the following code on that page: RQXFMWTF\nWaiting...\nUsing MongoDB:\t\t8.0.26\nUsing Mongosh:\t\t2.9.2\n\nEnterprise test&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">And if you run the <code>db.runCommand({connectionStatus:1})<\/code> command, you will see the OIDC connection information:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Enterprise test&gt; db.runCommand({connectionStatus:1})\n{\n  authInfo: {\n    authenticatedUsers: &#091; { user: 'okta-issuer\/dbiblog@dbi-services.com', db: '$external' } ],\n    authenticatedUserRoles: &#091;\n      { role: 'okta-issuer\/Everyone', db: 'admin' },\n      { role: 'okta-issuer\/dbigroup', db: 'admin' },\n      { role: 'readWriteAnyDatabase', db: 'admin' }\n    ]\n  },\n  ok: 1\n}<\/code><\/pre>\n\n\n\n<h2 id=\"h-adapt-dmk-to-work-with-oidc\" class=\"wp-block-heading\">Adapt DMK to work with OIDC<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you use the <a href=\"https:\/\/dbi-services.gitbook.io\/dmk-mongodb\">MongoDB DMK<\/a>, you should either adapt the <code>msp<\/code> alias or create a new <code>msoidc<\/code> alias to connect to your instances. To do so, edit the local configuration file of DMK with the <code>dmkl<\/code> alias:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># Option 1: change the msp alias\nalias::msp::novar_noforce::'ms --authenticationMechanism MONGODB-OIDC --oidcFlows=device-auth'::\n\n# Option 2: add a new msoidc alias\nalias::msoidc::novar_noforce::'ms --authenticationMechanism MONGODB-OIDC --oidcFlows=device-auth'::<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Since version 7.0.11, MongoDB natively supports OpenID Connect (OIDC) authentication. This move was part of MongoDB\u2019s cloud strategy, since cloud environments use OIDC a lot for authentication and authorization. In version 8.0, MongoDB deprecated LDAP authentication and authorization, making it clear that OIDC is the future for MongoDB authentication. In this blog, I will present [&hellip;]<\/p>\n","protected":false},"author":152,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":"","_members_access_role":[],"_members_access_error":""},"categories":[3788],"tags":[995,1547,3571,2961,3202,2764,4146,2564],"type_dbi":[4148,4151,3842,3407,4150,4147,4149,3289],"class_list":["post-45678","post","type-post","status-publish","format-standard","hentry","category-mongodb","tag-authentication","tag-ldap","tag-mongo","tag-mongodb","tag-oauth2","tag-oidc","tag-okta","tag-security-3","type-authentication","type-ldap","type-mongo","type-mongodb","type-oauth2","type-oidc","type-okta","type-security"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.2 (Yoast SEO v28.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>MongoDB OIDC Authentication with Okta - dbi Blog<\/title>\n<meta name=\"description\" content=\"How to configure MongoDB OIDC authentication with Okta, from the Okta application setup to the access policy, group claims, and MongoDB configuration.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.dbi-services.com\/blog\/mongodb-oidc-authentication-with-okta\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"MongoDB OIDC Authentication with Okta\" \/>\n<meta property=\"og:description\" content=\"How to configure MongoDB OIDC authentication with Okta, from the Okta application setup to the access policy, group claims, and MongoDB configuration.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.dbi-services.com\/blog\/mongodb-oidc-authentication-with-okta\/\" \/>\n<meta property=\"og:site_name\" content=\"dbi Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-06T06:58:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_applications_panel.png\" \/>\n\t<meta property=\"og:image:width\" content=\"704\" \/>\n\t<meta property=\"og:image:height\" content=\"984\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Julien Delattre\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Julien Delattre\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/mongodb-oidc-authentication-with-okta\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/mongodb-oidc-authentication-with-okta\\\/\"},\"author\":{\"name\":\"Julien Delattre\",\"@id\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/#\\\/schema\\\/person\\\/764ab019cc9dec42655b4c6b9b8e474e\"},\"headline\":\"MongoDB OIDC Authentication with Okta\",\"datePublished\":\"2026-08-06T06:58:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/mongodb-oidc-authentication-with-okta\\\/\"},\"wordCount\":1123,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/mongodb-oidc-authentication-with-okta\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/wp-content\\\/uploads\\\/sites\\\/2\\\/2026\\\/08\\\/okta_applications_panel.png\",\"keywords\":[\"Authentication\",\"ldap\",\"Mongo\",\"mongodb\",\"OAUTH2\",\"oidc\",\"okta\",\"Security\"],\"articleSection\":[\"MongoDB\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/mongodb-oidc-authentication-with-okta\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/mongodb-oidc-authentication-with-okta\\\/\",\"url\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/mongodb-oidc-authentication-with-okta\\\/\",\"name\":\"MongoDB OIDC Authentication with Okta - dbi Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/mongodb-oidc-authentication-with-okta\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/mongodb-oidc-authentication-with-okta\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/wp-content\\\/uploads\\\/sites\\\/2\\\/2026\\\/08\\\/okta_applications_panel.png\",\"datePublished\":\"2026-08-06T06:58:00+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/#\\\/schema\\\/person\\\/764ab019cc9dec42655b4c6b9b8e474e\"},\"description\":\"How to configure MongoDB OIDC authentication with Okta, from the Okta application setup to the access policy, group claims, and MongoDB configuration.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/mongodb-oidc-authentication-with-okta\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/mongodb-oidc-authentication-with-okta\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/mongodb-oidc-authentication-with-okta\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/wp-content\\\/uploads\\\/sites\\\/2\\\/2026\\\/08\\\/okta_applications_panel.png\",\"contentUrl\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/wp-content\\\/uploads\\\/sites\\\/2\\\/2026\\\/08\\\/okta_applications_panel.png\",\"width\":704,\"height\":984},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/mongodb-oidc-authentication-with-okta\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"MongoDB OIDC Authentication with Okta\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/\",\"name\":\"dbi Blog\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/#\\\/schema\\\/person\\\/764ab019cc9dec42655b4c6b9b8e474e\",\"name\":\"Julien Delattre\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a97d00e680bbf237126e24b65281cbcb66cd20bd1ed2d14bf928991b2bf68eb5?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a97d00e680bbf237126e24b65281cbcb66cd20bd1ed2d14bf928991b2bf68eb5?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a97d00e680bbf237126e24b65281cbcb66cd20bd1ed2d14bf928991b2bf68eb5?s=96&d=mm&r=g\",\"caption\":\"Julien Delattre\"},\"url\":\"https:\\\/\\\/www.dbi-services.com\\\/blog\\\/author\\\/juliendelattre\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"MongoDB OIDC Authentication with Okta - dbi Blog","description":"How to configure MongoDB OIDC authentication with Okta, from the Okta application setup to the access policy, group claims, and MongoDB configuration.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.dbi-services.com\/blog\/mongodb-oidc-authentication-with-okta\/","og_locale":"en_US","og_type":"article","og_title":"MongoDB OIDC Authentication with Okta","og_description":"How to configure MongoDB OIDC authentication with Okta, from the Okta application setup to the access policy, group claims, and MongoDB configuration.","og_url":"https:\/\/www.dbi-services.com\/blog\/mongodb-oidc-authentication-with-okta\/","og_site_name":"dbi Blog","article_published_time":"2026-08-06T06:58:00+00:00","og_image":[{"width":704,"height":984,"url":"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_applications_panel.png","type":"image\/png"}],"author":"Julien Delattre","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Julien Delattre","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.dbi-services.com\/blog\/mongodb-oidc-authentication-with-okta\/#article","isPartOf":{"@id":"https:\/\/www.dbi-services.com\/blog\/mongodb-oidc-authentication-with-okta\/"},"author":{"name":"Julien Delattre","@id":"https:\/\/www.dbi-services.com\/blog\/#\/schema\/person\/764ab019cc9dec42655b4c6b9b8e474e"},"headline":"MongoDB OIDC Authentication with Okta","datePublished":"2026-08-06T06:58:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.dbi-services.com\/blog\/mongodb-oidc-authentication-with-okta\/"},"wordCount":1123,"commentCount":0,"image":{"@id":"https:\/\/www.dbi-services.com\/blog\/mongodb-oidc-authentication-with-okta\/#primaryimage"},"thumbnailUrl":"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_applications_panel.png","keywords":["Authentication","ldap","Mongo","mongodb","OAUTH2","oidc","okta","Security"],"articleSection":["MongoDB"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.dbi-services.com\/blog\/mongodb-oidc-authentication-with-okta\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.dbi-services.com\/blog\/mongodb-oidc-authentication-with-okta\/","url":"https:\/\/www.dbi-services.com\/blog\/mongodb-oidc-authentication-with-okta\/","name":"MongoDB OIDC Authentication with Okta - dbi Blog","isPartOf":{"@id":"https:\/\/www.dbi-services.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.dbi-services.com\/blog\/mongodb-oidc-authentication-with-okta\/#primaryimage"},"image":{"@id":"https:\/\/www.dbi-services.com\/blog\/mongodb-oidc-authentication-with-okta\/#primaryimage"},"thumbnailUrl":"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_applications_panel.png","datePublished":"2026-08-06T06:58:00+00:00","author":{"@id":"https:\/\/www.dbi-services.com\/blog\/#\/schema\/person\/764ab019cc9dec42655b4c6b9b8e474e"},"description":"How to configure MongoDB OIDC authentication with Okta, from the Okta application setup to the access policy, group claims, and MongoDB configuration.","breadcrumb":{"@id":"https:\/\/www.dbi-services.com\/blog\/mongodb-oidc-authentication-with-okta\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.dbi-services.com\/blog\/mongodb-oidc-authentication-with-okta\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.dbi-services.com\/blog\/mongodb-oidc-authentication-with-okta\/#primaryimage","url":"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_applications_panel.png","contentUrl":"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2026\/08\/okta_applications_panel.png","width":704,"height":984},{"@type":"BreadcrumbList","@id":"https:\/\/www.dbi-services.com\/blog\/mongodb-oidc-authentication-with-okta\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.dbi-services.com\/blog\/"},{"@type":"ListItem","position":2,"name":"MongoDB OIDC Authentication with Okta"}]},{"@type":"WebSite","@id":"https:\/\/www.dbi-services.com\/blog\/#website","url":"https:\/\/www.dbi-services.com\/blog\/","name":"dbi Blog","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.dbi-services.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.dbi-services.com\/blog\/#\/schema\/person\/764ab019cc9dec42655b4c6b9b8e474e","name":"Julien Delattre","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a97d00e680bbf237126e24b65281cbcb66cd20bd1ed2d14bf928991b2bf68eb5?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a97d00e680bbf237126e24b65281cbcb66cd20bd1ed2d14bf928991b2bf68eb5?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a97d00e680bbf237126e24b65281cbcb66cd20bd1ed2d14bf928991b2bf68eb5?s=96&d=mm&r=g","caption":"Julien Delattre"},"url":"https:\/\/www.dbi-services.com\/blog\/author\/juliendelattre\/"}]}},"_links":{"self":[{"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/posts\/45678","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/users\/152"}],"replies":[{"embeddable":true,"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/comments?post=45678"}],"version-history":[{"count":28,"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/posts\/45678\/revisions"}],"predecessor-version":[{"id":46264,"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/posts\/45678\/revisions\/46264"}],"wp:attachment":[{"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/media?parent=45678"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/categories?post=45678"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/tags?post=45678"},{"taxonomy":"type","embeddable":true,"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/type_dbi?post=45678"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}