Case Study: Okta SSO for CLIs with WorkOS AuthKit

A WorkOS Case Study

Preview of the Okta Case Study

Okta adds enterprise SSO to CLIs in a day with WorkOS

Okta, a leading identity and access management company, needed to enable secure single sign-on (SSO) for its command-line interface (CLI) tool to meet enterprise security requirements. The challenge was that a traditional CLI, which typically uses static API keys, cannot natively speak the SAML or OIDC protocols required for enterprise authentication, making it difficult to pass a rigorous security review.

WorkOS implemented a solution using its AuthKit product, providing two standardized OAuth 2.0 flows: Authorization Code with PKCE for users with a local browser and Device Code for headless environments. This allowed Okta's CLI to securely delegate authentication to a user's browser, which then seamlessly routed through their organization's configured identity provider, such as Okta itself. The solution was implemented quickly, required minimal code, and provided enterprise-grade security with built-in support for MFA and conditional access policies, all while being free for up to one million monthly active users.


View this case study…

WorkOS

82 Case Studies