WorkOS
82 Case Studies
A WorkOS Case Study
Okta, a leading identity and access management company, needed to enable secure single sign-on (SSO) for its command-line interface (CLI) tool to meet enterprise security requirements. The challenge was that a traditional CLI, which typically uses static API keys, cannot natively speak the SAML or OIDC protocols required for enterprise authentication, making it difficult to pass a rigorous security review.
WorkOS implemented a solution using its AuthKit product, providing two standardized OAuth 2.0 flows: Authorization Code with PKCE for users with a local browser and Device Code for headless environments. This allowed Okta's CLI to securely delegate authentication to a user's browser, which then seamlessly routed through their organization's configured identity provider, such as Okta itself. The solution was implemented quickly, required minimal code, and provided enterprise-grade security with built-in support for MFA and conditional access policies, all while being free for up to one million monthly active users.