> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authorize Your Iru Tenant for Okta Workflows

> Authorize your Iru Endpoint tenant for Okta Workflows integration. Generate API tokens, configure the connector, and enable automated device workflows.

<Callout icon="list-check" color="#B84A7A" iconType="regular">This guide applies to Mac computers and Windows devices</Callout>

<Note>
  In Okta Workflows, the connector is still listed as **Kandji**. The steps in this guide that create an API token and copy your domain are performed in **Iru Endpoint**. When you configure the connection in Okta Workflows, select **Kandji** and enter your Iru Endpoint API token and domain.
</Note>

### About Authorizing Your Iru Tenant for Okta Workflows

Authorizing your Iru Endpoint tenant for Okta Workflows lets Okta Workflows connect to your tenant through the **Kandji** connector, so you can automate device management tasks in your workflows.

### How It Works

The **Kandji** connector in Okta Workflows connects to your Iru Endpoint tenant using an API token and domain. After you configure the connection, you can build workflows that respond to user lifecycle events and device management tasks without manual steps in Iru Endpoint.

### Prerequisites

Before you begin, ensure you have:

* Okta Workflows admin credentials
* Iru Endpoint administrator access
* API access enabled in your Iru Endpoint tenant

After successfully authorizing your Iru Endpoint tenant for Okta Workflows, you can [use Kandji connector action cards in Okta Workflows](/en/endpoint/integrations/okta-workflows/use-kandji-connector-action-cards-with-okta-workflows).

### Authorizing Your Iru Tenant

Authorization has two parts: create an API token and copy your domain in **Iru Endpoint**, then configure the **Kandji** connector in **Okta Workflows** with those values.

When you add a **Kandji** card to a workflow for the first time, Okta Workflows prompts you to configure the connection. You can save the connection and reuse it for future workflows.

<Note>
  You can create and manage multiple connections from your **Connections** page.
</Note>

#### Creating an API Token in Iru Endpoint

Complete these steps in the **Iru Endpoint** web app.

To create an API token for the Kandji connector in Okta Workflows:

<Steps>
  <Step title="Access Iru Endpoint">
    Sign in to the Iru Endpoint web app with administrator credentials.
  </Step>

  <Step title="Open Access">
    In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Access**.

    <Frame>
      <img src="https://mintcdn.com/iru/8BYPjuKZa-zyEEf_/assets/media/images/iru-nav-access.png?fit=max&auto=format&n=8BYPjuKZa-zyEEf_&q=85&s=466fdf5fb47efd6bab8b450a5a1e8302" alt="Screenshot of the account menu with Access option highlighted" width="562" height="1040" data-path="assets/media/images/iru-nav-access.png" />
    </Frame>
  </Step>

  <Step title="Add Token">
    On the **API tokens** tab, click **Add Token**.
  </Step>

  <Step title="Configure Token Name">
    In the **Name** field, enter a name such as Okta Workflows.
  </Step>

  <Step title="Add Token Description">
    In the Description field, enter a description such as *Allow Okta Workflows to use the Iru Endpoint API*.
  </Step>

  <Step title="Create Token">
    Click **Create**.
  </Step>

  <Step title="Copy API Token">
    In the **Copy your API token** dialog, click **Copy Token**.
  </Step>

  <Step title="Store Token Securely">
    Store the copied token in a safe place. If you lose the text for the token, you can delete it before you use it and create a new one with the steps above. You'll use this token in step 4 of the next section.
  </Step>

  <Step title="Confirm Token Copy">
    Select the checkbox for **I have copied the token and understand that I will not be able to see these details again.**
  </Step>

  <Step title="Continue Setup">
    Click Next.
  </Step>

  <Step title="Configure Permissions">
    In the **Manage API Permissions** dialog, click **Configure**.
  </Step>

  <Step title="Select Permissions">
    In the Permissions section, select the checkbox for each area to which you want Okta Workflows to have access. For example, select the checkbox for **Blueprints Management** to enable all permissions for inspecting and modifying Blueprints. Note: You can click the disclosure triangle to the right of the permission type to display more specific permissions.
  </Step>

  <Step title="Review Permissions">
    Review the permissions you've configured for the API token.
  </Step>

  <Step title="Save Configuration">
    Click **Save** then **Close**.
  </Step>

  <Step title="Verify Token Creation">
    On the **API tokens** tab, confirm that your new token is displayed.
  </Step>

  <Step title="Copy API URL">
    In **Your organization's API URL is** field, copy or make a note of your Iru Endpoint domain.

    <Frame>
      <img src="https://mintcdn.com/iru/97IKZnNVEzytYzut/assets/media/images/iru-okta-workflows-api-url.png?fit=max&auto=format&n=97IKZnNVEzytYzut&q=85&s=05f21971cae8156ca02cc0ab32a3e559" alt="Iru Endpoint API URL field showing the organization's API URL that needs to be copied for the Okta Workflows connection" width="1898" height="866" data-path="assets/media/images/iru-okta-workflows-api-url.png" />
    </Frame>
  </Step>
</Steps>

#### Setting Up the Kandji Connector in Okta Workflows

Complete these steps in **Okta Workflows**. You need the API token and domain from the previous section.

You can create more than one connection. For example, you might have multiple Iru Endpoint tenants or be testing multiple API tokens. The API token must include at least **Devices: Device Information: Device list** permission. Grant additional permissions based on the workflow actions you plan to use. For example, to list all devices, the token needs:

| Permission                                      | Description                                          |
| ----------------------------------------------- | ---------------------------------------------------- |
| **Devices: Device Information: Device list**    | Get a list of all devices in the Iru Endpoint tenant |
| **Devices: Device Information: Device details** | Get the full details for a specific device           |

<Steps>
  <Step title="Create New Connection">
    In Okta Workflows, from the Connections page or any card, click **New Connection**.

    <Frame>
      <img src="https://mintcdn.com/iru/TTV4GXkIHgRpdDZ5/assets/media/images/vfphord5i4ewvudgk8gpzxt6wlox5wna_q.png?fit=max&auto=format&n=TTV4GXkIHgRpdDZ5&q=85&s=eda67c90cc03aa82156d004721a7cbab" alt="Okta Workflows Connections page showing the New Connection button that needs to be clicked to create a new connection" width="788" height="336" data-path="assets/media/images/vfphord5i4ewvudgk8gpzxt6wlox5wna_q.png" />
    </Frame>
  </Step>

  <Step title="Select the Kandji connector">
    In the New Connection window, scroll if necessary, then select **Kandji**. This is the connector name in Okta Workflows; it connects to your Iru Endpoint tenant.

    <Frame>
      <img src="https://mintcdn.com/iru/qQl9m4UQwfP-FkWY/assets/media/images/khfam958ppbpyh-ve7nwy2xmrvkhbozwww.png?fit=max&auto=format&n=qQl9m4UQwfP-FkWY&q=85&s=1b1405cf087e856a1bb71f6d3de579b5" alt="Okta Workflows New Connection window showing the list of available connectors with Kandji highlighted for selection" width="755" height="826" data-path="assets/media/images/khfam958ppbpyh-ve7nwy2xmrvkhbozwww.png" />
    </Frame>
  </Step>

  <Step title="Configure Connection Nickname">
    In the **Connection Nickname** field, enter a unique name that will help you distinguish multiple Iru Endpoint tenants or multiple Iru Endpoint API keys.
  </Step>

  <Step title="Enter API Key">
    In the **API key** field, enter or paste the text of the API token you generated in step 7 of the previous section.
  </Step>

  <Step title="Enter domain">
    In the **Kandji domain** field, enter your full Iru Endpoint domain from step 16 of the previous section. Okta Workflows labels this field **Kandji domain**, but the value is your Iru Endpoint API URL (for example, *accuhive.api.kandji.io* or *accuhive.api.eu.kandji.io*).
  </Step>

  <Step title="Create Connection">
    Click **Create**.

    <Frame>
      <img src="https://mintcdn.com/iru/oxRcYXnzj6p6Lxvi/assets/media/images/ucjhliic8x7tljpejp3f0z3stj-4ue5f9q.jpg?fit=max&auto=format&n=oxRcYXnzj6p6Lxvi&q=85&s=bbfce12153f825043304e878a7977a7f" alt="Okta Workflows connection configuration form showing the Connection Nickname, API key, and Iru Endpoint domain fields filled out with the Create button ready to be clicked" width="1286" height="1396" data-path="assets/media/images/ucjhliic8x7tljpejp3f0z3stj-4ue5f9q.jpg" />
    </Frame>
  </Step>
</Steps>

The **Kandji** connector is now configured and connected to your Iru Endpoint tenant. You can use it with the available connector cards.

#### Using the Connection in Workflows

<Steps>
  <Step title="Create New Flow">
    In Workflows go to the Flows section and click **+New Flow**.
  </Step>

  <Step title="Add App Action">
    Click **Add app action**.
  </Step>

  <Step title="Select Kandji">
    In the **My Connected Apps** section, click **Kandji**. Okta Workflows still displays this app name; it provides access to your Iru Endpoint tenant.

    <Frame>
      <img src="https://mintcdn.com/iru/OVGwzrvB1dITOQ_N/assets/media/images/eagvnzntuqyfysksduawtmjno8xjxkaoqq.png?fit=max&auto=format&n=OVGwzrvB1dITOQ_N&q=85&s=a60a29cce45eccff26b06344a2554f64" alt="Okta Workflows My Connected Apps section showing Iru Endpoint as an available connected app that can be selected for workflow actions" width="788" height="576" data-path="assets/media/images/eagvnzntuqyfysksduawtmjno8xjxkaoqq.png" />
    </Frame>
  </Step>

  <Step title="Choose Connector Card">
    Select a connector card.
  </Step>

  <Step title="Configure and Continue">
    Configure the card and continue building your workflow.

    <Frame>
      <img src="https://mintcdn.com/iru/Pp4ndpzRp4nipP1L/assets/media/images/2dlkkgdqmcfliubdv8ctcltgbibrotfuia.png?fit=max&auto=format&n=Pp4ndpzRp4nipP1L&q=85&s=dbf6e6324fff652b8e5eab439d735176" alt="Okta Workflows connector card selection interface showing available Iru Endpoint action cards that can be selected for the workflow" width="1426" height="1444" data-path="assets/media/images/2dlkkgdqmcfliubdv8ctcltgbibrotfuia.png" />
    </Frame>
  </Step>
</Steps>
