Okta System API Token Creation Events

Flags Okta API token creation events to support investigation of potential persistence.

FreeReviewedSigma · Medium · v4
Product
okta
Service
okta
Author
Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-09-12
Updated
2026-07-31

What it detects

This rule identifies Okta System Log events where an API token is created (eventType system.api_token.create). Creating an API token can enable persistent access for automation or integrations and may be abused for unauthorized API usage. Detection relies on Okta event telemetry from the system log that records token creation actions.

Changelog

v4
  1. v4
    Candidate ingested via manual entry.2026-07-31
  2. v3
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31
  4. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.