Coupa OIN Application Provisioning Error when Enabling Okta Identity Governance (OIG)
Last Updated:
Overview
Missing OpenID Connect (OIDC) scopes in the Coupa application cause a provisioning error when enabling the Governance Engine. Add the required scopes in the Coupa web administration portal to resolve the error. When enabling the Governance Engine for the Coupa Okta Integration Network (OIN) application, Okta generates the following error during provisioning attempts:
OAuth credentials must be authenticated first before saving.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Integration Network (OIN)
- Coupa OIN Application
- Okta Identity Governance (OIG)
- Governance Engine
Cause
The OpenID Connect (OIDC) settings in Coupa lack the required scopes.
Solution
What steps are needed to resolve the missing OpenID Connect scopes in Coupa?
Navigate to the Coupa web administration portal and configure the OAuth2 and OpenID Connect client settings to include the required scopes for Coupa and Entitlements.
- Open the Coupa web administration portal.
- Navigate to Setup and choose OAuth2/OpenID Connect Clients.
- Add the following scopes:
openidoffline_accesscore.user.readcore.user.writecore.common.read
