Your Okta users, apps, policies & Workflows — backed up cold.
Enterprise-grade, automated backup & recovery for Okta — users, groups, applications, policies, authorization servers, identity providers, hooks, brands, System Log and Workflows. Incremental, encrypted, dependency-aware restore, hub and spoke.
35+ object typesDependency-aware restoreRecycle binHub and spokeEU-hosted
Why CYBBACK
Okta has no recycle bin — one deletion and your identity configuration is gone
Incremental forever
Only objects changed since the last run are fetched (lastUpdated filters); deletions are detected and kept in the CYBBACK recycle bin.
Dependency-aware restore
Restoring a user also recreates its deleted groups, app assignments, manager and (opt-in) admin roles and policies. The plan is checked live in your org before any write.
Recycle bin
Users, groups, apps and policies deleted from Okta stay browsable and restorable from every backup — Okta itself keeps nothing.
Drift detection
Automatic comparison between runs. Get alerted on mass deprovisioning, group or policy deletions between two backups.
AES-256-GCM encryption
API token / private key and backup files encrypted at rest. Master key in Google Secret Manager (EU). Optional per-file encryption.
Bring Your Own Bucket
Store backups on your S3-compatible storage. Your data, your provider, your region. Per-backup snapshot of credentials.
What gets backed up
Your Okta org, layer by layer
Users & groupsProfiles, statuses, memberships, group rules, admin roles, manager — deprovisioned users included
User schema & typesCustom attributes, user types, linked objects, profile mappings
System Log (optional)Audit events archived (30-day initial window, then incremental) — beyond Okta's 90-day retention
Okta Workflows (bridge)Every saved flow is exported by a flow you build in your tenant (Okta has no Workflows management API) and attached to the next backup
Technical specifications
Built on the Okta Management API
Authentication
SSWS API token or OAuth 2.0 API Services app (client_credentials + private_key_jwt) — encrypted AES-256-GCM in the CYBBACK vault
API endpoints
Okta Management API /api/v1 · per-bucket rate-limit aware (users / groups / apps / logs) · Link-header pagination
Backup mode
Incremental forever (catalog/pool). Users & groups via lastUpdated / lastMembershipUpdated; other categories re-snapshotted; deletions diffed per run
Multi-org
One credential per org. Hub and spoke topology (Org2Org) detected automatically; each org backed up separately
Passwords and MFA factors are not restorable (users land STAGED or receive an activation email). SAML certificates and authorization-server issuers are regenerated on recreation. IdP and hook secrets must be re-entered. Workflows are restored through an assisted import in the Workflows console, connections to re-link (no Okta import API)
Native exports
ZIP with raw JSON per category, CSV (users, groups, members, app assignments, admins, apps), HTML report, System Log
Drift detection
3 severity levels (info / warning / critical). Custom thresholds on deletions of users, groups, apps, policies
Notifications
In-app · email · Slack · webhooks
Hosting region
Google Cloud — europe-west1 (Belgium)
Trust & compliance
Security you can prove
GDPR-alignedEU residency, DPA on request
AES-256-GCMIndustry-standard encryption
Audit logsEvery action is traceable
EU hostingBelgium (europe-west1)
Start your free trial
Create an Okta API token or API Services app, paste it into CYBBACK, and back up your whole org in under 5 minutes.