CYBBACK| for Okta
Product Datasheet

Your Okta users, apps, policies & Workflows — backed up cold.

Enterprise-grade, automated backup & recovery for Okta — users, groups, applications, policies, authorization servers, identity providers, hooks, brands, System Log and Workflows. Incremental, encrypted, dependency-aware restore, hub and spoke.

35+ object typesDependency-aware restoreRecycle binHub and spokeEU-hosted
Why CYBBACK

Okta has no recycle bin — one deletion and your identity configuration is gone

Incremental forever
Only objects changed since the last run are fetched (lastUpdated filters); deletions are detected and kept in the CYBBACK recycle bin.
Dependency-aware restore
Restoring a user also recreates its deleted groups, app assignments, manager and (opt-in) admin roles and policies. The plan is checked live in your org before any write.
Recycle bin
Users, groups, apps and policies deleted from Okta stay browsable and restorable from every backup — Okta itself keeps nothing.
Drift detection
Automatic comparison between runs. Get alerted on mass deprovisioning, group or policy deletions between two backups.
AES-256-GCM encryption
API token / private key and backup files encrypted at rest. Master key in Google Secret Manager (EU). Optional per-file encryption.
Bring Your Own Bucket
Store backups on your S3-compatible storage. Your data, your provider, your region. Per-backup snapshot of credentials.
What gets backed up

Your Okta org, layer by layer

Users & groupsProfiles, statuses, memberships, group rules, admin roles, manager — deprovisioned users included
User schema & typesCustom attributes, user types, linked objects, profile mappings
ApplicationsSAML, OIDC, SWA, Org2Org apps with user/group assignments, OIDC secrets, SAML keys, features, grants
Policies & rulesGlobal session, password, MFA enrollment, app access, profile enrollment, IdP routing — with their rules
Security objectsNetwork zones, trusted origins, device assurance, behavior rules, ThreatInsight, authenticators
Federation & authorizationAuthorization servers (scopes, claims, policies), identity providers and keys
Admin modelCustom admin roles, resource sets, role assignments
Org configurationOrg settings, brands & themes, custom domains, email domains, event/inline hooks, features, API token metadata
System Log (optional)Audit events archived (30-day initial window, then incremental) — beyond Okta's 90-day retention
Okta Workflows (bridge)Every saved flow is exported by a flow you build in your tenant (Okta has no Workflows management API) and attached to the next backup
Technical specifications

Built on the Okta Management API

AuthenticationSSWS API token or OAuth 2.0 API Services app (client_credentials + private_key_jwt) — encrypted AES-256-GCM in the CYBBACK vault
API endpointsOkta Management API /api/v1 · per-bucket rate-limit aware (users / groups / apps / logs) · Link-header pagination
Backup modeIncremental forever (catalog/pool). Users & groups via lastUpdated / lastMembershipUpdated; other categories re-snapshotted; deletions diffed per run
Multi-orgOne credential per org. Hub and spoke topology (Org2Org) detected automatically; each org backed up separately
Capture optionsClient toggles: System Log (initial window 1–90 days), device inventory, Workflows bridge
FrequencyManual, twice daily (default schedule), daily, weekly, or custom cron expression
Storage backendDefault: CYBBACK secure storage (EU). Optional: BYOB — any S3-compatible provider
Encryption at restAES-256-GCM, optional per-user toggle. Manifest excluded from encryption
Restore granularityObject by object across 25+ restorable categories; recycle bin view; matching by id then login/name (portable across orgs)
Restore optionsDry-run · update existing · name prefix · user activation mode · dependency cascade (groups, assignments, manager, members, policies, admin roles) · asynchronous worker
Honest limitsPasswords and MFA factors are not restorable (users land STAGED or receive an activation email). SAML certificates and authorization-server issuers are regenerated on recreation. IdP and hook secrets must be re-entered. Workflows are restored through an assisted import in the Workflows console, connections to re-link (no Okta import API)
Native exportsZIP with raw JSON per category, CSV (users, groups, members, app assignments, admins, apps), HTML report, System Log
Drift detection3 severity levels (info / warning / critical). Custom thresholds on deletions of users, groups, apps, policies
NotificationsIn-app · email · Slack · webhooks
Hosting regionGoogle Cloud — europe-west1 (Belgium)
Trust & compliance

Security you can prove

GDPR-alignedEU residency, DPA on request
AES-256-GCMIndustry-standard encryption
Audit logsEvery action is traceable
EU hostingBelgium (europe-west1)

Start your free trial

Create an Okta API token or API Services app, paste it into CYBBACK, and back up your whole org in under 5 minutes.

Start free trial