Skip to content

This tool is not affiliated with, endorsed by or sponsored by Okta, Inc. Okta is a trademark of Okta, Inc. Other names are trademarks of their respective owners.

Glossary

externalSessionId

The Okta session identifier in authenticationContext, used to group every event of one sign-in session and to spot a session replayed from elsewhere.

authenticationContext.externalSessionId identifies the Okta session an event belongs to. Grouping events by it shows everything done in one session; seeing the same value from two networks (ASNs) or two browsers is the classic trace of a stolen session cookie. Okta Security notes that this identifier can be regenerated after factor lifecycle events, while rootSessionId follows the whole interactive session (Okta Security), so investigators should pivot on both.

More in Okta session hijacking detection.

This tool is not affiliated with, endorsed by or sponsored by Okta, Inc. Okta is a trademark of Okta, Inc. Other names are trademarks of their respective owners.