Glossary
Okta API token (SSWS)
A long-lived secret for the Okta management API that carries the permissions of the admin who created it, sent in an SSWS Authorization header.
An Okta API token authenticates calls to the Okta management API with an Authorization: SSWS <token> header. Okta documents that a token has the permissions of the user who created it, stays valid for 30 days and renews each time it is used, and is rejected only once its creator is deactivated (Okta Help Center). Resetting the creator's password or MFA therefore does not revoke it. Creation is logged as system.api_token.create; activity can be traced through transaction.detail.rootApiTokenId. See API token abuse.