Okta
Okta apps are SSO assignments, not OAuth consent grants, so rows carry no permission scopes — the scan shows which apps are connected and who is assigned, with AI detection by app name. Scope-based flags (--risky, --fail-on-risky) do not apply.
One-time setup:
assetloom-app-scanner config oktaIt asks for your org URL (paste anything from your Okta tab — subdomain, org URL, or an Admin Console URL), points you to the exact API token page for your org (read-only admin is enough), verifies the pasted token with one API call, and asks where to save (default ~/.assetloom-scanner/okta.json, so scans can omit --key).