Trigger a Flow when suspicious activity is reported in Okta.

Unless otherwise indicated, field types are text.


  • Date and Time: date and time the webhook event was published
  • Name: name of the user who reported suspicious activity
  • Email: email address of the user
  • User ID: ID of the user
  • Suspicious Activity Details: details about the suspicious activity reported
  • Full Details (object): entire raw JSON payload returned from the Okta API