Version 1.2.5 · Free & open source

Stop writing Okta expressions by hand.

ORB drops a visual logic builder straight into the Okta admin console. Compose nested AND / OR conditions, import an expression you already have, and see exactly which users match before you ever hit save.

Runs entirely in your browser. Nothing leaves your tenant.

9+Okta upgrades
0Servers involved
16Profile operators
100%Open source

Paste the expression. Get the logic.

ORB parses real Okta Expression Language, including nested parentheses, negation and String.* helpers, then maps every fragment onto a control you can actually click. Edit the blocks and valid expression language regenerates as you type.

  1. 1Import an existing rule, or start from a blank condition
  2. 2Tokens resolve into profile attributes, operators and values
  3. 3Nested groups become AND / OR blocks you can reorder
  4. 4Copy the regenerated expression back into Okta with confidence
ANDmatch all of the following
ProfileDepartmentequalsEngineering
ORmatch any of the following
Groupis a member ofContractors
Groupname starts withVENDOR-

Nine upgrades the admin console was missing

Every one of them lives inside pages you already use. No separate app, no data export, no setup.

Visual logic builder

Compose nested AND / OR conditions on profile attributes and group membership. Valid Okta Expression Language generates live as you build.

Groups > Rules > Add Rule

Real-time rule preview

Test an expression against live users before you activate it. See who matches, who doesn't, and catch the mistake while it's still cheap.

Preview OEL Rule

Auth DENY tracing

Open a DENY event in the System Log and jump straight to the authentication policy rule that triggered it. No more guessing which policy fired.

Reports > System Log

Push group discovery

A Push Groups tab on every group page lists each application the group is pushed to, and the target group name on the other side.

Directory > Groups

Search that reaches everything

Find a Workflow by partial name regardless of which folder it lives in, and search authentication policies by application.

Workflows · Auth Policies

CSV exports

Export from the People page, app assignments, group membership and push groups. Pick the profile and app-specific attributes you want in the file.

People · Applications · Groups

Helpdesk MFA verification

Validate a caller from the user page by sending a real MFA prompt, so IT support can confirm identity without a scripted secret question.

Directory > People

Custom attributes, discovered

ORB reads your user schema and offers your custom attributes in a dropdown, with boolean operators where the schema says boolean.

No more typing user.customField

View rule from a group

Looking at a group populated by a rule? A View Rule button shows the expression behind it in one click. More features land with every release.

...and more coming soon

This is the real builder. Go ahead.

The panel below runs the exact same code ORB injects into Okta, loaded straight from the extension source. Build a rule, nest some logic, or load one of the sample expressions and watch it come apart into blocks.

your-org-admin.okta.com/admin/groups/rules ORB sandbox
Load a sample

Note: the live user preview is intentionally absent here, since that feature talks to your own Okta tenant. Everything else is the genuine article, custom attributes included.

Two minutes, two options

The Chrome Web Store build keeps itself updated as new features ship. The source is always there if you'd rather load it yourself.

From the Chrome Web Store

Search for ORB or Okta Rule Builder and you'll find it. Installing this way means new features arrive automatically.

Open the Chrome Web Store

Load it unpacked

  1. Download the repository files into a folder named ORB. If it arrives as a .zip, extract it.
  2. Open chrome://extensions/ in Chrome.
  3. Turn on Developer mode in the top right.
  4. Click Load unpacked in the top left and select your ORB folder.
Get the source on GitHub

The things people ask first

Does ORB send my Okta data anywhere?
No. ORB runs entirely in your browser and talks only to the Okta tenant you are already signed in to, using your own session. There is no ORB server, no analytics and no third party endpoint. The source is public, so you can verify that yourself.
What permissions does it need?
ORB only activates on Okta admin and org domains. It needs to read and modify the page you are on so it can inject its UI, and it reuses your existing admin session to call the Okta API for things like the user schema and rule previews. It cannot do anything your admin account cannot already do.
Will it break my existing rules?
ORB never writes a rule on its own. It builds an expression and hands it to you to review, copy and save in Okta yourself. When an expression contains a fragment ORB cannot map to a control, it preserves the text verbatim as an editable Raw EL row and warns you rather than silently dropping it.
Is the generated expression language actually valid?
The operators map to documented Okta Expression Language functions, and unsupported patterns such as String.endsWith are deliberately left out. The builder is still marked beta, so verify any expression with the rule preview before you activate it. That is exactly what the preview is for.
Does it work with my custom attributes?
Yes. ORB loads your user schema and lists your custom attributes in the attribute dropdown with their real display names. Attributes the schema types as boolean get Is True and Is False operators, which generate an unquoted boolean comparison rather than a string match.
Is it affiliated with Okta?
No. ORB is an independent community tool built by an Okta admin, for Okta admins. It is not endorsed by, affiliated with or supported by Okta, Inc.
I found a bug, or I want a feature.
Open an issue on GitHub. Every one gets read.

Built by Tim McWeeny

ORB started as a single rule builder packaged for the Rockstar extension and grew into a general toolkit for Okta admins who spend their days in the console. It is free, open source, and shipped on evenings and weekends.

Special thanks to Gabriel Stroka, creator of the much loved Rockstar extension, for all his help and encouragement building this tool.

Latest release

Version 1.2.5

  1. Added a Push Groups tab to every group page, listing each app the group is pushed to.
  2. Improved overall UI readability and consistency across every injected panel.
  3. Auth policy triggers reviewable directly from DENY events in the System Log.
Full version notes