ST-2026-228 · Authentication & identity
Okta breached-credentials protection configuration API is GA in Production
Okta made the breached-credentials protection configuration API generally available in Production, exposing retrieve and replace endpoints for eligible Customer Identity customers to control the detection method used with the premium breached-credentials feed.
Previous state
Okta's August 2026 release notes state that the breached-credentials protection configuration API is GA in Production but do not state a prior availability state for its retrieve and replace endpoints.
Current state
Eligible Okta Customer Identity customers can use the Breached Credential Protection API to retrieve or replace the protection configuration and programmatically control the detection method used with the premium breached-credentials feed.
Affected users
Who needs to care
Eligible Okta Customer Identity customers using Identity Threat Protection and the premium breached-credentials detection feed.
Required response
What to do
Review current breached-credential detection settings and, where the premium feed is licensed, integrate the GA retrieve/replace configuration endpoints into governed security administration and change control.
Evidence boundary
What the source does not prove
Okta proves Production GA of the configuration API for eligible OCI customers. It does not change protection automatically for every tenant, prove that every customer licenses the premium feed, or establish a detected compromise for any user.
Lifecycle history
Dated event sequence
- Breached-credentials configuration API GA in Production
Okta's August monthly release lists the Retrieve and Replace configuration endpoints as generally available in Production.
Evidence ledger
First-party sources
- 01Okta — Okta Identity Engine API release notes 2026
Official Okta Developer release notes · 2026-08-05
Open official source ↗