SSF Security Event Tokens
This feature is only available with Identity Threat Protection in Identity Engine.
The Shared Signals Framework (SSF) Security Event Tokens API allows third-party security event providers to send Security Event Tokens (SETs) to Okta. The provider must be configured in Okta as a Security Events Provider instance before transmitting a SET to Okta. See Create a Security Events Provider. After the token is verified, any appropriate action is performed upon ingestion.
Okta uses the Shared Signals Framework (SSF) defined by the OpenID Shared Signals and Events Framework specification. A risk signal is ingested as a Security Event Token (SET), a type of JSON Web Token (JWT) that must comply with the SET RFC: RFC 8417 - Security Event Token(SET). The security.events.provider.receive_event System Log event is created when a SET is published to Okta successfully.