1 · Pre-populate — probe the visitor's extension for its current Okta tenant
(loads a hidden
/home/plugin/ classification pass and reads the markers
the plugin injects).
idle
Detected tenant:
—
2 · Override — set the org the dynamic
/.well-known/okta-organization
mirrors for this session (arbitrary injection).
Session org:
…
· well-known probes: 0
3 · Plant — visit
/home/plugin/
with the Okta Browser Plugin installed (or use the button to open it).
| Extension DOM marker | Meaning | Status |
|---|---|---|
okta-plugin-message-channel-available | content script present (baseline) | |
okta-plugin-version | page classified as org UserHome | |
okta-plugin-version-from-headers | customDomain mapping applied (trust signal) | |
sites-loaded | org tasks ran (tabs/sites fetched) | |
plugin-context | interstitial context JSON (domain/newDomain) | |
okta-plugin-consent-required-from-headers | account consent banner triggered |
4 · Undo — server reset + the extension's own storage reset
(
/plugin/resetstorage on the planted org wipes DOMAINS,
TRUSTED_OKTA_DOMAIN_LIST and the account allow-list).
Authorized testing only — run against your own orgs and your own browser profiles. Signals: