Okta Client SDK Design
The Okta Client SDK represents a collection of SDKs for different languages, each of which itself is a modular ecosystem of libraries that build upon one-another to enable client applications to:
- Authenticate clients with a Resource Server (RS) using a variety of authentication flows
- Flexibly store and manage the resulting tokens enabling a wide variety of use-classes
- Transparently persist and manage the lifecycle of those tokens through authentication, refresh, and revocation
- Secure applications and tokens, using best practices, by default
Design philosophy
These SDKs follow a common set of patterns, with key philosophies that guide its design and development. These include:
- 1-Line To Integrate
- Additive Development
- Discoverable APIs
- Overridable Business Logic
- Security & Defaults OOTB
For more details about this, please see the design philosophy document, since it influences all feature development within this SDK.
See more ›Architectural parity
All SDKs, regardless of the language or environment they're built for, aim to have parity with the architecture and patterns followed in other languages. Affordances are allowed for language or platform differences, but the patterns and structure of these libraries should remain the same.
This allows skills and knowledge a developer learns from using an SDK in one platform to be transferable to other platforms. Furthermore it makes it easier to identify feature parity gaps between platforms.
See more ›Structure and modularization
While this is referred to as the Client SDK, it actually consists of multiple libraries and components that all build upon eachother to provide modularization, extensibility, and customizability.

Each library within this ecosystem is accessible to the developer, providing direct control and extensibility at any layer. Each logical layer either introduces new features and capabilities, or abstracts and simplifies the libraries below them.
Ownership and collaboration
This collection of SDKs are not intended to be owned by any one group within Okta. Instead one or more libraries may be primarily owned by different teams, and to coordinate / collaborate with other groups to ensure consistency and stability of the interfaces.
One team within Okta WIC owns the overall architecture of these libraries, as well as the primary foundation and authentication tools, and (at least initially) acts as the primary architectural steering group for these libraries.
See more ›Modular library ecosystem
The client SDKs are modularized into different libraries/frameworks that encapsulates their specific capabilities, and enables:
- Other libraries to be built upon them, and
- Provide targeted extension points for customers to alter behavior in a more consistent and reliable manner.
The library ecosystem is largely divided into three separate layers:
- Foundational / common capabilities shared by all upstream libraries
- Low-level authentication libraries that implement specific styles of authentication flows
- UI libraries to simplify integration of sign-in to different application environments
Each "layer" of SDKs are directly accessible to the app developer, which allows them to interact directly with the user-facing SDK they choose to use, or to work with lower layers (either partially or exclusively) to customize their login experience as they see fit.