Okta halved the idle window on its free developer plan to 90 days

Stani Mihov

Founder & CEO

·

TL;DR

What changed:

  • Idle Integrator Free Plan orgs are now deactivated after 90 days instead of 180, unless you have submitted an app to the Okta Integration Network.

  • Okta's license to your data now covers providing its products and services in general, not only this agreement.

  • Your Integrator Data is now listed as part of the usage data Okta owns.

  • The $100 liability cap now protects only Okta, and its exceptions for confidentiality and privacy breaches are gone.

  • Okta can now change the terms by posting them on its website.

What to do: If your team tests an Okta integration on a free Integrator org, use it at least every 90 days, and keep real customer data out of it.

The change

Okta's Integrator Free Plan is the free environment developers use to build and test integrations with Okta, such as single sign-on or user provisioning for their own product. On September 2, 2026, Venpo detected a rewrite of the plan's subscription agreement.

The headline change is a number: idle orgs are now deactivated after 90 days instead of 180. The same rewrite also widens Okta's rights over the data you put into the plan, makes the liability cap one-sided, and lets Okta change the terms by posting them. The redline is on the public change page.

What changed

  • 90 days instead of 180. "Integrator orgs will be deactivated if they are inactive for 90 days, unless Integrator submits an Integrator Application to the Okta Integration Network." The old window was 180 days.

  • A revocable license. Your right to use the plan is now described as "revocable."

  • Wider data rights. Okta's license to use Integrator Data now covers what is needed "to provide Okta's products or services," not only this agreement, and is no longer tied to the term.

  • Data folded into usage data. Okta's usage data, which Okta owns, now expressly includes "the Integrator Data."

  • A one-sided cap. The $100 liability cap now covers only Okta, and the old exceptions for confidentiality and privacy or data processing breaches were removed.

  • Changes by posting. Amendments used to require a signed writing from both parties. Now Okta "may amend this Agreement from time to time, and will be effective upon posting on its website."

Who runs into the 90-day clock

Many SaaS companies build an Okta integration so their customers can sign in with Okta or sync users automatically. The work usually happens in an Integrator Free Plan org: a test environment that gets busy during a release and then sits untouched until the next one.

Under the old terms, that test org could sit idle for six months. Now it can be deactivated after three, unless the company has submitted its app to the Okta Integration Network. A deactivated org means losing access to the test configurations, test users, and app settings inside it, right when someone needs them for the next fix.

Your data gets a wider license

The old agreement let Okta use Integrator Data as needed to perform this agreement, for its term. The new one lets Okta use it "as reasonably necessary for Okta to perform its rights and obligations under this Agreement, or to provide Okta's products or services," with no link to the term. Integrator Data is also now listed as part of the usage data that Okta owns.

There are limits. If Okta gives this data to third parties, it must be anonymized and aggregated so it cannot be linked to you or your users, and usage data has to be de-identified or aggregated before it is disclosed. Okta's confidentiality obligations still apply, and its Data Processing Addendum still governs personal data.

The liability cap now protects one side

The old cap limited both parties to $100, with exceptions for breaches of confidentiality and of privacy or data processing obligations. The new cap limits only Okta's liability to $100, and those exceptions are gone. In practice, a data problem on the free plan now falls under the same $100 limit on Okta's side, while your own liability is no longer capped by this clause.

What did not change

The plan is still free, within the org features and limits Okta publishes. Okta still has to give 30 days' written notice to terminate for convenience. Marketing emails still come with an opt-out, although consent now starts at registration. And the Okta Integration Network exception gives companies with a submitted app a way out of the 90-day rule.

Why this matters

Free developer plans are easy to forget in a vendor review because nobody pays for them. But they often hold real configurations, test users, and sometimes real customer data copied in to reproduce a bug. When the terms for those plans change, the risk lands on the engineering team that relies on them, not on procurement.

Developer platforms have been tightening their terms in several ways, as we saw when DigitalOcean made spend commitments non-cancelable and Stripe shifted liability to users. Keeping free plans in scope is part of continuous vendor contract monitoring.

Potential impact

For a SaaS company that builds on Okta, the update raises four practical questions:

  • Does your team have Integrator Free Plan orgs for testing an Okta integration, and when was each one last used?

  • Have you submitted your app to the Okta Integration Network, which exempts the org from the 90-day rule?

  • Is any real customer or employee data sitting in a free test org?

  • Who would notice if Okta changed these terms again, now that a change takes effect when it is posted?

Questions like the last one are why monitoring vendor terms of service matters for free plans as much as paid ones.

How Venpo detected it

Venpo monitors Okta's developer and legal pages as part of continuous vendor risk monitoring. On September 2, it flagged the rewrite of the Integrator Free Plan agreement and separated the substantive changes from a large number of wording and formatting edits. The full redline is on the Okta change page, and every monitored Okta document is listed on the Okta vendor profile.

Business outcome

Teams that track Okta got a plain-English list of the changes, starting with the shorter idle window. That leaves time to log in to idle test orgs, clear out real data, and decide whether to submit the app to the Okta Integration Network. The alternative is finding a deactivated test org the week a customer needs an SSO fix.

Key takeaway

Okta cut the idle window on its free developer plan from 180 days to 90, and in the same rewrite widened its data rights, made the liability cap protect only itself, and gave itself the right to change the terms by posting them. Free plans change as often as paid ones, which is why automated monitoring should cover both.

The change

Okta's Integrator Free Plan is the free environment developers use to build and test integrations with Okta, such as single sign-on or user provisioning for their own product. On September 2, 2026, Venpo detected a rewrite of the plan's subscription agreement.

The headline change is a number: idle orgs are now deactivated after 90 days instead of 180. The same rewrite also widens Okta's rights over the data you put into the plan, makes the liability cap one-sided, and lets Okta change the terms by posting them. The redline is on the public change page.

What changed

  • 90 days instead of 180. "Integrator orgs will be deactivated if they are inactive for 90 days, unless Integrator submits an Integrator Application to the Okta Integration Network." The old window was 180 days.

  • A revocable license. Your right to use the plan is now described as "revocable."

  • Wider data rights. Okta's license to use Integrator Data now covers what is needed "to provide Okta's products or services," not only this agreement, and is no longer tied to the term.

  • Data folded into usage data. Okta's usage data, which Okta owns, now expressly includes "the Integrator Data."

  • A one-sided cap. The $100 liability cap now covers only Okta, and the old exceptions for confidentiality and privacy or data processing breaches were removed.

  • Changes by posting. Amendments used to require a signed writing from both parties. Now Okta "may amend this Agreement from time to time, and will be effective upon posting on its website."

Who runs into the 90-day clock

Many SaaS companies build an Okta integration so their customers can sign in with Okta or sync users automatically. The work usually happens in an Integrator Free Plan org: a test environment that gets busy during a release and then sits untouched until the next one.

Under the old terms, that test org could sit idle for six months. Now it can be deactivated after three, unless the company has submitted its app to the Okta Integration Network. A deactivated org means losing access to the test configurations, test users, and app settings inside it, right when someone needs them for the next fix.

Your data gets a wider license

The old agreement let Okta use Integrator Data as needed to perform this agreement, for its term. The new one lets Okta use it "as reasonably necessary for Okta to perform its rights and obligations under this Agreement, or to provide Okta's products or services," with no link to the term. Integrator Data is also now listed as part of the usage data that Okta owns.

There are limits. If Okta gives this data to third parties, it must be anonymized and aggregated so it cannot be linked to you or your users, and usage data has to be de-identified or aggregated before it is disclosed. Okta's confidentiality obligations still apply, and its Data Processing Addendum still governs personal data.

The liability cap now protects one side

The old cap limited both parties to $100, with exceptions for breaches of confidentiality and of privacy or data processing obligations. The new cap limits only Okta's liability to $100, and those exceptions are gone. In practice, a data problem on the free plan now falls under the same $100 limit on Okta's side, while your own liability is no longer capped by this clause.

What did not change

The plan is still free, within the org features and limits Okta publishes. Okta still has to give 30 days' written notice to terminate for convenience. Marketing emails still come with an opt-out, although consent now starts at registration. And the Okta Integration Network exception gives companies with a submitted app a way out of the 90-day rule.

Why this matters

Free developer plans are easy to forget in a vendor review because nobody pays for them. But they often hold real configurations, test users, and sometimes real customer data copied in to reproduce a bug. When the terms for those plans change, the risk lands on the engineering team that relies on them, not on procurement.

Developer platforms have been tightening their terms in several ways, as we saw when DigitalOcean made spend commitments non-cancelable and Stripe shifted liability to users. Keeping free plans in scope is part of continuous vendor contract monitoring.

Potential impact

For a SaaS company that builds on Okta, the update raises four practical questions:

  • Does your team have Integrator Free Plan orgs for testing an Okta integration, and when was each one last used?

  • Have you submitted your app to the Okta Integration Network, which exempts the org from the 90-day rule?

  • Is any real customer or employee data sitting in a free test org?

  • Who would notice if Okta changed these terms again, now that a change takes effect when it is posted?

Questions like the last one are why monitoring vendor terms of service matters for free plans as much as paid ones.

How Venpo detected it

Venpo monitors Okta's developer and legal pages as part of continuous vendor risk monitoring. On September 2, it flagged the rewrite of the Integrator Free Plan agreement and separated the substantive changes from a large number of wording and formatting edits. The full redline is on the Okta change page, and every monitored Okta document is listed on the Okta vendor profile.

Business outcome

Teams that track Okta got a plain-English list of the changes, starting with the shorter idle window. That leaves time to log in to idle test orgs, clear out real data, and decide whether to submit the app to the Okta Integration Network. The alternative is finding a deactivated test org the week a customer needs an SSO fix.

Key takeaway

Okta cut the idle window on its free developer plan from 180 days to 90, and in the same rewrite widened its data rights, made the liability cap protect only itself, and gave itself the right to change the terms by posting them. Free plans change as often as paid ones, which is why automated monitoring should cover both.

Real-time change notifications

Stay ahead of every legal change

Get updates, product news and expert tips on navigating legal changes

Stripe updated Terms of Service

Dispute resolution clause now requires mandatory arbitration in all regions

High Impact2 hours ago
AWS modified Privacy Policy

Data retention period extended from 2 years to 5 years for all services

Medium Impact5 hours ago
Shopify revised Acceptable Use Policy

New restrictions on AI-generated content in product descriptions

Review1 day ago
Slack changed Data Processing Agreement

Third-party data sharing expanded to include analytics partners

High Impact1 day ago

Real-time change notifications

Stay ahead of every legal change

Get updates, product news and expert tips on navigating legal changes

Stripe updated Terms of Service

Dispute resolution clause now requires mandatory arbitration in all regions

High Impact2 hours ago
AWS modified Privacy Policy

Data retention period extended from 2 years to 5 years for all services

Medium Impact5 hours ago
Shopify revised Acceptable Use Policy

New restrictions on AI-generated content in product descriptions

Review1 day ago
Slack changed Data Processing Agreement

Third-party data sharing expanded to include analytics partners

High Impact1 day ago