> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blinq.me/llms.txt
> Use this file to discover all available pages before exploring further.

# Troubleshooting Okta provisioning

> Connection failures, values that don't reach the card, and users who stay active after being unassigned.

Because Blinq support sets up the Okta side with you, they'll work through most of these with you directly. These are the checks that resolve the majority of cases.

| Symptom                                                 | Cause and fix                                                                                                                                                                                                                                 |
| ------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Test Connector Configuration fails                      | The base URL or token doesn't match. Confirm **Authentication Mode** is **HTTP Header** and that the token follows the `Bearer` prefix in the Authorization field. If it still fails, generate a new token in Blinq and re-enter both values. |
| Provisioning stopped working after a staff change       | The token belongs to the admin who created it. If that admin was deactivated or lost the admin role, a current workspace admin needs to generate a new token and re-enter it in Okta.                                                         |
| Provisioned cards have no template                      | No default template is set for provisioning. Attach one under **Team Card Provisioning** card settings. A template chosen during a bulk CSV invite doesn't carry over to users Okta provisions afterwards.                                    |
| A phone number is wrong, or shows an internal extension | Blinq shows whatever your directory holds in that field, including four-digit internal extensions. Check the value on the user's Okta profile, and map only one phone attribute so two values don't compete.                                  |
| A field ignores directory updates                       | The field is showing a value entered in Blinq, so it's no longer linked to your directory. See [How provisioning works](/identity/how-provisioning-works) for how fields become unlinked and what to check.                                   |
| A user unassigned in Okta is still active in Blinq      | Check that the deactivation provisioning actions are enabled on the Blinq app in Okta. Okta only sends the deactivation if those actions are switched on.                                                                                     |
| Provisioned cards have no profile photo                 | Photos aren't part of the directory feed. The card owner or a workspace admin adds them in Blinq.                                                                                                                                             |

## What to send support

If none of these explain it, email [support@blinq.me](mailto:support@blinq.me) with the user's email address, the field involved, and roughly when the change was made in Okta. That's enough to trace the request on the Blinq side.

<hr />

### Need help?

For any questions or issues, [contact Blinq support](https://support.blinq.me/en/) or email [support@blinq.me](mailto:support@blinq.me).
