Organizations choose Okta to make identity the control point: one dashboard, one lifecycle, one place where onboarding grants everything and offboarding removes everything. That promise holds for hundreds of applications.
Physical keys break it. They are handed out at a desk, registered in a separate key management tool or a spreadsheet, and returned whenever someone remembers. So while Okta deactivation strips a leaver of every application in seconds, their key keeps working:
Under NIS2 and the CER Directive, critical entities are expected to govern access to premises with the same discipline as access to systems. The gap between Okta and your keys is precisely where that expectation bites.
Key2XS is middleware that makes physical access one more thing Okta assigns. It reads users, groups and lifecycle states from Okta and orchestrates the matching key rights in iLOQ.
| From Okta | To iLOQ via Key2XS |
|---|---|
| Users (joiners, movers, leavers) | Key holders created, updated or deactivated |
| Group memberships | Key rights and access to lock groups |
| Deactivation and suspension | Immediate withdrawal of key rights |
| Assignment history | Documented authorization behind every key |
Changes flow through in near real-time, so deactivating a user in Okta does not wait for a nightly batch to reach your keys.
Key2XS is used where physical access affects public safety, service continuity or regulatory compliance: utilities, government, transport, healthcare and industry.
Okta has excellent APIs and automation hooks, and iLOQ has an API too. But a homegrown bridge means owning connector code against two evolving platforms, building your own audit layer, covering every lifecycle edge case, and maintaining it for years while it quietly becomes critical infrastructure. Key2XS delivers this as a maintained platform: