Okta administration that fits in your pocket.
Suspend a compromised user, clear their sessions, toggle a network zone, biometric-confirmed, audit-logged, from your phone. The action set is gated by the Okta scopes your integration was granted.
Connects through the Butterfly Security API Service Integration on the Okta Integration Network, using the scopes you grant it.
Universal binary · iPhone & iPad · iOS/iPadOS 17.0+ · Free download, works with the 30-day trial · Biometric-confirmed mutations only.
Live screen from Butterfly Security on iPhone.
Captured in the app's built-in Demo Mode with sample data. Voiceover and captions included, under two and a half minutes.
Watch the whole app, start to finish
Okta doesn't ship an admin app for iPhone, so this is the first one. The tour runs from sign-in through a containment action to the executive brief, and it shows both gates refusing work as well as allowing it.
Free download. iPhone and iPad on iOS 17.0 or later. Works with the 30-day trial.
What you can do from your phone
The action set is the result of a lot of customer interviews. Basically, "what do you actually do from your phone when something goes wrong at 2am?"
Incident response
- Suspend / unsuspend / deactivate users
- Clear all active sessions
- Toggle network zones for containment
Helpdesk
- Send password reset emails
- Expire passwords (force re-set)
- Unlock locked-out accounts
Membership
- Add or remove a group member
- Assign or unassign a user to an app
- Browse users, groups, apps, system log
Disaster recovery
- Resilience score with factor breakdown
- Executive brief for leadership handoffs
- Drift detection (last 7 days)
- One-tap backup, restore preview
Excluded by design
Mobile UX shouldn't make catastrophic mistakes easier. Three things that stay desktop-only:
Full org restore
Can touch thousands of resources. The companion gives you a read-only restore preview; execution stays desktop so you can review the dry-run diff first.
Create / delete user, group, app
Not enough screen real estate to review the implications of structural changes. Browse on phone, edit on desktop.
Policy edits
A wrong sign-on policy edit can take down your SSO for the entire org. That deserves the desktop UX, the diff view, and the ability to revert quickly.
Architecture and constraints
Capability-gated against your real Okta grants
After you pick a connection, the app asks Okta which scopes are actually live. Buttons you can't use stay visible with a lock icon and the scope name. No bait-and-switch, no silent failures.
Biometric on every mutation
Even with a valid session, every action requires Face ID or Touch ID. Sessions get hijacked; device biometric is fresh consent. This is the bar 1Password and Stripe Card set.
Friction proportional to blast radius
Suspend → confirm → Face ID. Deactivate → type-the-user's-email → Face ID. Full org restore → not on the phone at all. Mobile UX shouldn't make catastrophic mistakes easier.
Audit-logged server-side
Every action (read or write) lands in your activity log with the actor, the target, the Okta status code, and the result. Same audit surface as the web app.
Executive-ready evidence
The companion turns recovery score, backup currency, critical drift, and control design into a shareable brief for CIO, CTO, and audit conversations.
FAQ
Where do I get it?
It is live on the App Store now, a universal binary for iPhone and iPad running iOS or iPadOS 17.0 or later. No signup list, no TestFlight gate.
What does it cost?
Included with any Butterfly account, including the 30-day free trial, same as the web app.
How does it sign in?
Same email-code flow as butterflysecurity.org. Your existing Okta connections, scope grants, and audit log carry through.
Why isn't full restore on the phone?
Full org restores can touch thousands of resources. We're deliberately keeping that flow desktop-only so you can review the dry-run diff before executing. The companion gives you a read-only restore preview.
What about destructive actions?
Deactivate requires typing the user's email exactly to confirm, then Face ID. Delete user, delete group, and delete app are intentionally out of scope for the phone. Those stay desktop-only.
Does it work for read-only Okta integrations?
Yes. The action set scales to whatever your Okta integration was granted. Read-only customers get the browse, search, and dashboard surfaces; the mutation buttons stay visibly locked with the missing scope's name.
Does this replace mobile.okta.com?
No. mobile.okta.com is for end users signing in to apps. Butterfly Security is for administrators taking action on the org.
Ready when the next incident is.
Free download, works with the 30-day trial. Available now on the App Store.
Download on the App Store