Okta brings first-class identity to AI agents with Agent SSO

Powered by the Cross App Access protocol, Agent SSO reduces static API keys and consent fatigue by extending enterprise identity policy directly to AI agent connections

Acerca de Okta

Okta

Okta, Inc. is The World’s Identity Company™. We secure AI, machine, and human identity so everyone is free to safely use any technology. Our customer and workforce solutions empower businesses and developers to protect their AI agents, users, employees, and partners while driving security, efficiencies, and innovation. Learn why the world’s leading brands trust Okta for authentication, authorization, and more at okta.com.

24 agosto 2026 Tiempo de lectura: ~

August 24, 2026 – Today, Okta, Inc. announced the General Availability of Agent SSO, bringing the open Cross App Access (XAA) standard directly into the identity product used by over 20,000 customers. To help ensure the agentic enterprise is secure by default, Agent SSO enables organizations to model AI agents as first-class identities governed by centralized policies. By managing agents alongside human identities, security teams can easily enforce granular guardrails while reducing risky static API keys, unmanaged connections, and repetitive user consent prompts.

Why it matters

Despite the rapid adoption of AI agents across enterprise workflows, only 34% of organizations apply the same identity and security controls to their agentic labor force as they do to their human employees. That’s because, historically, connecting these AI agents to enterprise applications has required fragmented, point-to-point approaches that leave them operating as anonymous network traffic without centralized visibility, administrative oversight, or lifecycle audit trails.

Agent SSO helps solve this challenge by leveraging Cross App Access (XAA) – a standard that lets ISVs enable secure agent-to-app and app-to-app access, which was initially led by Okta and adopted across the industry by leading AI platforms, SaaS providers, and identity partners. Just as Single Sign-On (SSO) centralized human access decisions at the identity provider layer, Agent SSO shifts agent authorization from individual applications directly to the enterprise identity provider.

How it works

When an XAA-supported AI agent connects to an enterprise application, Agent SSO enables it to be registered as a first-class identity in Okta’s Universal Directory, visible alongside human employees. For example, if an organization deploys Anthropic’s Claude, security administrators can govern its access natively—assigning, monitoring, and updating security policies just as they would for any human worker. This centralized control allows teams to secure their agentic workforce just as they would their human workforce, without forcing employees to share static, risky credentials or navigate constant consent screens.

"Okta is an undisputed leader in SSO, and now we’re bringing SSO for your AI agents," said Ric Smith, President of Products and Technology at Okta. "AI agents are fast becoming a primary interface for how work gets done, but granting them access to enterprise systems shouldn't require trading away security or visibility. With Agent SSO, we are helping to establish a fundamental security standard for the agentic enterprise. By treating every connected agent as a first-class identity and bundling this capability directly into our core SSO offering, Okta is making it effortless for enterprises to secure AI workflows from day one."

Anchoring the industry blueprint for the secure agentic enterprise

The blueprint for the secure agentic enterprise is a shared architecture for giving agents the access they need, with the necessary controls around them. It focuses on three non-negotiable governance questions: Where are my agents, what can they connect to, and what can they do?

Agent SSO serves as a foundational security layer of the blueprint, that answers the first two questions:

  • Where are my agents? By registering each XAA-supported agent as a first class identity in Universal Directory, Agent SSO centralizes visibility across all platforms.

  • What can they connect to? Powered by the Cross App Access protocol, Agent SSO replaces hardcoded credentials and broad OAuth authorizations with identity-governed, short-lived tokens, verifying that agents can connect only to sanctioned applications, APIs, tools, and Model Context Protocol (MCP) servers under strict least-privilege policies.

Where are my agents? What can the connect to? What can they do?

While Agent SSO establishes the essential identity foundation for known agents, securing the agentic enterprise requires continuous, end-to-end oversight. To answer the third crucial question—What can they do?—Okta for AI Agents provides organizations with better visibility to discover unmanaged agents, govern their entire lifecycle, and enforce precise runtime controls. 

About Cross App Access

Built as an extension of OAuth and formally incorporated as the official Enterprise-Managed Authorization extension for MCP, XAA is an open, vendor-neutral protocol, initially led by Okta, that reduces enterprise blind spots by allowing identity security to follow agents dynamically across applications. 

Implementing XAA is a core part of the blueprint for the secure agentic enterprise—a broader industry framework built on knowing exactly where agents are, what they can connect to, and what they are authorized to do. 

To deliver instant value, organizations can access Cross App Access integrations on the Okta Integration Network (OIN), a prebuilt ecosystem that reduces the need to build custom integrations. The OIN provides out-of-the-box support for leading AI agents, SaaS apps, and platforms, including Anthropic (Claude), Archestra.AI, Asana, Atlassian, Canva, Datadog, Figma, Glean, Granola, Linear, MintMCP, Notion, Serval, Slack, and Supabase. 

For more information on securing AI agents with Okta, visit here.

Acerca de Okta

Okta

Okta, Inc. is The World’s Identity Company™. We secure AI, machine, and human identity so everyone is free to safely use any technology. Our customer and workforce solutions empower businesses and developers to protect their AI agents, users, employees, and partners while driving security, efficiencies, and innovation. Learn why the world’s leading brands trust Okta for authentication, authorization, and more at okta.com.

Get our Identity newsletter