What is Cross App Access?

Cross App Access (XAA) is an open identity protocol that centralizes authorization in the identity provider. By leveraging the IETF's ID-JAG and extending to MCP servers, XAA eliminates static credentials and consent fatigue while enabling full auditability across agentic AI workflows.

Deploying AI agents is easy. Granting them access to enterprise systems without creating security blind spots is not. As AI moves from simple chat interfaces to autonomous workflows, enterprises are hitting a wall: Legacy access models force a losing choice between lockdown security and employee productivity.

Without an identity-first approach, scaling AI creates unmanaged risk and operational friction. Relying on legacy patterns like static API keys and broad service accounts strips away user context and creates overprivileged access. At the same time, endless consent prompts fatigue employees and leave IT without centralized visibility or control over these connections.

Securing agentic workflows requires a fundamental shift in how access is granted. As an open industry protocol, Cross App Access (XAA) centralizes authorization in the identity provider (IdP), eliminating static credentials and consent prompts altogether. Okta brings this standard to its platform through Agent SSO, which is included in core Workforce SSO plans. By modeling agentic connections as workload principals in Universal Directory, Okta allows enterprises to treat every connected agent as a first-class identity, attach clear access policies, and audit agent actions across their entire stack.

"Using Cross App Access integrations in Agent SSO, we eliminated the friction of dozens of separate OAuth flows for HubSpotters. From the first prompt, people have access to key context across an array of corporate applications—because an AI agent is only as capable as the context it can reach."
— Andrew Meinert, Director, System Operations, AI, HubSpot

XAA secures AI workflows through centralized control and zero friction

XAA is rapidly becoming the foundational standard for connecting AI to enterprise software because it addresses both security and usability at once. SaaS builders and enterprise customers are embracing XAA with rare urgency because it delivers key operational outcomes:

  • More visibility: Connects the user's identity to the requesting agent's identity, enabling complete audit logs of data flows between agents and resources.
  • Centralized control: Shifts access decisions from individual end users to the enterprise IdP, enforcing identity-based security policies instead of relying on static tokens.
  • Zero-friction user experience: Eliminates redundant consent screens and repetitive OAuth prompts that slow users down, letting employees work seamlessly without authorization fatigue.

Okta Agent SSO vs. legacy agent access

Access vectorLegacy API keys and OAuthOkta Agent SSO (XXA standard)
Credential managementStatic secrets prone to leakageDynamic, token-based identity assertions
Authorization governanceUnmanaged user-level consentsCentralized Universal Directory policies
Agent visibilityShadow AI risks and hidden connectionsFirst-class workload principle visibility

Technically, XAA achieves this by building on the IETF's Identity Assertion JWT Authorization Grant (ID-JAG) and extending to Model Context Protocol (MCP) servers through enterprise-managed authorization. These dual outcomes have fueled a thriving XAA ecosystem.

Today, we’re celebrating the rapid expansion of the XAA ecosystem, bringing pre-built, secure agent integrations to the market-leading tools driving modern business. By replacing static secrets and endless consent prompts with identity-based controls, XAA allows enterprises to connect agents to critical resources seamlessly.

"Adopting the Cross App Access protocol gives our customers an easy way to manage how third-party tools securely connect to Notion, all in one place. It delivers the kind of secure-by-default AI agent access enterprise IT teams actually want."
— David Rosenberg, Head of Ecosystem, Notion

Explore the expanding network of XAA integrations

Gradient banner featuring a grid of tech and software logos against a blue-to-purple background.

Rather than building custom integrations from scratch, enterprises can plug into a pre-built standard that instantly connects AI agents across their tech stack. Beyond the catalog of integrations already live in the Okta Integration Network, the newest additions include: 

XAA requesting app integrations (client AI agents) 

Capsule Security, Crogl, Glean (now with both requesting and resource integrations), MERGE, NanoCo.ai, Tungsten Dev

XAA resource app integrations (downstream applications and MCP servers) 

Atomicwork, Browserbase, Cerby, Crossbeam, Exa, Immuta, Lucid, Mate Security, Miro, Opal, World ID, Notion, Willow, Syndio, Zendesk, StitchOps

XAA supported identity infrastructure, gateways, and frameworks 

Aembit, LiteLLM (BerriAI), Gumloop, Truefoundry, Bloom, ClearVector, Kindo

Enable Cross App Access natively in Okta through Agent SSO

Okta brings Cross App Access into production natively through Agent SSO, which is included in Okta Workforce Identity SSO plans. Organizations model XAA-supported agents (like Claude) as workload principals in Universal Directory, treating every agent as a first-class identity. This enforces policy directly at the IdP layer, eliminating static credentials and employee consent fatigue while ensuring security teams get complete visibility and auditable records from day one.

While Agent SSO governs known agent connections, scaling to complete AI governance is seamless. Okta for AI Agents builds directly on top of Agent SSO, unlocking shadow agent discovery, agent-to-agent governance, kill-switch capabilities, and human-in-the-loop approvals without requiring you to re-register or rebuild existing agent connections.

Build a more secure agentic enterprise by enabling first-class identity for every XAA-enabled agent connection. Download our Agent SSO one-pager to learn how Okta Agent SSO brings the XAA open protocol into your identity platform and helps you secure your agent-to-app connections. 

Start connecting AI agents to your tech stack today. Explore the full directory of XAA integrations in the Okta Integration Network, or speak with your Okta account team to see how Agent SSO fits your architecture.

* Some integrations listed in this blog may not yet be available on the Okta Integration Network or elsewhere. Okta may decide when or whether to release any integration, product or service (and any accompanying features) in its sole and absolute discretion. These materials are intended for general informational purposes only and are not intended to be legal, privacy, security, compliance, or business advice. © Okta, Inc. and/or its affiliates.

About Okta

Okta

Okta, Inc. is The World’s Identity Company™. We secure AI, machine, and human identity so everyone is free to safely use any technology. Our customer and workforce solutions empower businesses and developers to protect their AI agents, users, employees, and partners while driving security, efficiencies, and innovation. Learn why the world’s leading brands trust Okta for authentication, authorization, and more at okta.com.

Continue your Identity journey