Start with Identity
← Blog
News

Okta ships Agent SSO, making AI agents first-class identities instead of static API keys

Okta made Agent SSO generally available on August 24, 2026, registering AI agents in Universal Directory with short-lived governed tokens and pushing Cross App Access into the Model Context Protocol as its enterprise authorization extension.

By SWI Community TeamAug 24, 2026Updated Aug 29, 2026

Okta made Agent SSO generally available on August 24, 2026 and included it in core Okta SSO at no extra cost. Agent SSO registers an AI agent as a first-class identity in Universal Directory and issues short-lived, governed tokens in place of the static API keys agents normally carry. Admins assign and revoke agent access through the same workflows they use for employees. Underneath sits Cross App Access, the vendor-neutral OAuth extension Okta designed and has now had adopted as the official Enterprise-Managed Authorization extension for the Model Context Protocol. Launch integrations cover Anthropic, Asana, Atlassian, Datadog, Figma, Glean, Linear, Notion, Slack, and Supabase.

Why it matters

The hard part of agent access was never authentication, it was that an agent's credential is usually a long-lived API key sitting in a config file with no owner, no expiry, and no revocation story. Moving that to short-lived tokens issued by the identity provider is the same move that killed per-app passwords for humans. Cross App Access landing inside the MCP authorization spec matters more than the product: it means the delegation pattern is standardized rather than Okta-specific. Okta's own figure, that only 34 percent of organizations apply human-grade controls to agents, is the gap. If you are building agent access today, read our agentic identity primer and treat every agent as a non-human identity that needs an owner and a lifecycle.

Source: Okta

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Independent analysis. No vendor sponsorship.