Okta ships Agent SSO, making AI agents first-class identities instead of static API keys
Okta made Agent SSO generally available on August 24, 2026, registering AI agents in Universal Directory with short-lived governed tokens and pushing Cross App Access into the Model Context Protocol as its enterprise authorization extension.
Okta made Agent SSO generally available on August 24, 2026 and included it in core Okta SSO at no extra cost. Agent SSO registers an AI agent as a first-class identity in Universal Directory and issues short-lived, governed tokens in place of the static API keys agents normally carry. Admins assign and revoke agent access through the same workflows they use for employees. Underneath sits Cross App Access, the vendor-neutral OAuth extension Okta designed and has now had adopted as the official Enterprise-Managed Authorization extension for the Model Context Protocol. Launch integrations cover Anthropic, Asana, Atlassian, Datadog, Figma, Glean, Linear, Notion, Slack, and Supabase.
Why it matters
The hard part of agent access was never authentication, it was that an agent's credential is usually a long-lived API key sitting in a config file with no owner, no expiry, and no revocation story. Moving that to short-lived tokens issued by the identity provider is the same move that killed per-app passwords for humans. Cross App Access landing inside the MCP authorization spec matters more than the product: it means the delegation pattern is standardized rather than Okta-specific. Okta's own figure, that only 34 percent of organizations apply human-grade controls to agents, is the gap. If you are building agent access today, read our agentic identity primer and treat every agent as a non-human identity that needs an owner and a lifecycle.
Source: Okta
Related on Start with Identity
- BlogGoogle and Mastercard's answer to "can I trust an AI agent to pay for this" is a cryptographic mandate
Google's Agent Payments Protocol and Mastercard's Verifiable Intent framework, both contributed to the FIDO Alliance for standardization, define how an AI agent
- BlogAkeyless ships Runtime Authority, authorising AI agents per action instead of per session
Agents hold no secrets and get no standing privilege. Every action is authorised at the moment it happens, and the audit trail links the originating prompt to t
- BlogC1 ships enterprise-managed authorization, putting SSO in front of MCP agents
The identity platform formerly called ConductorOne now issues short-lived scoped tokens for MCP servers under the open enterprise-managed authorization extensio
- ArticleIdentity-First Security Strategy: Making Identity the New Perimeter
How to build an identity-first security strategy that treats identity as the primary security perimeter, converging IAM and security operations into a unified a
- GuideSecuring AI Agent Identities: A Guide for Security Teams
AI agents are a new kind of non-human identity: autonomous, fast, and acting on a user's behalf. Traditional service accounts do not fit them. Here is what agen
- ArticleTop 8 Secrets Management Tools for Securing Credentials and API Keys in 2026
Compare the top 8 secrets management tools, HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager, CyberArk Conjur, Doppler, 1Password Secre