Okta brings first-class identity to AI agents with Agent SSO

Agent SSO makes the open Cross App Access standard part of core Okta SSO, giving every Okta customer a first-class identity model for AI agents. Okta for AI Agents extends discovery, lifecycle management, and governance to every agent in the enterprise.

About Okta

Okta

Okta, Inc. is The World’s Identity Company™. We secure AI, machine, and human identity so everyone is free to safely use any technology. Our customer and workforce solutions empower businesses and developers to protect their AI agents, users, employees, and partners while driving security, efficiencies, and innovation. Learn why the world’s leading brands trust Okta for authentication, authorization, and more at okta.com.

24 August 2026 Time to read: ~

SAN FRANCISCO, August 24, 2026 — Okta, Inc. (NASDAQ: OKTA), the leading independent identity partner, today announced the general availability of Agent SSO, bringing the open Cross App Access standard into the identity product used by more than 20,000 customers. Agent SSO establishes a first-class identity model for AI agents at the point of connection and is included in core Okta SSO plans at no additional cost. It’s an easy first step to securing your agents, but scaling to Okta for AI Agents is critical. Okta for AI Agents discovers, onboards, protects, and governs every agent across the enterprise, including support for non-Cross App Access agents.

The Agent Identity Gap

Enterprises are deploying AI agents faster than they can govern them. Only 34% of organizations apply the same security controls to AI agents as they do to human workers, according to Okta's AI Agents at Work 2026 report.

Most agents reach enterprise data through static API keys, one-off OAuth grants, and custom integrations built application by application. They operate as anonymous traffic with no owner, no policy, and no audit trail. The problem compounds as agents multiply across teams, because organizations must account for three populations at once: agents they built themselves, agents embedded in the software they buy, and agents employees deploy without central approval.

How Agent SSO Works

Agent SSO applies to AI agents that support Cross App Access. When such an agent connects to an enterprise application, Okta registers it as a first-class identity in Universal Directory alongside human employees, then issues short-lived, identity-governed tokens in place of stored credentials.

Administrators assign, monitor, and update agent policy through the same console and the same workflows they use for employees. For example, if an organization deploys Anthropic's Claude, security teams govern its access natively. Employees no longer share static credentials or approve repeated consent prompts.

Just as Single Sign-On centralized human access decisions at the identity provider, Agent SSO moves agent authorization from individual applications to the enterprise identity provider.

"Okta is an undisputed leader in SSO, and now we're bringing SSO for your AI agents," said Ric Smith, President of Products and Technology at Okta. "AI agents are fast becoming a primary interface for how work gets done, but granting them access to enterprise systems shouldn't require trading away security or visibility. With Agent SSO, we are helping to establish a fundamental security standard for the agentic enterprise. By treating every connected agent as a first-class identity and bundling this capability directly into our core SSO offering, Okta is making it effortless for enterprises to secure AI workflows from day one."

Seamlessly scale from Agent SSO to Okta for AI Agents 

Agent SSO answers one question: how do Cross App Access agents connect to enterprise applications and MCP servers?

Okta for AI Agents answers the rest: where are all the agents, what can any of them connect to, and what are they allowed to do?

Generally available since May 2026, it discovers unregistered and shadow AI agents, then assigns them named human owners. It connects agents to resources Cross App Access does not reach, including custom authorization servers, service accounts, secrets, and other agents. And it governs what every agent can do through access certifications, approval workflows, and agent deactivation.

Where are my agents? What can the connect to? What can they do?
 

Agent SSO

Okta for AI Agents

 

Agents that speak Cross App Access

Every agent, regardless of where it was built

Where are my agents?

Registers Cross App Access agents in Universal Directory

Registers all agents, including finding shadow AI agents through browser, endpoint, and network detection

What can they connect to?

Identity-governed tokens for agent-to-app connections through Cross App Access

Extends to non-Cross App Access supported agents, and includes agent-to-agent connections and runtime enforcement 

What can they do?

N/A

End-to-end governance with certification reviews, advanced authorization, kill switch

 

Agent SSO is the first step, because every agent it touches is already a first-class identity. Upgrading to Okta for AI Agents doesn’t require you to re-register the agents. It brings all agents under the same model and applies full governance controls to them.

Industry Adoption of Cross App Access

Organizations can deploy Cross App Access integrations through the Okta Integration Network, a prebuilt ecosystem that removes the need for custom integration work. The network provides out-of-the-box support for Anthropic (Claude), Archestra.AI, Asana, Atlassian, Canva, Datadog, Figma, Glean, Granola, Linear, MintMCP, Notion, Slack, and Supabase.

Availability

Agent SSO is generally available today and included in core Okta SSO at no additional cost. Okta for AI Agents is available as a separate subscription. Additional information is available here.

About Cross App Access

Cross App Access is an open, vendor-neutral protocol that allows identity security to follow agents dynamically across applications. Okta initially led its design, and it has been adopted across the industry by AI platforms, SaaS providers, and identity vendors. Cross App Access extends OAuth and is formally incorporated as the official Enterprise-Managed Authorization extension for the Model Context Protocol.

The protocol is not limited to AI agents. It supports any case where one application acts on behalf of a user, such as syncing meeting notes from Zoom into Asana.

About Okta for AI Agents

Okta for AI Agents gives AI agents a first-class identity so organizations can discover, onboard, protect, and govern them across any agent framework, cloud, or SaaS environment. It supports agents built in-house, agents embedded in purchased software, and agents deployed without central approval, and it governs the full agent lifecycle including access certification, approval workflows, and agent deactivation.

About Okta

Okta

Okta, Inc. is The World’s Identity Company™. We secure AI, machine, and human identity so everyone is free to safely use any technology. Our customer and workforce solutions empower businesses and developers to protect their AI agents, users, employees, and partners while driving security, efficiencies, and innovation. Learn why the world’s leading brands trust Okta for authentication, authorization, and more at okta.com.

Get our Identity newsletter