SAN FRANCISCO, August 24, 2026 — Okta, Inc. (NASDAQ: OKTA), the leading independent identity partner, today announced the general availability of Agent SSO, bringing the open Cross App Access standard into the identity product used by more than 20,000 customers. Agent SSO establishes a first-class identity model for AI agents at the point of connection and is included in core Okta SSO plans at no additional cost. It’s an easy first step to securing your agents, but scaling to Okta for AI Agents is critical. Okta for AI Agents discovers, onboards, protects, and governs every agent across the enterprise, including support for non-Cross App Access agents.
The Agent Identity Gap
Enterprises are deploying AI agents faster than they can govern them. Only 34% of organizations apply the same security controls to AI agents as they do to human workers, according to Okta's AI Agents at Work 2026 report.
Most agents reach enterprise data through static API keys, one-off OAuth grants, and custom integrations built application by application. They operate as anonymous traffic with no owner, no policy, and no audit trail. The problem compounds as agents multiply across teams, because organizations must account for three populations at once: agents they built themselves, agents embedded in the software they buy, and agents employees deploy without central approval.
How Agent SSO Works
Agent SSO applies to AI agents that support Cross App Access. When such an agent connects to an enterprise application, Okta registers it as a first-class identity in Universal Directory alongside human employees, then issues short-lived, identity-governed tokens in place of stored credentials.
Administrators assign, monitor, and update agent policy through the same console and the same workflows they use for employees. For example, if an organization deploys Anthropic's Claude, security teams govern its access natively. Employees no longer share static credentials or approve repeated consent prompts.
Just as Single Sign-On centralized human access decisions at the identity provider, Agent SSO moves agent authorization from individual applications to the enterprise identity provider.
"Okta is an undisputed leader in SSO, and now we're bringing SSO for your AI agents," said Ric Smith, President of Products and Technology at Okta. "AI agents are fast becoming a primary interface for how work gets done, but granting them access to enterprise systems shouldn't require trading away security or visibility. With Agent SSO, we are helping to establish a fundamental security standard for the agentic enterprise. By treating every connected agent as a first-class identity and bundling this capability directly into our core SSO offering, Okta is making it effortless for enterprises to secure AI workflows from day one."
Seamlessly scale from Agent SSO to Okta for AI Agents
Agent SSO answers one question: how do Cross App Access agents connect to enterprise applications and MCP servers?
Okta for AI Agents answers the rest: where are all the agents, what can any of them connect to, and what are they allowed to do?
Generally available since May 2026, it discovers unregistered and shadow AI agents, then assigns them named human owners. It connects agents to resources Cross App Access does not reach, including custom authorization servers, service accounts, secrets, and other agents. And it governs what every agent can do through access certifications, approval workflows, and agent deactivation.
Agent SSO | Okta for AI Agents | |
|---|---|---|
Agents that speak Cross App Access | Every agent, regardless of where it was built | |
Where are my agents? | Registers Cross App Access agents in Universal Directory | Registers all agents, including finding shadow AI agents through browser, endpoint, and network detection |
What can they connect to? | Identity-governed tokens for agent-to-app connections through Cross App Access | Extends to non-Cross App Access supported agents, and includes agent-to-agent connections and runtime enforcement |
What can they do? | N/A | End-to-end governance with certification reviews, advanced authorization, kill switch |
Agent SSO is the first step, because every agent it touches is already a first-class identity. Upgrading to Okta for AI Agents doesn’t require you to re-register the agents. It brings all agents under the same model and applies full governance controls to them.
Industry Adoption of Cross App Access
Organizations can deploy Cross App Access integrations through the Okta Integration Network, a prebuilt ecosystem that removes the need for custom integration work. The network provides out-of-the-box support for Anthropic (Claude), Archestra.AI, Asana, Atlassian, Canva, Datadog, Figma, Glean, Granola, Linear, MintMCP, Notion, Slack, and Supabase.
Availability
Agent SSO is generally available today and included in core Okta SSO at no additional cost. Okta for AI Agents is available as a separate subscription. Additional information is available here.
About Cross App Access
Cross App Access is an open, vendor-neutral protocol that allows identity security to follow agents dynamically across applications. Okta initially led its design, and it has been adopted across the industry by AI platforms, SaaS providers, and identity vendors. Cross App Access extends OAuth and is formally incorporated as the official Enterprise-Managed Authorization extension for the Model Context Protocol.
The protocol is not limited to AI agents. It supports any case where one application acts on behalf of a user, such as syncing meeting notes from Zoom into Asana.
About Okta for AI Agents
Okta for AI Agents gives AI agents a first-class identity so organizations can discover, onboard, protect, and govern them across any agent framework, cloud, or SaaS environment. It supports agents built in-house, agents embedded in purchased software, and agents deployed without central approval, and it governs the full agent lifecycle including access certification, approval workflows, and agent deactivation.