<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Introduces Agent SSO for Cross App Access (XAA)

Okta Identity Engine
API Access Management

Overview

Okta introduces Agent SSO: Agent-to-App Connections, enabling secure connections between artificial intelligence agents and applications. This functionality allows administrators to register an agent as a workload principal and connect it to an XAA-enabled Okta Integration Network (OIN) application, or a custom XAA-enabled Security Assertion Markup Language (SAML) or OpenID Connect (OIDC) application. The Okta Admin Console now includes an AI Agents option under the Directory menu to manage these integrations.

 

NOTE: Agent SSO is Generally Available and included in core workforce SSO plans.

 

Applies To

  • Okta Identity Engine (OIE)
  • Single Sign-On (SSO)
  • Agent SSO
  • Cross App Access (XAA)
  • Workforce SSO SKU
  • AI Agents

Solution

What features does Agent SSO provide?

Agent SSO enables secure connections between artificial intelligence agents and applications. This functionality allows administrators to register an agent as a workload principal. After registration, administrators connect the agent to an XAA-enabled Okta Integration Network (OIN) application, or a custom XAA-enabled Security Assertion Markup Language (SAML) or OpenID Connect (OIDC) application.

 

How does it work?

When an XAA-supported AI agent connects to an enterprise application, Agent SSO enables it to be registered as a first-class identity in Okta’s Universal Directory, visible alongside human employees. For example, if an organization deploys Anthropic’s Claude, security administrators can govern its access natively—assigning, monitoring, and updating security policies just as they would for any human worker. This centralized control allows teams to secure their agentic workforce just as they would their human workforce, without forcing employees to share static, risky credentials or navigate constant consent screens.

 

When is Okta for AI Agents or Okta Identity Governance required?

Determine the appropriate Okta product for advanced agent management by reviewing the following use cases.

  • Okta requires Okta for AI Agents (O4AA) to establish agent-to-agent connections and manage the governance and lifecycle of the agents.
  • Administrators must use either O4AA or Okta Identity Governance (OIG) to assign a human owner to an agent.

 

How are AI Agents managed in the Okta Admin Console?

Okta provides a dedicated interface for agent management in the Okta Admin Console. Administrators access this feature by navigating to the Directory menu and selecting AI Agents. This view will be there for all customers and does not require the Okta for AI Agents SKU.

AI Agents

 

Related References

Loading
Okta Introduces Agent SSO for Cross App Access (XAA) | Okta Support