Okta Agent SSO is GA: short-lived tokens replace agents' API keys

The Cross App Access protocol it runs on is now MCP's enterprise auth layer, with Claude, Slack and Figma supported out of the box — free in core Okta SSO.

Nowline AUG 27 4:00 AM banner

Top AI stories from the last hour

Top AI stories from the last hour

Copy markdown

  • First-class identity, not a static key

    Okta now registers each AI agent in its Universal Directory beside human employees and hands it short-lived, identity-governed tokens instead of stored API keys or one-off OAuth grants. It went GA August 24 at no extra cost inside core Okta SSO, so you assign, monitor and revoke an agent's access from the same console you use for people.

  • It's the enterprise auth layer for MCP

    The real unlock is the protocol underneath: Cross App Access, an OAuth extension now positioned as the Enterprise-Managed Authorization extension for the Model Context Protocol. Claude, Slack, Figma, Canva, Datadog, Asana and Atlassian work out of the box, so an MCP agent can reach them with scoped, auditable tokens rather than a shared key sitting in an env var.

  • The catch: only XAA-aware pairs are covered

    Governance kicks in only when both the agent and the destination speak XAA. Okta can't discover unmanaged agents, MCPs without XAA support still fall back to legacy credentials, and issued tokens stay valid until they expire unless you revoke them by hand. Confirm both ends actually support Cross App Access before assuming an integration is locked down.

  • Elsewhere: a 100B-doc web index built for agents

    Accel-backed Keenable came out of stealth with a search index of more than 100 billion documents aimed at AI agents rather than people, already wired into several labs at training and runtime. Self-serve access is still rolling out, but it's a sign agent-native web search — the layer behind Exa and Tavily — is getting crowded.