Skip to content

Security1 publisher2 min readPublished

Okta swaps agent API keys for short-lived tokens across 14 prebuilt integrations

Agent SSO went generally available on August 24 at no extra cost inside core Okta SSO, registering Cross App Access agents in Universal Directory and issuing short-lived tokens. Discovering unregistered agents takes a separate subscription.

The Watch · Security desk

Illustration accompanying Okta swaps agent API keys for short-lived tokens across 14 prebuilt integrations

What happened

  • Okta declared Agent SSO generally available on August 24, 2026, putting the Cross App Access standard into the identity product it says more than 20,000 customers use, at no extra cost in core SSO plans.
  • The feature registers a connecting agent as a first-class identity in Universal Directory alongside human employees, then issues short-lived, identity-governed tokens instead of stored credentials.
  • Prebuilt Cross App Access integrations in the Okta Integration Network cover 14 named vendors, among them Anthropic's Claude, Atlassian, Datadog, Notion, Slack and Supabase.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Agent SSO covers only agents that speak Cross App Access. An agent wired by hand to a service account or a secrets store is outside the free tier, and Okta puts that plumbing behind the paid subscription.
  • capability Revoking an agent becomes an identity action in the console security teams already run for employees, instead of hunting keys application by application.
  • cost Securing the agents an enterprise already knows about now costs nothing, while discovering the unregistered ones is a separate line item, and the release does not list a price for it.
  • decision The agent-authorization question for buyers narrows to whether a given vendor's agent implements Cross App Access, and the Integration Network list answers that for 14 of them today.

Static API keys, one-off OAuth grants and custom integrations built application by application are how most agents reach enterprise data today, and Okta describes that traffic as anonymous: no owner, no governing policy and nothing in an audit trail [7]. The credential sitting in the agent's config is no longer what grants lasting access, and cutting an agent off is one action in the console the team already uses for employees [6].

Okta's own framing names three agent populations an enterprise has to account for: the ones it built, the ones embedded in the software it buys, and the ones employees stand up without central approval [8]. Agent SSO reaches the second population, and only where the vendor has shipped Cross App Access support [4]. Cross App Access is an open, vendor-neutral protocol [19].

Everything else sits behind the paid product. Okta for AI Agents discovers unregistered and shadow agents and assigns them named human owners [14]. It also covers what the protocol does not reach: custom authorization servers, service accounts, secrets, and agent-to-agent access [15]. Governance there runs through access certifications, approval workflows and agent deactivation [16]. That subscription reached general availability in May 2026, roughly three months before the free entry point [20]. Okta says upgrading does not require re-registering agents Agent SSO has already touched [17].

The demand-side number comes from the vendor. Okta's AI Agents at Work 2026 report puts the share of organizations applying the same security controls to AI agents as to human workers at 34%, which leaves about two thirds not doing so [9][10].

"By treating every connected agent as a first-class identity and bundling this capability directly into our core SSO offering, Okta is making it effortless for enterprises to secure AI workflows from day one," said Ric Smith, President of Products and Technology at Okta [18].

For a security team the configuration question this quarter is specific: which agents already running in the environment speak Cross App Access, and who holds the keys for the rest. Agent SSO answers the first half at the identity provider, and covers connections to MCP servers as well as to applications [23]. The static keys behind the rest stay in place until someone inventories them, and inventorying them takes the paid product [14].

What to watch

  • Whether vendors outside the 14 already in the Okta Integration Network ship Cross App Access support, and how quickly.
  • Whether Okta publishes list pricing for Okta for AI Agents or keeps it in quote-only deals.
  • Whether any measurement outside Okta's own report tests the 34% figure on agent security controls.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories