Okta Gives AI Agents Their Own Logins With Agent SSO
Agents that speak the Cross App Access standard now get registered in Okta’s directory alongside employees and receive short-lived tokens instead of a static API key.
Okta launched Agent SSO on August 24, extending single sign-on to software that acts on its own. When an AI agent that supports the open Cross App Access standard connects to an enterprise application, Okta registers it in Universal Directory as a first-class identity — listed alongside human employees — and issues short-lived, identity-governed tokens rather than letting it authenticate with a static API key.
The gap it targets is well documented, including by Okta itself. The company’s 2026 research found only 34% of organizations apply security controls to AI agents equivalent to those they apply to human workers. In practice most agents reach enterprise data through static API keys, one-off OAuth grants or bespoke integrations. Those credentials tend to be long-lived, broadly scoped, unattached to any named owner, and invisible to the audit trail — which is a poor combination once an agent is touching payroll systems or customer records.
Okta’s structural claim is that the fix belongs at the identity layer, not in each application. “Just as Single Sign-On centralized human access decisions at the identity provider, Agent SSO moves agent authorization from individual applications to the enterprise identity provider,” said Ric Smith, the company’s president of products and technology. The practical consequence is that security teams manage agent policy through the same administrative consoles and workflows they already use for staff, and can revoke an agent’s access in one place instead of hunting down keys scattered across a dozen SaaS tools.
Distribution is the more interesting part of the announcement. Agent SSO is included at no additional cost in core Okta SSO plans, which makes it immediately available to more than 20,000 existing customers rather than something they have to buy into. Pre-built integrations arrive through the Okta Integration Network, covering Anthropic’s Claude along with Slack, Asana, Datadog, Figma and Notion.
The limits are worth reading carefully. Agent SSO governs agents that speak Cross App Access, so its reach depends on how widely vendors adopt that standard — an agent that does not implement it is not covered. Everything else Okta pitches for agent governance sits in a separate subscription, Okta for AI Agents, which reached general availability on April 30 and handles discovering shadow agents nobody registered, lifecycle management from onboarding to decommissioning, and support for agents outside the Cross App Access path.
Bundling the basic case into plans customers already pay for is a way to make one protocol the default before rivals settle on another. Whether that works is now less a product question than a question of how many agent vendors ship Cross App Access support in the next few quarters.
Want AI news before everyone else?
The morning's most important AI stories, straight to your inbox. No fluff.