The mechanism for giving AI agents inside a company the same identity as human employees has become a standard feature. On August 24, 2026, Okta made Agent SSO, a single sign-on capability for AI agents, generally available. It is included in the core SSO plans used by more than 20,000 customers, with no additional charge. The goal is to move companies away from wiring agents into internal systems with static API keys, and toward managing them centrally at the identity provider.

Access That Belongs to No One Is Piling Up

When teams connect an agent to an internal application, the options they reach for are fairly predictable: issue a long-lived API key, push through a one-off OAuth grant, or build a custom integration for that specific application. All of them work, and all of them share the same flaw. Nothing about the owner survives in the record.

The result is that agent traffic moves through the company anonymously. Who is responsible for it, which policy applies to it, and what it accessed and when are the three things operations actually needs, and all three are missing while the number of agents keeps growing.

In Okta's own AI Agents at Work 2026 report, only 34 percent of organizations apply the same security controls to AI agents that they apply to human workers. The remaining two thirds are not enforcing on agents touching internal systems what they already enforce on people.

Part of the reason governance falls behind is that there is not just one kind of agent to govern. There are agents a company builds itself, agents already embedded in the SaaS products it buys, and agents employees start using without going through IT. All three populations have to be accounted for at once.

Replacing Stored Credentials With Short-Lived Tokens

Agent SSO covers agents that support Cross App Access. When such an agent tries to connect to an internal application, Okta registers it as a first-class identity in Universal Directory, sitting in the same directory as human employees and handled the same way.

Instead of stored credentials, a registered agent receives a short-lived token issued for each connection. Administrators do not need to learn a separate console for agents. They assign, monitor, and update policy through the same console and the same workflows they already use for employee access.

If a company has deployed Anthropic's Claude, for example, the security team can govern its access natively as part of normal permission management. Employees no longer share static credentials or approve the same consent screen over and over.

Conceptually, single sign-on moved access decisions for humans out of individual applications and into the identity provider. Agent SSO performs the same relocation for agent authorization.

Standardizing the Entry Point, Charging for the Governance

It is worth being precise about which question Agent SSO answers. Its scope is a single connection point: how a Cross App Access agent reaches internal applications and MCP servers.

How many agents exist inside the company, what each of them can connect to, and what each is allowed to do are answered by Okta for AI Agents, the higher tier that has been generally available since May 2026 and is sold as a separate subscription. It discovers unregistered shadow agents and assigns them named human owners, and it reaches resources Cross App Access does not, including custom authorization servers, service accounts, secrets, and agent-to-agent connections. Governance functions such as access certifications, approval workflows, and agent deactivation also sit on that side.

The line between free and paid is clear, but the upgrade path is designed to be light. Agents already registered through Agent SSO are already first-class identities, so moving up does not require registering them again. The entry point is standardized for free, and the governance is where the billing starts.

Who Is Already Supported, and a Use Case Beyond AI Agents

Connections are available through the Okta Integration Network, so no custom integration work is required. The published list of supported destinations includes Anthropic (Claude), Archestra.AI, Asana, Atlassian, Canva, Datadog, Figma, Glean, Granola, Linear, MintMCP, Notion, Slack, and Supabase, covering most of the SaaS products used in day-to-day work.

Cross App Access, the foundation underneath, is an open, vendor-neutral specification whose design Okta led, built as an extension of OAuth. What matters most about its positioning is that it has been formally incorporated as Enterprise-Managed Authorization, the official extension of the Model Context Protocol (MCP). As MCP spreads as the connection standard between agents and external tools, Cross App Access takes on the enterprise authorization piece of it.

The specification is not limited to AI agents. It covers any case where one application acts on a user's behalf in another, so conventional integrations such as syncing Zoom meeting notes into Asana fit the same framework.

Summary

Okta has made Agent SSO generally available, allowing Cross App Access agents to be registered as first-class identities in Universal Directory. Static API keys are replaced by short-lived tokens, and management stays in the same console used for employees. It is included in core SSO plans at no additional cost, while shadow agent discovery and governance belong to the separately priced Okta for AI Agents. Given that only 34 percent of organizations currently apply equivalent controls to agents, standardizing the connection layer for free is a reasonable place to start.