Okta's Cross App Access reaches Auth0 developers this week as agent identity rollout begins
Every capability claim here is vendor-sourced. But the rollout dates are concrete, and they collide with Tuesday's finalization of the MCP specification.
Okta's Cross App Access, the company's protocol for authorizing AI agents into enterprise applications and into other agents, enters early access for Auth0 developers at the end of July, which is this week. Okta Workforce customers get supported Cross App Access applications through the Okta Integration Network in August, according to the company's rollout schedule. Okta announced its latest agent security lineup last week, and the window in which any of it becomes something developers can actually touch opens now.
What Cross App Access is
Cross App Access, which Okta abbreviates XAA, is an open OAuth extension for agent-to-app and app-to-app connections. In its partner announcement, Okta says the protocol replaces static API keys with identity-based tokens under centralized policy, with every action logged and access tightly scoped. The partner list the company published spans both sides of the connection: Claude, Cursor, Docker, VS Code and Zoom as requesting applications, and Asana, Atlassian, Canva, Datadog, Figma, Glean, Linear, Slack and Supabase among the resource applications. All of those capability descriptions come from Okta; none of this has independent production mileage yet, which is what the early access period is for.
Okta inside Anthropic's beta
The most concrete deployment Okta describes is Anthropic's beta program, where Okta is the featured identity provider governing Claude's access to participating MCP providers, with joint customers including HubSpot, Ramp and Webflow, according to the company. That sits on top of groundwork laid earlier this month: the Model Context Protocol's Enterprise Managed Authorization extension reached stable status with Anthropic, Microsoft and Okta as identity providers and Asana, Atlassian, Canva, Figma, Linear and Supabase on the server side, as InfoQ reported on July 6. The pattern across both efforts is the same: move authorization decisions out of individual servers and into the enterprise identity provider.
Runtime policy for sensitive moments
Alongside the protocol work, Okta's July product announcements add enforcement machinery. Agent Gateway, available as a research release, sits between agents and enterprise systems, validating agent identity, checking policy and issuing short-lived credentials without code changes, per the company. Agent-to-Agent Connections, which Okta lists as generally available, applies the same verification when one agent hands off work to another, aiming to prevent unauthorized lateral movement between agents. Okta chief product officer Ely Kahn says the goal is that "every agent connection can be evaluated and authorized in real time, then continuously validated as projects evolve." The company also cites its own finding that 76 percent of AI applications are purchased rather than built in-house, its argument for why credential sprawl is the default failure mode.
The identity layer meets Tuesday's spec
The timing gives this rollout more weight than a routine product cycle. The final 2026-07-28 MCP specification lands Tuesday with a stateless core and authorization aligned to OAuth and OpenID Connect practice, as GaaS News details in our story on what breaks Tuesday. A stateless protocol makes per-request identity the only identity there is, which is exactly the layer Okta is selling. Whether XAA becomes the standard way agents carry that identity depends on adoption Okta cannot announce on its own behalf: resource applications have to ship support, and enterprises have to turn it on. The dates to watch are this week for Auth0 early access, August for the Okta Integration Network listings, and the months after for evidence that the partner logos convert into working integrations.