Agentic market $10.8B and climbing  ·  editor@gaasnews.com
Sections
HomeWhat is GaaS?PlatformsPricingGlossaryOpinionAboutContact
HomeProtocolsOkta agent identity
Protocols

Okta's Cross App Access reaches Auth0 developers this week as agent identity rollout begins

Every capability claim here is vendor-sourced. But the rollout dates are concrete, and they collide with Tuesday's finalization of the MCP specification.

AJ
Andrew Jamerson
Founding Editor
Jul 26, 2026 · 4 min read
Cross App Access puts an identity layer between agents and the apps they touch // GaaS News

Okta's Cross App Access, the company's protocol for authorizing AI agents into enterprise applications and into other agents, enters early access for Auth0 developers at the end of July, which is this week. Okta Workforce customers get supported Cross App Access applications through the Okta Integration Network in August, according to the company's rollout schedule. Okta announced its latest agent security lineup last week, and the window in which any of it becomes something developers can actually touch opens now.

What Cross App Access is

Cross App Access, which Okta abbreviates XAA, is an open OAuth extension for agent-to-app and app-to-app connections. In its partner announcement, Okta says the protocol replaces static API keys with identity-based tokens under centralized policy, with every action logged and access tightly scoped. The partner list the company published spans both sides of the connection: Claude, Cursor, Docker, VS Code and Zoom as requesting applications, and Asana, Atlassian, Canva, Datadog, Figma, Glean, Linear, Slack and Supabase among the resource applications. All of those capability descriptions come from Okta; none of this has independent production mileage yet, which is what the early access period is for.

Okta inside Anthropic's beta

The most concrete deployment Okta describes is Anthropic's beta program, where Okta is the featured identity provider governing Claude's access to participating MCP providers, with joint customers including HubSpot, Ramp and Webflow, according to the company. That sits on top of groundwork laid earlier this month: the Model Context Protocol's Enterprise Managed Authorization extension reached stable status with Anthropic, Microsoft and Okta as identity providers and Asana, Atlassian, Canva, Figma, Linear and Supabase on the server side, as InfoQ reported on July 6. The pattern across both efforts is the same: move authorization decisions out of individual servers and into the enterprise identity provider.

Runtime policy for sensitive moments

Alongside the protocol work, Okta's July product announcements add enforcement machinery. Agent Gateway, available as a research release, sits between agents and enterprise systems, validating agent identity, checking policy and issuing short-lived credentials without code changes, per the company. Agent-to-Agent Connections, which Okta lists as generally available, applies the same verification when one agent hands off work to another, aiming to prevent unauthorized lateral movement between agents. Okta chief product officer Ely Kahn says the goal is that "every agent connection can be evaluated and authorized in real time, then continuously validated as projects evolve." The company also cites its own finding that 76 percent of AI applications are purchased rather than built in-house, its argument for why credential sprawl is the default failure mode.

The identity layer meets Tuesday's spec

The timing gives this rollout more weight than a routine product cycle. The final 2026-07-28 MCP specification lands Tuesday with a stateless core and authorization aligned to OAuth and OpenID Connect practice, as GaaS News details in our story on what breaks Tuesday. A stateless protocol makes per-request identity the only identity there is, which is exactly the layer Okta is selling. Whether XAA becomes the standard way agents carry that identity depends on adoption Okta cannot announce on its own behalf: resource applications have to ship support, and enterprises have to turn it on. The dates to watch are this week for Auth0 early access, August for the Okta Integration Network listings, and the months after for evidence that the partner logos convert into working integrations.

AJ

Andrew Jamerson

Founding Editor, GaaS News

Andrew Jamerson is the founding editor of GaaS News, covering the economics of the agent era. He started the publication to cover Agentic AI as a Service as a dedicated beat and edits every article on the site.

Be on the list when the beat breaks

One email when a platform ships, a round closes, or the ground shifts under the software stack.