← Back to all sparks
Okta logo

Okta

INFRA · APISDEVOPS
Velocity5.0

Identity and access management platform

Okta's developer channel has become an extended argument for Cross App Access as the way agents get authorized.

cross-app-accessagent-authorizationsamlmcpdeveloper-educationoin
Current state
This feed is Okta's developer blog, so entries are guides and tutorials rather than release notes. Four of the last six are about Cross App Access, the Identity Assertion Authorization Grant implementation Okta is pushing as the mechanism for agent-to-app authorization.
Where it's heading
The XAA content has moved from explaining the concept to closing adoption gaps: SAML apps that will not migrate to OIDC, a C# MCP walkthrough, and instructions for listing XAA connections on the Okta Integration Network. That progression is what a vendor publishes when it wants a spec adopted rather than admired.
Prediction
Expect further XAA enablement content aimed at specific stacks and more emphasis on OIN listings, since the value of the approach rises with the number of apps on both sides that support it.

Recent moves

  1. 15d ago

    Build a Flask App with Okta for Secure OIDC Login and Authorized API Calls

    A standard tutorial on adding OIDC login and authorized API calls to a Flask app. Framework onboarding content with no bearing on Okta's product direction.

    View source ↗
  2. 26d ago

    Enable Your SAML Requesting App for Cross App Access

    A guide to supporting Cross App Access from SAML requesting apps, covering the security and uniqueness requirements the Identity Assertion Authorization Grant did not originally address for SAML. It extends XAA's reach to federations that will not move to OIDC.

    View source ↗
  3. 27d ago

    Build a Secure C# MCP App with Cross App Access (XAA)

    A walkthrough for building a C# MCP application using Cross App Access, framed around the gap that appears when an agent needs access across several resources on a user's behalf. It connects the XAA push directly to MCP-based agent tooling.

    View source ↗
  4. 1mo ago

    Introducing Okta Journeys: A Better Way for Developers to Learn Identity

    Okta Journeys launches as a task-oriented way to navigate Okta's documentation, replacing the stitching-together of how-to guides and scattered posts. Documentation structure is not a product capability, but it is a stated response to repeated developer complaints.

    View source ↗
  5. 1mo ago

    How to Build and List Secure Cross App Access (XAA) Connections on Okta Integration Network (OIN)

    Instructions for building and listing Cross App Access connections on the Okta Integration Network, pitched against static API keys and unmanaged OAuth consent. Getting XAA connections into the OIN catalog is the distribution step that makes the spec useful in practice.

    View source ↗
  6. 1mo ago

    Enabling Cross App Access for SAML-Based Enterprise Apps

    A near-duplicate of the later SAML Cross App Access guide, aimed at letting AI agents reach a SAML-federated app's API without an OIDC migration. Same material, restated for the agent-access framing.

    View source ↗