Okta announced general availability of Agent SSO on August 24, 2026, a change that gives AI agents a first-class identity model at the moment they connect into enterprise systems. Rather than treating an autonomous agent as an anonymous script holding a stored API key, Agent SSO registers it in Okta's Universal Directory alongside human employees, then issues short-lived, policy-governed tokens whenever that agent needs to act inside another application on a user's behalf. It ships inside core Okta SSO plans at no additional cost, a distribution decision that puts agent identity in front of more than 20,000 existing Okta customers by default rather than as a separate upsell. The launch is one entry in a fast-moving, multi-vendor effort to answer a question enterprise identity teams did not have to ask five years ago: what happens when the thing requesting access is not a person.
AnthropicWhat Agent SSO actually changes
The mechanics are specific. When a supported AI agent needs to reach a second application while acting for a user, that request routes through Okta rather than through a credential the agent has been handed and is expected to keep safe. Okta registers the agent as its own entry in Universal Directory, the same directory that already holds human employee accounts. Administrators then apply access policy to that entry using the identical console and workflows they use for people: which applications the agent may reach, under what conditions, and for how long. When the agent acts, Okta issues a short-lived, identity-governed token scoped to that one action rather than a standing key that keeps working until someone remembers to revoke it.
How Agent SSO governs one agent action
The mechanism replaces a standing, stored credential with a scoped token minted for a single action and admin-defined policy that mirrors how human employee access is already governed.
Applies to agents that support the open Cross App Access standard, which Agent SSO folds into core Okta SSO plans. Source: Okta newsroom, August 24, 2026; Okta Developer documentation on AI agent token exchange.
Underneath the product sits an open standard called Cross App Access, built on a new IETF OAuth specification called the Identity Assertion JWT Authorization Grant, informally ID-JAG. The pattern lets an enterprise identity provider that an application already trusts for single sign-on mediate a second application's authorization decision too, translating identity and permission context across the boundary instead of asking the agent to hold and present its own long-lived secret. Okta's launch partners for Cross App Access support include Anthropic's Claude, along with Asana, Atlassian, Canva, Datadog, Figma, Glean, Notion, Slack, and Supabase, according to Okta's own newsroom announcement. Agent SSO is the product wrapper that makes this standard part of core SSO rather than a separate integration project.
This built on an earlier release. Okta for AI Agents, a broader product covering agent discovery, credential issuance, and lifecycle governance, reached general availability on April 30, 2026, following an early-access period that began the previous November. Agent SSO narrows in on one specific, high-frequency motion inside that broader system: the moment an agent needs to act in a second app on a user's behalf, made available to every core SSO customer rather than only the ones who had adopted the fuller governance product.
Why static credentials do not survive contact with autonomous agents
Traditional enterprise identity and access management was built for a world where the thing logging in was a person who could be asked to re-authenticate, could recognize a phishing prompt, and logged in a handful of times a day. Machine-to-machine access has existed for decades in the form of API keys and service accounts, but it stayed a comparatively small, slow-moving category: a key got issued once, rotated on some schedule if the organization was disciplined about it, and sat in a secrets manager or, more often, a configuration file.
AI agents break that model on two axes at once. First, volume: agents are provisioned quickly, often by individual teams outside a formal request process, and one agent can be the entry point for dozens of tool connections rather than one. Palo Alto Networks' 2026 Identity Security Landscape research put machine identities, AI agents included, at 109 for every human identity in the enterprises it studied, up from 82 to 1 a year earlier, and attributed roughly 79 of those 109 machine identities per human directly to AI agents. Other measurements land at different absolute ratios (Rubrik Zero Labs has cited 45 to 1 with some organizations above 100 to 1, KPMG has cited 80 to 1), but every recent estimate agrees on direction: the non-human population is both larger than the human one and growing faster.
Second, behavior: an agent does not just hold a credential, it acts on one, autonomously and repeatedly, often chaining access across several systems in a single task without a human in the loop to notice something is wrong. A static API key that would sit mostly idle in a traditional service account becomes, in an agent's hands, the thing that gets exercised continuously and unpredictably. If that key is long-lived and broadly scoped, a single leaked credential or a single compromised agent stops being a contained incident and becomes a standing foothold across every system that credential can reach.
A stolen human password gets one login. A stolen static agent key can keep working, unnoticed, for as long as nobody happens to look.
Framing echoed across Okta's, Microsoft's, and independent identity-security research through 2026
The response the industry has converged on, at least on paper, has three parts: least privilege scoped to what a given task actually needs rather than what an agent's platform is broadly capable of, short-lived tokens that expire rather than persist, and per-action authorization with a real audit trail so that "what did this agent actually do" has an answer after the fact. Agent SSO's design (registration, policy, expiring token, repeat) is one vendor's implementation of that pattern applied specifically to the moment an agent crosses from one application into another.
The governance gap the product is trying to close
Okta's own research gives the clearest read on how far enterprise practice still lags that design goal. The company's "AI Agents at Work 2026" report, fielded in March 2026 across 784 executives and knowledge workers in seven countries, found that only 34% of organizations apply the same security controls to AI agents that they apply to human employees. The same survey found 58% of organizations had already experienced an AI-related security incident or close call in the prior twelve months, and 53% now have a formal AI deployment strategy, up sharply from about 10% a year earlier. Put together, the numbers describe organizations that are deploying agents faster than they are governing them: adoption and incident exposure are both climbing, while the specific practice of treating an agent's access with the same rigor as a person's access remains a minority behavior.
Incidents are already common. Matching controls are not.
Share of organizations reporting each, from Okta's AI Agents at Work 2026 survey of 784 executives and knowledge workers across seven countries, fielded March 2026.
Fewer than two in five organizations apply the same security controls to AI agents that they apply to human employees, even though a majority have already had an incident.
A separate survey Okta has cited from Gravitee, "The State of AI Agent Security 2026," found 88% of organizations reporting confirmed or suspected AI agent security incidents and only 22% of organizations treating agents as independent, identity-bearing entities rather than folding them into a shared service account. The two surveys use different populations and methodologies, so the exact percentages should not be read as directly comparable, but they point the same direction: incident exposure is now common, and identity-first governance of agents is not.

Closing that gap is also, transparently, a business strategy. On July 30, 2026, Okta signed a definitive agreement to acquire Permiso Security for approximately $200 million in a largely cash deal. Permiso, founded by former FireEye executives, builds threat-detection software that watches what happens after an identity, human or machine, has already been granted access, looking for the kind of anomalous behavior that indicates a credential is being misused. Folding that into Okta's identity fabric extends the company's reach from the moment of authorization, which Agent SSO governs, into continuous monitoring of what an agent actually does with the access it was given. The deal is expected to close in the third quarter of Okta's fiscal 2027.
Where this sits in a crowded field
Okta is not alone in building this layer, and treating Agent SSO as a settled industry standard would overstate one vendor's position. Microsoft has built a parallel effort called Entra Agent ID, which creates agent identity accounts inside Entra ID using federated identity credentials rather than passwords, aimed at the same underlying problem for organizations already standardized on Microsoft's identity stack. A cluster of newer, agent-identity-specific security vendors, including companies like Oasis Security, has grown up around the same premise: that non-human and agentic identity is now large and fast-moving enough to need its own dedicated tooling, distinct from both classic human IAM and classic secrets management. Where Agent SSO deals specifically with an agent crossing from one application into another under a user's authority, adjacent efforts like the Model Context Protocol's own authorization model address a related but separate problem: how an individual tool an agent calls authenticates that call in the first place. The practical shape of enterprise agent security in 2026 is several of these layers stacked together rather than one company's product covering the whole problem.
None of this is unique to a chat interface or a single AI lab's agent framework, either. Any system that lets an agent reach real tools, real data, and real credentials on a user's behalf runs into the same design question Okta is trying to answer at the identity-provider layer: how do you grant an agent exactly the access a task requires, for exactly as long as the task takes, with a record of what it did. Products that route work across many underlying AI models, including Metir AI's own model-agnostic approach, face a version of the same problem one layer down, in how credentials and tool access are scoped and governed for an agent regardless of which model happens to be doing the reasoning behind it.
The takeaway
What is verifiable is straightforward: Okta shipped a no-additional-cost mechanism on August 24, 2026 that treats AI agents as first-class, policy-governed identities issuing short-lived tokens instead of static keys, building on an April 30, 2026 product and a July 30, 2026 acquisition that both point the same direction. What is not yet true, by Okta's own survey data, is that most organizations have caught up to that design: just over a third apply the same controls to agents that they apply to people, even as a majority have already had an incident. The technology for scoped, short-lived, auditable agent access now exists from multiple vendors. Whether enterprises actually turn it on is a separate, and currently unresolved, question.
Sources:
- Okta brings first-class identity to AI agents with Agent SSO | Okta Newsroom
- Okta launches Agent SSO for governing enterprise AI agents | TechNode Global
- Okta launches Agent SSO to manage enterprise AI agent access | SecurityBrief
- AI Agents at Work 2026: Securing the agentic enterprise | Okta Newsroom
- Set up AI agent token exchange | Okta Developer
- Cross App Access: Securing AI agent and app-to-app connections | Okta
- Identity Assertion JWT Authorization Grant | IETF Datatracker
- Okta for AI Agents is Now Generally Available | Okta Blog
- Okta Announces New Blueprint for the Secure Agentic Enterprise | Okta Investor Relations
- Okta buys AI security startup Permiso, source says for about $200M | TechCrunch
- Okta to acquire Permiso Security in reported $200M identity security deal | SiliconANGLE
- CIOs must rethink identity now people are being outnumbered by nonhuman entities | TechRadar Pro
- What are agent identities? Microsoft Entra Agent ID | Microsoft Learn
- Okta, Inc. | Wikipedia
Image credits
Header image: 100 First Plaza, the office tower at 100 First Street, San Francisco that houses Okta's corporate headquarters, photographed from Salesforce Park, by Dead.rabbit, via Wikimedia Commons, licensed under CC BY-SA 4.0. In-body photograph of the same building, 100 First Plaza, photographed from street level in 2008, by Miguel Chavez, via Wikimedia Commons, released as public domain.
