Identity management company Okta has made Agent SSO generally available, giving enterprises a way to register artificial intelligence agents as identities and govern how they access applications and data.
The product is part of Okta’s existing single sign-on service and is available at no additional cost to customers on core SSO plans, according to the company’s announcement. Okta positions the release as an alternative to giving agents static API keys or broadly scoped OAuth tokens.
Agents become managed identities
Agent SSO allows an organization to register an AI agent in Okta Universal Directory. Administrators can then apply access policies and issue short-lived tokens when the agent needs to act in another application on a user’s behalf.
The distinction matters because an autonomous or semi-autonomous agent may call multiple business systems during a task. Traditional credentials can be difficult to trace to a specific agent, user and action, particularly when developers embed long-lived secrets in workflows.
Okta said Agent SSO is based on Cross App Access and an enterprise-managed authorization extension to the Model Context Protocol. The design aims to let a destination application understand that an agent is acting for a user while allowing the enterprise to maintain central control over the authorization.
The company said the product can enforce policies based on the user, agent and target application. It can also provide administrators with a record of agent access through the same identity infrastructure used for employees and conventional applications.
Enterprise software vendors are participating
Okta named Anthropic, Asana, Atlassian, Canva, Datadog, Figma, Glean, Miro, Monday.com, OpenAI and Salesforce among the companies working with its agent identity approach. The presence of collaboration and development platforms is relevant because these systems often contain the documents, code and customer data that workplace agents are expected to use.
Support across vendors will determine how useful the model becomes in practice. An organization can centrally govern an agent only when the connected service recognizes the relevant identity and authorization signals. Enterprises should therefore confirm the availability and scope of each integration rather than assuming uniform support.
Okta cited its own research indicating that organizations are adopting agents faster than they are establishing governance. That conclusion is directionally consistent with the identity industry’s focus on non-human identities, but the underlying survey methods and definitions should be reviewed before relying on the percentages in the company’s release.
Short-lived access narrows credential risk
Replacing static secrets with short-lived tokens can reduce the window in which a stolen credential remains useful. It can also make revocation and policy changes more responsive when an employee changes roles, an agent is modified or an integration is disabled.
Agent identity does not address every security issue associated with AI systems. Enterprises still need controls for data classification, prompt injection, model behavior, tool permissions and human approval of sensitive actions. Identity provides a control point, but it cannot determine whether every action an authorized agent attempts is safe or appropriate.
The release is relevant for Asia-Pacific companies adopting workplace agents across distributed teams and regulated sectors. Financial services, healthcare and public-sector deployments in particular may require evidence that an automated action can be traced to both the software agent and the person or process that authorized it.
Agent SSO’s inclusion in core plans may encourage early testing, although buyers will need to assess application coverage, logging detail and how the system interacts with their existing privileged-access and data-governance tools.
Featured image: FlyD on Unsplash
As AI agents multiply, identity becomes the enterprise control plane

