ST-2026-239 · Authentication & identity
Okta adds manual authorization-server registration for third-party MCP servers in Beta
Okta's Preview release adds APIs to attach manually configured authorization servers to third-party MCP servers using issuer, authorizationEndpoint and tokenEndpoint values, alongside discovered servers.
Previous state
The governed Okta MCP integration surface did not expose the current API path for adding a manually configured authorization server alongside discovered server registrations.
Current state
Preview orgs can add and update manually configured authorization servers for a third-party MCP server, supply issuer and authorization/token endpoints, and mix manual and discovered registrations; issuer remains immutable.
Affected users
Who needs to care
Developers and administrators integrating third-party MCP servers with Okta where authorization-server discovery is unavailable or manual endpoint configuration is required.
Required response
What to do
Treat the capability as Beta in Preview, supply the three documented endpoint properties, preserve issuer immutability, and validate update behavior before production adoption.
Evidence boundary
What the source does not prove
Okta proves Beta availability in Preview and the named API parameters and update rules. It does not establish General Availability in Production or automatic migration of existing MCP server registrations.
Lifecycle history
Dated event sequence
- Manual MCP registration entered Beta
Okta listed the API capability in weekly release 2026.08.3 for Preview orgs.
Evidence ledger
First-party sources
- 01Okta — Okta Identity Engine API release notes 2026
Official Okta developer release notes · 2026-08-26
Open official source ↗