ST-2026-101 · Authentication & identity
Okta previews cross app access for AI agents and applications
Okta Cross App Access can connect custom SAML or OIDC agentic requesting applications to OIDC and SAML resource applications through administrator-managed, user-delegated connections without runtime consent prompts.
Previous state
Okta’s documented Cross App Access connection types did not include custom SAML requesting applications, so those apps could not use the XAA resource-connection path to act against OIDC or SAML resource applications.
Current state
Cross App Access supports custom SAML and OIDC agentic requesting applications connected to OIDC or SAML resource applications. Okta administrators manage the connection and delegated user access, while the Delegation Links and resource-connection APIs expose tokenType and connectionType options for the supported requesting applications.
Affected users
Who needs to care
Okta administrators and application teams configuring AI agents or other custom SSO requesting applications to act for users against OIDC or SAML resource applications, including deployments that previously configured access through delegation links.
Required response
What to do
Model and approve each requesting-to-resource application connection in Okta, set the required tokenType and connectionType values in API-managed configurations, validate the allowed user actions, and reconfigure earlier Delegation-tab access in the User access tab where Okta’s migration guidance applies.
Evidence boundary
What the source does not prove
The July change was listed for Preview orgs, and the August expansion was expected in Preview orgs on 17 August 2026. This record does not claim general availability in Production. Administrator-managed connections remove runtime consent but do not remove Okta policy, visibility or action controls.
Lifecycle history
Dated event sequence
- Custom SAML requesting apps added in Preview
Okta added custom SAML requesting applications to Cross App Access and extended the Delegation Links and resource-connection APIs with tokenType and connectionType options.
- Expanded customer preview expected
Okta listed Cross App Access support for AI agents and applications for all customers as expected in Preview orgs and moved earlier delegation-link configuration to administrator-managed User access.
Evidence ledger
First-party sources
- 01Okta — Okta Identity Engine API release notes 2026
Official Okta Identity Engine release notes · 2026-08-17
Open official source ↗