API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-101 · Authentication & identity

Okta previews cross app access for AI agents and applications

Okta Cross App Access can connect custom SAML or OIDC agentic requesting applications to OIDC and SAML resource applications through administrator-managed, user-delegated connections without runtime consent prompts.

OktaCross App AccessAI agentsSAMLOIDCdelegation linksresource connectionsauthenticationpreview

Previous state

Okta’s documented Cross App Access connection types did not include custom SAML requesting applications, so those apps could not use the XAA resource-connection path to act against OIDC or SAML resource applications.

Current state

Cross App Access supports custom SAML and OIDC agentic requesting applications connected to OIDC or SAML resource applications. Okta administrators manage the connection and delegated user access, while the Delegation Links and resource-connection APIs expose tokenType and connectionType options for the supported requesting applications.

Who needs to care

Okta administrators and application teams configuring AI agents or other custom SSO requesting applications to act for users against OIDC or SAML resource applications, including deployments that previously configured access through delegation links.

What to do

Model and approve each requesting-to-resource application connection in Okta, set the required tokenType and connectionType values in API-managed configurations, validate the allowed user actions, and reconfigure earlier Delegation-tab access in the User access tab where Okta’s migration guidance applies.

What the source does not prove

The July change was listed for Preview orgs, and the August expansion was expected in Preview orgs on 17 August 2026. This record does not claim general availability in Production. Administrator-managed connections remove runtime consent but do not remove Okta policy, visibility or action controls.

Lifecycle history

Dated event sequence

  1. Custom SAML requesting apps added in Preview

    Okta added custom SAML requesting applications to Cross App Access and extended the Delegation Links and resource-connection APIs with tokenType and connectionType options.

  2. Expanded customer preview expected

    Okta listed Cross App Access support for AI agents and applications for all customers as expected in Preview orgs and moved earlier delegation-link configuration to administrator-managed User access.

Evidence ledger

First-party sources

  1. 01
    Okta — Okta Identity Engine API release notes 2026

    Official Okta Identity Engine release notes · 2026-08-17

    Open official source ↗