ST-2026-232 · Authentication & identity
Okta adds API-key and static-JWKS authentication for Privileged Access workload connections
Okta Privileged Access now documents API-key authentication as generally available for workload connections and supports static JWKS content for JWT verification without a public key-discovery endpoint.
Previous state
The governed SchemaTrace corpus did not track API-key authentication and static-JWKS verification as supported authentication mechanisms for Okta Privileged Access workload connections.
Current state
Okta documents API-key authentication for workload connections as generally available and supports static JWKS content so a workload connection can verify JWTs without relying on a public key-discovery endpoint.
Affected users
Who needs to care
Okta Privileged Access workload-connection integrations choosing how workloads authenticate and how JWT signing keys are supplied for verification.
Required response
What to do
Use the documented API-key or static-JWKS mechanism where it matches the workload-connection design, and validate configuration against Okta's current Privileged Access guidance.
Evidence boundary
What the source does not prove
Okta proves support for these workload-connection authentication methods. It does not establish that every Okta tenant has configured them or that unrelated Okta authentication flows changed.
Lifecycle history
Dated event sequence
- Workload-connection authentication update published
Okta documented API-key authentication as GA and static JWKS support for workload connections.
Evidence ledger
First-party sources
- 01Okta — 2026 Okta Privileged Access release notes
Official Okta developer release notes · 2026-08-20
Open official source ↗