TrueFoundry, an AI gateway vendor, announced on October 1 that it had integrated Okta’s Cross App Access (XAA) protocol into its gateway. That makes the gateway itself the identity checkpoint: the place where an agent presents credentials before any downstream tool or MCP server sees the request. It is the latest signal that XAA, Okta’s open protocol for governing agent-to-app connections, is scaling not just through partner count but through the infrastructure layer where it actually matters. Okta’s XAA ecosystem now includes over 25 early adopters, and the company’s XAA developer playground opened this month.
The identity gap XAA was built to close is straightforward. Most agents running in production authenticate with static API keys. Those keys do not expire, they are rarely scoped to a particular task, and they produce almost no audit trail. IT teams end up with limited visibility into what an agent actually accessed and when. Okta research cited by TrueFoundry puts numbers on the consequence: 88 percent of organizations report confirmed or suspected AI agent security incidents, and 92 percent of those that experienced an AI-related breach lacked adequate access controls.
XAA replaces the static key with a short-lived token scoped to the specific task an agent is carrying out. The token is issued in real time against the user’s active Okta identity, it can be revoked at any point, and it is logged so access remains auditable after the fact. Agent connections are evaluated against the organization’s central identity policy in the same way a human user’s access would be. Built on the ID-JAG standard (Identity Assertion Authorization Grant), XAA is an open OAuth extension that has been incorporated into MCP as its official authorization extension. It is vendor-neutral by design.
Agent SSO, which launched in August 2026, brought XAA into Okta’s workforce plans at no additional cost for over 20,000 customers, treating agents as first-class identities in the same directory as human users. XAA OIN Submission reached GA in the 2026.09.0 monthly release; the protocol itself is in Early Access with GA targeted for FY27.
The deeper issue is where this identity logic gets enforced. The AI gateway is becoming the natural enforcement point because it sits directly in the path of agent traffic. TrueFoundry’s gateway, for example, validates the Okta token on each request, performs a token exchange with Okta to receive an ID-JAG assertion scoped to the target MCP server, and issues a short-lived, audience-restricted access token for that server. The gateway registers in the Okta Integration Network with a dual role, allowing it to bridge XAA to MCP servers that do not natively support the protocol. In this architecture, Okta acts as the Policy Decision Point and the gateway as the Policy Enforcement Point, enabling real-time, continuous scope validation.
This is the same execution-layer gateway pattern Forkast has been tracking since earlier this year. The difference is that identity is now being applied at the protocol level rather than bolted on as a vendor-specific feature.
The ecosystem is expanding fast. Beyond the 25-plus early adopters, the XAA partner list now includes identity infrastructure and gateway vendors such as Aquera, Archestra.AI, Cloudflare, Keycard, Keycloak, MintMCP, Scalekit, Stytch by Twilio, WorkOS, and Zuplo. This follows Aembit’s integration at Oktane in September, which established the first third-party enforcement point for XAA. The early adopter set includes Anthropic, Zoom, Slack, Atlassian, Canva, Docker, Datadog, Cursor, and Figma among others.
There is no equivalent protocol on Windows or Linux for agent-specific access control at the identity layer. Apple’s recent macOS Full Disk Access changes address agent permissions at the OS level through consent flows. XAA operates at the identity provider layer, below the OS but above the application. The convergence of XAA and MCP means the gateway is becoming the identity checkpoint: a standardized place where every agent connection gets evaluated against enterprise policy before it reaches a tool.
The pattern Okta is building follows a familiar structure. Define the standard. Let the ecosystem build enforcement on top. The harness pattern is becoming identity-aware. Commodity infrastructure is bundling identity as a default feature. Kubernetes agent sandboxes provide container-level isolation alongside gateway-level identity enforcement. Each layer is shipping, each is operating above the operating system, and each serves a different enforcement function. XAA sits at the identity provider layer, underneath all of them.
