Opal Zero is here. Read the news and explore the

Platform

Customers

Resources

Platform

Customers

Resources

Opal Joins Okta’s Cross App Access Ecosystem: Every Agent Connection Gets an Owner, a Purpose, and a Time Limit

Sameer Mehta

Product

0

1

Today at Oktane, Okta announced the expanded Cross App Access ecosystem on the keynote stage: more than 50 companies, Slack, Notion, Figma, Datadog, Zoom, and Claude among them, committed to one open standard for how AI agents connect to enterprise apps. Opal joins that ecosystem, serving two roles: as a resource app, it’s where agents go to ask for access, and they reach it through XAA. As the governance layer, it’s where every connection Okta authorizes gets governed on the same terms as a person’s access.

It’s also one of Opal Zero’s launch integrations. Last week we introduced Opal Zero, just-in-time access governance for AI agents, on a premise that’s simple to state and hard to do: least privilege for an agent means three things at once, a grant that expires, an owner for every agent, and a decision at the point of access. With Cross App Access, agents reach the apps they need, Opal included, through the identity layer that already governs your employees, and Opal Zero holds each of those connections to all three conditions.

Static keys are how agents get standing access

Most agents still reach tools with a static API key someone pasted into a config file. It never expires, nobody owns it, and when the agent does something it shouldn’t, there’s no trail back to a person.

The data says this is the norm. Opal Labs found that more than 96% of non-human identities have no recorded purpose, and only 10% of their access was reviewed in the past year.

What Cross App Access changes

Cross App Access is an open, vendor-neutral protocol that extends OAuth so an enterprise identity provider can broker the connection between an AI agent and the app it needs. It is also an enterprise authorization extension of the MCP spec, so it covers MCP servers as well as APIs.

Instead of an agent holding a long-lived key:

  1. The connection is anchored to an Okta identity: the user the agent is acting for, or, with Agent SSO, the agent itself, registered as a first-class identity in Universal Directory.

  2. Okta issues a short-lived token scoped to what that task needs, under your existing policies.

  3. The app accepts the token, enforces the scope, and logs the action.

  4. Revoke the identity in Okta and every downstream connection goes with it.

No custom governance to build. No consent prompt on every connection. One audit trail across humans and agents.

“Organizations shouldn’t have to choose between adopting AI tools and maintaining visibility over enterprise access,” says Aaron Parecki, Senior Director of Identity Standards at Okta. “By connecting apps with the Cross App Access protocol, security teams get more control and users get a better experience without all the OAuth consent prompts.”

Where Opal Zero comes in

XAA is how the agent connects, and Opal Zero is how it stays accountable: an owner, a decision on every request it makes, and an end date on what it holds.

An owner for every agent: Opal Zero’s Inventory ingests agents from Okta and maps each one to an owner, a purpose, and what it can reach, with people and agents held to the same record. An XAA-connected agent shows up with a name and a reason to exist, not as an anonymous client ID.

A decision at the point of access: When an agent needs more than it has, it files the request itself through Opal’s MCP server, and Paladin decides it the moment it’s made, against your policy and everything Opal knows about that agent: its owner, its declared purpose, its blast radius, whether it’s carrying a long-lived credential, what its activity says it actually does, and whether the ask reaches past what its owner holds. A policy might auto-approve reads and put a human in the loop for writes, deletes, and anything that touches a sensitive system. Every decision ships with its reasoning and a full audit trail.

Grants that expire: XAA tokens are short-lived by design. Opal Zero’s Risk Center finds what isn’t: unowned and dormant agents, standing privileges, access that reaches past an agent’s purpose. It explains why each one matters and routes the fix to the owner, inline: assign an owner, revoke the access, or deactivate the agent.

Every connection Okta authorizes lands in Opal’s access graph with an owner, a purpose, and a time bound, reviewed and revoked on the same terms as human access.

We named the product for the goal: reduce standing access to zero. The connection is where that starts.

Get started

AI that makes continuous access decisions, with you on the dial.

AI that makes continuous access decisions, with you on the dial.

AI that makes continuous access decisions, with you on the dial.

Everything you need to know about Opal

What is Opal Security and what does it do?

What systems does Opal integrate with?

How is Opal different from traditional IGA and IAM tools?

Can Opal govern AI agents and non-human identities?

Does Opal replace my existing identity stack?

How fast can Opal be deployed?

Who is Opal's leadership?

0

FAQ

Everything you need to know about Opal

What is Opal Security and what does it do?

What systems does Opal integrate with?

How is Opal different from traditional IGA and IAM tools?

Can Opal govern AI agents and non-human identities?

Does Opal replace my existing identity stack?

How fast can Opal be deployed?

Who is Opal's leadership?

0

FAQ

Everything you need to know about Opal

What is Opal Security and what does it do?

What systems does Opal integrate with?

How is Opal different from traditional IGA and IAM tools?

Can Opal govern AI agents and non-human identities?

Does Opal replace my existing identity stack?

How fast can Opal be deployed?

Who is Opal's leadership?

0

FAQ

See. Encode.

Enforce.

© 2026

See. Encode.

Enforce.

© 2026

See.

Enforce.

Encode.

© 2026