The numbers should stop you cold. According to the Cloud Security Alliance, non-human identities now outnumber human employees by ratios reaching 90:1 in some organizations. Seventy percent of enterprises grant AI agents higher permissions than their human staff. Only 28 percent can trace an AI agent's actions back to a responsible individual. These are not theoretical risks. These are the conditions that produce catastrophic breaches.
In August 2026, Okta launched Agent SSO, a product designed to address exactly this problem. The company is giving it away โ bundled free into its Core SSO offering. That decision tells you more about the competitive dynamics of the AI identity market than any press release ever could.
The Context: What Okta Actually Built
Agent SSO is Okta's attempt to bring enterprise identity management to AI agents. The technical foundation is XAA โ Extended Agent Authorization โ an extension of the OAuth 2.0 framework. It leverages RFC 8693 (Token Exchange) and RFC 7523 (JWT-based Client Authentication) to create a standardized way for AI agents to authenticate and authorize actions on behalf of principals.
The critical move is integration with the Model Context Protocol. Anthropic's MCP has become the de facto standard for AI agent tool interoperability. By having XAA incorporated into MCP's Enterprise-Managed Authorization extension, Okta has positioned identity at the tool/agent communication layer, not just the application layer. Every MCP-based tool call can now carry XAA identity context.
The product's core value proposition is straightforward: short-term tokens instead of long-lived credentials, automatic rotation, least-privilege access, and a "human owner" accountability model. Every agent must have a designated human responsible for its actions.
The Core: What the Technical Analysis Reveals
Let me be precise about what XAA is and is not. It is not a new authentication protocol. It is a compositional innovation โ combining existing OAuth 2.0 standards and applying them to a new scenario: machine/agent workloads. The technical barrier to entry is low. Any competent identity team could replicate the protocol in weeks.
The real moat is integration depth. Okta's Universal Directory already contains the organizational identity graph for over 18,000 enterprise customers. Agent SSO plugs AI agents into that existing graph. The agent becomes another entity in the directory, subject to the same lifecycle management, policy enforcement, and audit trails as human employees.
This is the correct security direction. Long-lived API keys are the single largest vulnerability in non-human identity management. A leaked key is permanent until discovered. A short-term token with automatic rotation limits the blast radius of any single compromise to minutes, not years. This aligns with the broader industry trend โ Google's BeyondCorp, AWS IAM Roles Anywhere, and similar initiatives all push toward ephemeral credentials.
The security data supports the design choices. Organizations implementing least-privilege access for AI report a 17 percent incident rate. Those granting over-privileged access report 76 percent. The gap is not subtle. It is the difference between a manageable risk and a guaranteed breach.
But here is what the marketing materials do not tell you. The "open, vendor-neutral" XAA narrative has a commercial edge. Okta leads the standard's development. The evolution direction is tied to Okta's product roadmap. True neutrality would require formal adoption by an independent standards body โ OIDF or IETF โ as an RFC. That has not happened. NIST has launched an initiative, but no formal standard exists. The technical landscape is far from converged.
The decision to charge separately for "non-XAA agent" governance is revealing. It means legacy agents require an adaptation layer or reverse engineering. This is not just a technical distinction. It is a sales lever, pushing customers toward the new standard and away from existing deployments.
The Commercial Play: Open Core, Standard Lock-In
The bundling strategy is textbook open core. Basic XAA support is free to drive adoption and establish the standard. Advanced features โ shadow AI discovery, access certification for non-XAA agents, manual owner assignment โ are paid subscriptions. The genius is that Okta has turned what would normally require a separate budget line item into a free add-on to an existing contract. Procurement friction drops to zero.
The revenue growth comes from the standard itself. Every customer that adopts XAA becomes more deeply embedded in Okta's identity graph. Agent access policies, audit trails, and lifecycle management all bind to the platform. This is not just technical lock-in. It is standard lock-in. The cost of migrating to a competitor increases with every agent added to the system.
The competitive pressure on pure-play AI identity startups is severe. Companies like Clerk, WorkOS, and Auth0's AI identity offerings now face a free product from a company with 18,000 enterprise customers. The consolidation wave in this space is inevitable. Some will be acquired. Others will retreat to vertical niches.
The Competitive Landscape: Two Giants, One Standard
The real battle is between Okta and Microsoft Entra Agent ID. Microsoft has over 500 million monthly active users on Entra ID. Its AI toolchain โ Azure OpenAI, Copilot Studio, Semantic Kernel โ integrates seamlessly with Entra Agent ID. For enterprises already running AI workloads on Azure, the path of least resistance is Microsoft.
Okta's counter is neutrality. For multi-cloud, multi-SaaS enterprises that do not want to be locked into the Microsoft ecosystem, Okta offers a standardized, independent option. The MCP adoption of XAA is the key advantage โ MCP is model-agnostic, giving Okta a neutral high ground.
The alliance structure is telling. Cloudflare at the gateway layer. Slack at the collaboration layer. WorkOS at the API layer. Anthropic as the model partner. This is a coalition designed to counter Microsoft's platform dominance. The identity standard war is the projection of the AI model war. Whoever controls agent identity controls the enterprise AI stack.
The Contrarian Angle: Centralization Is the New Attack Surface
Here is the uncomfortable parallel that the enterprise security community does not want to discuss. Okta's Agent SSO centralizes AI agent identity management into a single platform. That platform becomes a high-value target. If Okta is compromised, an attacker gains control over thousands of agent identities simultaneously. This is the same single-point-of-failure problem that plagues centralized systems everywhere.
The crypto industry learned this lesson the hard way. The entire premise of decentralized identity is that no single entity should control the keys to the kingdom. The 2022 Okta security incident โ where a supplier breach exposed customer data โ demonstrated that even the best-funded identity providers are vulnerable. Agent SSO expands that attack surface significantly.
The "shadow AI discovery" feature is a double-edged sword. It identifies AI agents operating without formal approval. But it is also a tool for IT departments to expand surveillance over business units. The boundary between security and monitoring is dangerously blurry.
There is also a deeper structural issue. The competition between Okta and Microsoft Entra Agent ID is not really about identity. It is about model market share. Microsoft has OpenAI. Anthropic has aligned with Okta through XAA. The identity layer is the projection of the AI model war. Whoever controls agent identity controls the enterprise AI stack.
The Takeaway: The Ledger Remembers
The ledger remembers what the hype forgets. Every line of code is a legal precedent. The identity layer for AI agents is being built right now, and the decisions made in the next 18 months will determine who controls the digital workforce for the next decade.
Okta's bet is that open standards and vendor neutrality will beat platform lock-in. Microsoft's bet is that deep ecosystem integration will win. The crypto industry's bet โ if it makes one โ should be that decentralized identity protocols offer a third path. The question is whether the market will accept centralized identity for AI agents, or whether the security failures that plagued centralized systems in Web2 will repeat themselves.
Trust is a variable, not a constant. The data does not lie. The 90:1 ratio, the 76 percent incident rate, the 28 percent traceability โ these are the warning signs. The question is not whether AI agents will be deployed at scale. They already are. The question is whether the identity infrastructure supporting them will be built on sound principles or on the same fragile foundations that produced the last decade's breaches.
The bug was there before the launch. It always is.