Eventually week’s Oktane convention in Las Vegas, Okta unveiled its formidable imaginative and prescient for remodeling the Okta platform right into a management aircraft for AI brokers and increasing deeper into AI safety. The technique was mirrored all through the occasion’s keynotes and product bulletins, which centered closely on agent id, runtime authorization, agent-to-agent interactions, and ecosystem collaboration.
In his opening keynote, Okta CEO Todd McKinnon emphasised that open requirements and collaboration are essential to scale AI, acknowledging that no single vendor can govern and safe the agent ecosystem alone. The announcement of the Blueprint Alliance, a coalition of distributors with experience in quite a lot of areas, underscored this level. (Blueprint Alliance is a multi-vendor, open IAM for AI brokers’ structure that has agent governance, id administration, authorization, and interoperability elements.) The Blueprint Alliance intends to coordinate with different distributors on how you can construct interoperable id infrastructures. There’s additionally a possibility for Okta / Auth0 to increase the Blueprint Alliance to CIAM and eCommerce and loyalty applications sooner or later. It additionally highlights that the success of Okta’s technique in the end is determined by whether or not the safety, and particularly the IAM/Identification Safety trade converges round widespread requirements for agent id, belief propagation, authorization, and accountability.
Okta is productizing their IAM for brokers technique and planning to unify all (human, NHI, and agentic) id administration right into a single management aircraft. Okta sees agent authentication and session administration being completely different from human authentication and session administration. Dynamic AI agent authorization primarily based on intent and context had been heart stage in bulletins.
Highlights: In collaboration with Anthropic and different distributors, Okta has been actively creating the Cross Software Entry (XAA) and Enterprise Managed Entry specs which are actually a part of the MCP Authorization Extensions (issued by Anthropic, primarily based on OAuth 2.1, however not but a part of requirements issued by a requirements physique). Keenly believing in open requirements and protocols, Okta has been selling trade collaboration and coopetition. At Oktane, Okta was additionally in a position to usher in panelists from respected North American monetary establishments to explain their IAM for AI brokers’ journey.
Challenges: SPIFFE has been changing into the de-factor requirements for non-human identities. Okta nonetheless doesn’t have a full SPIFFE agent id implementation – like Aembit or Teleport, for instance – (Okta has help for SPIFFE-based authentication on the roadmap for This autumn 2026) and nonetheless have disclosed any plans for any common know-your-agent (KYA) requirements or frameworks. On condition that the Auth0 (CIAM) and Okta workforce IAM stacks have completely different session administration and AI agent administration capabilities, not having a unified platform will increase the seller’s product improvement prices. It additionally will increase enterprises’ price of constructing a unified workforce and CIAM infrastructure with equal-strength, and interoperable human and non-human identities. The seller’s technique for utilizing the prevailing High quality Grained Authorization resolution for AI brokers appears unclear. Lastly, Okta’s pricing for IAM for AI brokers continues to be unresolved, as a substitute of month-to-month energetic person (MAU) primarily based pricing (widespread with human IAM), it probably can be transaction primarily based.
Alternatives: Okta might play an necessary function in creating foundations for intent discovery and authorization determination making – areas the place there aren’t any mature requirements right now. Constructing vendor-agnostic reference architectures for human, non-human, and agentic AI id administration for purchasers is probably going – the Blueprint Alliance is an efficient first step on this path. Okta can also be venturing into the CIEM area with AWS admin id evaluation, full with entry request administration. Verifying human to agent supplier (utilizing OAuth 2.0), agent supplier + agent to service supplier belief will assist total agent adoption.
Forrester purchasers serious about discussing IAM for AI Brokers, please e-book an inquiry or steering session with us.


