# Cross-App Access (XAA)

**Canonical:** https://apis.io/apis/okta/okta-cross-app-access/  
**Provider:** Okta — https://apis.io/providers/okta/  
**Base URL:** https://xaa.dev  
**Documentation:** https://xaa.dev/

Cross-App Access (XAA) is one of 28 APIs that [Okta](https://apis.io/providers/okta/) publishes on the [APIs.io](https://apis.io/) network. Tagged areas include Cross-App Access, AI Agents, Authentication, ID-JAG, and Authorization. The published artifact set on APIs.io includes API documentation and an engineering blog.

Cross-App Access is Okta's emerging OAuth profile for secure agent-to-app and app-to-app authorization, based on the IETF draft "OAuth Identity Assertion Authorization Grant" (ID-JAG, draft-ietf-oauth-identity-assertion-authz-grant). It lets an Identity Provider mint an identity assertion that downstream resource applications can exchange for a scoped access token, eliminating long-lived unmanaged credentials between AI agents and SaaS apps. Okta operates xaa.dev as a public sandbox for testing requesting and resource application implementations.

## Machine-readable artifacts (27)

- **Documentation** — https://xaa.dev/
- **Specification** — https://datatracker.ietf.org/doc/html/draft-ietf-oauth-identity-assertion-authz-grant
- **Sandbox** — https://xaa.dev/
- **Blog** — https://developer.okta.com/blog/2026/01/20/introducing-xaadev-a-playground-for-cross-app-access
- **Blog** — https://developer.okta.com/blog/2026/02/10/make-secure-app-to-app-connections-using-cross-app-access
- **APIsJSON** — https://raw.githubusercontent.com/api-evangelist/okta/refs/heads/main/apis.yml
- **Arazzo** — https://raw.githubusercontent.com/api-evangelist/okta/refs/heads/main/arazzo/okta-assign-admin-role-to-group-workflow.yml
- **Arazzo** — https://raw.githubusercontent.com/api-evangelist/okta/refs/heads/main/arazzo/okta-assign-admin-role-to-user-workflow.yml
- **Arazzo** — https://raw.githubusercontent.com/api-evangelist/okta/refs/heads/main/arazzo/okta-assign-group-to-application-workflow.yml
- **Arazzo** — https://raw.githubusercontent.com/api-evangelist/okta/refs/heads/main/arazzo/okta-create-and-activate-application-workflow.yml
- **Arazzo** — https://raw.githubusercontent.com/api-evangelist/okta/refs/heads/main/arazzo/okta-create-and-activate-authenticator-workflow.yml
- **Arazzo** — https://raw.githubusercontent.com/api-evangelist/okta/refs/heads/main/arazzo/okta-create-and-activate-group-rule-workflow.yml
- **Arazzo** — https://raw.githubusercontent.com/api-evangelist/okta/refs/heads/main/arazzo/okta-create-and-refresh-session-workflow.yml
- **Arazzo** — https://raw.githubusercontent.com/api-evangelist/okta/refs/heads/main/arazzo/okta-create-app-assign-user-and-activate-workflow.yml
- **Arazzo** — https://raw.githubusercontent.com/api-evangelist/okta/refs/heads/main/arazzo/okta-create-group-and-add-members-workflow.yml
- **Arazzo** — https://raw.githubusercontent.com/api-evangelist/okta/refs/heads/main/arazzo/okta-create-policy-with-rule-workflow.yml
- **Arazzo** — https://raw.githubusercontent.com/api-evangelist/okta/refs/heads/main/arazzo/okta-create-user-with-group-membership-workflow.yml
- **Arazzo** — https://raw.githubusercontent.com/api-evangelist/okta/refs/heads/main/arazzo/okta-deactivate-and-delete-user-workflow.yml
- **Arazzo** — https://raw.githubusercontent.com/api-evangelist/okta/refs/heads/main/arazzo/okta-enroll-and-activate-factor-workflow.yml
- **Arazzo** — https://raw.githubusercontent.com/api-evangelist/okta/refs/heads/main/arazzo/okta-find-user-and-assign-app-workflow.yml
- **Arazzo** — https://raw.githubusercontent.com/api-evangelist/okta/refs/heads/main/arazzo/okta-find-user-and-suspend-workflow.yml
- **Arazzo** — https://raw.githubusercontent.com/api-evangelist/okta/refs/heads/main/arazzo/okta-offboard-user-clear-sessions-workflow.yml
- **Arazzo** — https://raw.githubusercontent.com/api-evangelist/okta/refs/heads/main/arazzo/okta-onboard-user-to-group-and-app-workflow.yml
- **Arazzo** — https://raw.githubusercontent.com/api-evangelist/okta/refs/heads/main/arazzo/okta-provision-admin-user-workflow.yml
- **Arazzo** — https://raw.githubusercontent.com/api-evangelist/okta/refs/heads/main/arazzo/okta-reactivate-suspended-user-workflow.yml
- **Arazzo** — https://raw.githubusercontent.com/api-evangelist/okta/refs/heads/main/arazzo/okta-reset-and-reenroll-factor-workflow.yml
- **Arazzo** — https://raw.githubusercontent.com/api-evangelist/okta/refs/heads/main/arazzo/okta-update-group-rule-expression-workflow.yml

## Other Okta APIs (12)

- [Okta for AI Agents](https://apis.io/apis/okta/okta-for-ai-agents/)
- [Okta Application API](https://apis.io/apis/okta/okta-application-api/)
- [Okta Authenticator API](https://apis.io/apis/okta/okta-authenticator-api/)
- [Okta AuthorizationServer API](https://apis.io/apis/okta/okta-authorizationserver-api/)
- [Okta Brand API](https://apis.io/apis/okta/okta-brand-api/)
- [Okta Domain API](https://apis.io/apis/okta/okta-domain-api/)
- [Okta EventHook API](https://apis.io/apis/okta/okta-eventhook-api/)
- [Okta Feature API](https://apis.io/apis/okta/okta-feature-api/)
- [Okta Group API](https://apis.io/apis/okta/okta-group-api/)
- [Okta GroupSchema API](https://apis.io/apis/okta/okta-groupschema-api/)
- [Okta IdentityProvider API](https://apis.io/apis/okta/okta-identityprovider-api/)
- [Okta InlineHook API](https://apis.io/apis/okta/okta-inlinehook-api/)

## Tags

Cross-App Access, AI Agents, Authentication, ID-JAG, Authorization

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/okta/okta-cross-app-access/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/okta/.
