# Okta

**Canonical:** https://apis.io/providers/okta/  
**Website:** https://www.okta.com/  
**APIs profiled:** 28

Okta is the workforce identity incumbent — its Identity Cloud platform (also called the Okta Workforce Identity Platform) covers Single Sign-On, Adaptive MFA, Universal Directory, Lifecycle Management, Identity Governance, Privileged Access, Device Access, Identity Threat Protection, Identity Security Posture Management, Access Gateway, and API Access Management. Customer identity is handled by Auth0, which Okta acquired in 2021 and now operates as its consumer-facing identity arm. The platform now extends to securing AI agents via Okta for AI Agents and the Cross-App Access (XAA) protocol — an emerging OAuth profile based on the IETF ID-JAG draft for agent-to-app authorization. The Okta Management API is the primary developer surface, with an official MCP server (okta-mcp-server) exposing administrative operations to LLM agents under human-in-the-loop confirmation.

## Kin Score — 57.5 / 100 (strong)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 57.5).

| Facet | Score |
|---|---|
| Discoverability | 59.3 |
| Contract Quality | 77.8 |
| Governance | 13.6 |
| Contract Governance | 13.6 |
| Operational Transparency | 42.1 |
| Developer Ergonomics | 73.8 |
| Commercial Clarity | 51.3 |
| Access Clarity | 51.3 |

## Agent readiness — 34.4 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | documented |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | derived |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Paid · Self-serve signup — onboarding: self-serve, pricing: paid, trial: no (confidence: high).

## APIs (28)

- **Cross-App Access (XAA)** — Cross-App Access is Okta's emerging OAuth profile for secure agent-to-app and app-to-app authorization, based on the IETF draft "OAuth Identity Assertion Authorization Grant" (I...
- **Okta for AI Agents** — Okta for AI Agents secures the full lifecycle of AI agents — discovery, registration with mandatory human ownership, least-privilege scope enforcement, runtime monitoring, and i...
- **Okta Application API** — The Application API from Okta — 31 operation(s) for application.
- **Okta Authenticator API** — The Authenticator API from Okta — 4 operation(s) for authenticator.
- **Okta AuthorizationServer API** — The AuthorizationServer API from Okta — 21 operation(s) for authorizationserver.
- **Okta Brand API** — The Brand API from Okta — 15 operation(s) for brand.
- **Okta Domain API** — The Domain API from Okta — 4 operation(s) for domain.
- **Okta EventHook API** — The EventHook API from Okta — 5 operation(s) for eventhook.
- **Okta Feature API** — The Feature API from Okta — 5 operation(s) for feature.
- **Okta Group API** — The Group API from Okta — 16 operation(s) for group.
- **Okta GroupSchema API** — The GroupSchema API from Okta — 1 operation(s) for groupschema.
- **Okta IdentityProvider API** — The IdentityProvider API from Okta — 16 operation(s) for identityprovider.
- **Okta InlineHook API** — The InlineHook API from Okta — 5 operation(s) for inlinehook.
- **Okta LinkedObject API** — The LinkedObject API from Okta — 2 operation(s) for linkedobject.
- **Okta Log API** — The Log API from Okta — 1 operation(s) for log.
- **Okta NetworkZone API** — The NetworkZone API from Okta — 4 operation(s) for networkzone.
- **Okta Org API** — The Org API from Okta — 14 operation(s) for org.
- **Okta Policy API** — The Policy API from Okta — 8 operation(s) for policy.
- **Okta ProfileMapping API** — The ProfileMapping API from Okta — 2 operation(s) for profilemapping.
- **Okta Session API** — The Session API from Okta — 3 operation(s) for session.
- **Okta Subscription API** — The Subscription API from Okta — 6 operation(s) for subscription.
- **Okta Template API** — The Template API from Okta — 2 operation(s) for template.
- **Okta ThreatInsight API** — The ThreatInsight API from Okta — 1 operation(s) for threatinsight.
- **Okta TrustedOrigin API** — The TrustedOrigin API from Okta — 4 operation(s) for trustedorigin.
- **Okta User API** — The User API from Okta — 36 operation(s) for user.
- **Okta UserFactor API** — The UserFactor API from Okta — 7 operation(s) for userfactor.
- **Okta UserSchema API** — The UserSchema API from Okta — 2 operation(s) for userschema.
- **Okta UserType API** — The UserType API from Okta — 2 operation(s) for usertype.

## MCP servers (1)

- **Okta MCP Server**

## Agentic access (1)

- **Okta Agentic Access** — 341 operations · 210 acting · 15 human-in-the-loop

## Security (4)

- **Okta Authentication** — apiKey · 1 scheme
- **Okta Domain Security** — TLSv1.3 · HSTS · DMARC
- **Okta Vulnerability Disclosure** — Bugcrowd · security.txt · contact published
- **Okta Trust Center** — SOC 2, ISO 27001, ISO 27017, ISO 27018, PCI DSS, HIPAA, FedRAMP, GDPR, CSA STAR, FIPS 140

## Plans (1)

- **Okta Plans Pricing**

## Tags

Identity, Workforce Identity, Customer Identity, Authentication, Authorization, Single Sign-On, Multi-Factor Authentication, Identity Governance, Privileged Access, AI Agents, Cross-App Access, MCP, Platform

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/okta/). Scores are computed from the provider's own public artifacts under a published rubric.
