AI Security

Okta puts identity in the agent tool path. Agent Gateway is the runtime bet.

Okta product blog + help docs. Identity-native proxy for MCP/tool calls. Short-lived brokered creds. Research release; APIs Beta Sep 16. Pricing Undisclosed. Kill standing API keys — or another gateway tax?

Sep 22, 2026 · 5 min read

Standing API keys in agent configs are the quiet breach pattern of 2026. Okta’s answer is to put identity in the request path.

Okta Agent Gateway, described in Okta’s product blog and Help Center, is an identity-native proxy between AI agents and the enterprise tools those agents call. It aggregates tools from remote MCP servers behind a single Okta-secured endpoint, authenticates the agent (and the user behind it), enforces policy on every tool call, and produces a unified audit trail. Downstream credentials are injected by Okta so the agent never directly holds them. Short-lived tokens replace long-lived keys. Instant revocation at the gateway is the operational punchline.

What it is not, per Okta: a replacement for your existing MCP or API gateway. Routing, rate limits, and connectivity stay where they are. Agent Gateway adds identity and policy on top. Teams point agent clients at the gateway endpoint. Okta claims no code changes to agents and no modifications to downstream systems. Named agent environments in the blog: Claude Code, Cursor, GitHub Copilot, Salesforce Agentforce, and agents that can target an MCP endpoint — plus Amazon Bedrock AgentCore in adjacent Okta AI Agents messaging. Treat platform lists as company-stated support, not as a CyberMerge compatibility matrix.

Credential patterns Okta documents today: Cross-App Access (XAA) for Okta-enabled resources, and brokered consent via Okta’s Secure Token Service (STS) for external systems such as GitHub and Slack. For regulated / on-prem constraints, Okta Professional Services offers MCP Bridge for similar enforcement inside customer infrastructure. Availability status matters for buyers: Okta’s July 2026 product innovations article offered Agent Gateway as a research release via the Research Partner Program; Agent-to-Agent Connections was called GA there; Resource Access Certifications for AI Agents was Early Access. Okta Developer Identity Engine release notes list Agent Gateway APIs as Beta expected in Preview orgs on September 16, 2026. The Oktane 2026 press release planned Agent Gateway generally available in Q3. Pricing and attach economics: Undisclosed.

Why this lands on today’s Featured slate. The public tape is full of agent-control narratives — Cyera’s Goldman-backed “trust layer,” Outerlimit’s $16M action-layer pre-seed, Darktrace / SECURE AI GA elsewhere on the wire. Okta’s wedge is different: it already owns enterprise identity for many buyers, and it is extending that control plane into runtime tool calls. The failure mode it attacks is concrete and sourced in Okta’s own blog vignette — a developer drops a GitHub PAT and a Slack token into an agent config; standing access; no attribution; poisoned prompt takes the tokens with it.

Competitive framing (share Undisclosed). Traditional API/MCP gateways route traffic. Identity-native gateways attribute who acted, for whom, under what policy, at the moment of execution — Okta’s comparison table says as much. Startups will sell specialized agent authorization fabrics. Cloud providers will bolt policy onto their agent runtimes. Okta’s bet is that the IdP stays in the path. Boards should ask: which agents are already discovered; which tool calls already flow through Okta; what happens when a kill switch fires mid-session (Oktane materials discuss expanding kill-switch to the gateway). Attach rates: Undisclosed.

POV: Runtime identity for agents is becoming a category, not a feature checkbox. Research release + API Beta is not the same as ubiquitous GA. Underwrite revoke latency, attribution quality, and whether security teams will accept another hop — before you pay for the narrative.

Underwrite sheet — sourced only: Okta Agent Gateway identity-native proxy (Okta blog / Help); MCP aggregation; short-lived brokered credentials; no agent code changes (company); XAA + STS brokered consent; MCP Bridge via Professional Services; research release (July 2026 Okta article); Agent Gateway APIs Beta Sep 16, 2026 (Okta Developer notes); planned GA Q3 (Oktane 2026 press); pricing Undisclosed. Kill standing keys — or another gateway tax?

Sources