# What happened Aembit, an identity and access management (IAM) vendor for AI agents, announced support for Okta's Cross App Access (XAA). The company launched as an Okta partner for XAA at Oktane 2026. The integration lets enterprises use their existing Okta identity to authorize agent-driven access to downstream apps without asking users to grant consent for each connection.
# Why this matters Agentic AI workflows often move across multiple services during a single task. That multiplies access relationships security teams must govern and creates repeated consent steps for users. Aembit combines XAA's streamlined authorization model with its own controls so organizations can reduce operational friction while keeping a single enforcement and audit point for agent access.
# What Aembit provides with XAA support
- Reduce authorization sprawl: Users can rely on enterprise single sign-on (SSO) for approved agent workflows instead of reauthorizing each service.
- Central policy enforcement: Security teams apply identity and access policies to agent-driven connections through Aembit rather than leaving decisions to individual users.
- Blended identity and accountability: Aembit links user context with a verified agent identity to show which agent acted, on whose behalf, and under which policy.
Aembit implements XAA through an Enterprise-Managed Authorization Credential Provider that follows the Model Context Protocol Working Group's Enterprise-Managed Authorization extension. This runs alongside Aembit's existing OAuth capabilities to provide a consistent control layer across environments with varying XAA support.
# What the company said
# Practical implications for security teams Security teams get a single enforcement point for agent access to MCP servers, tools, and enterprise resources. That reduces the need to manage authorization separately for every connection and helps preserve an audit trail tying agent actions back to user context and policy decisions.
# How organizations can adopt it Enterprises already using Okta can enable agent workflows that use XAA where supported and continue to rely on existing OAuth flows for other services. Aembit's credential provider gives a migration path that mixes both approaches while keeping centralized policy enforcement.
# Where to learn more Aembit points users to aembit.io for details on the integration and product information.
# Bottom line Aembit's XAA support aims to simplify authorization for agent-driven workflows by extending enterprise identity controls to AI agents while retaining centralized enforcement, blended identity for accountability, and an incremental adoption path that coexists with OAuth.