AEMBIT has announced support for Okta’s Cross App Access (XAA), an open protocol designed to let an existing enterprise identity authorise access to approved downstream applications without requiring separate user consent for each connection. The announcement was made on 22 September 2026 at Oktane 2026 in Las Vegas, where Aembit said it had become an Okta XAA launch partner. The feature is being added to Aembit IAM for Agentic AI, which provides verified agent identities, policy-based access controls and audit records.
The companies say XAA can reduce the number of individual authorisation relationships created when AI agents work across collaboration, project-management, development and data platforms. Aembit will act as the policy enforcement point, allowing organisations to apply Okta identity and access policies to agent-driven connections while linking the user’s context to the verified identity of the agent. This is intended to show which agent acted, on whose behalf and under which policy.
Aembit says organisations can use XAA for supported services while retaining existing OAuth authorisation elsewhere, rather than requiring an immediate, all-or-nothing migration.
Support is provided through Aembit’s Enterprise-Managed Authorization Credential Provider, which implements the Model Context Protocol Working Group’s Enterprise-Managed Authorization extension. The provider operates alongside Aembit’s existing OAuth capabilities and is also intended to provide a common control layer for access to MCP servers, tools and enterprise resources. The announcement describes a product launch and does not report a security incident or confirmed exploitation.