logo
Okta introduces Cross App access to help secure AI agents in the enterprise

Okta introduces Cross App access to help secure AI agents in the enterprise

Time of India5 days ago

Okta, Inc., the leading independent identity partner, today announced Cross App Access, a new protocol to help secure AI agents. As an extension of OAuth, it brings visibility and control to both agent-driven and app-to-app interactions, allowing IT teams to decide what apps are connecting and what information AI agents can access.Why it matters:
More AI tools are using protocols like Model Context Protocol (MCP) and Agent2Agent (A2A) to connect their AI learning models to relevant data and apps within the enterprise. However, for connections to be established between agents and apps, such as Google Drive or Slack, users need to manually log in and consent to grant the agent access to each integration.
These app-to-app connections occur without oversight, with IT and security teams having to rely on manual and inconsistent processes to gain visibility. This creates a big blind spot in enterprise security and expands an increasingly unmanaged perimeter.
This challenge will be amplified with the explosion of AI agents, which are introducing new, non-deterministic access patterns, crossing system boundaries, triggering actions on their own, and interacting with sensitive data.
Today's security controls aren't equipped to handle their autonomy, scale, and unpredictability. Existing identity standards are not designed for securing an interconnected web of services and applications in the enterprise – and while MCP improves transparency and communication between agents, it doesn't help manage access.
"While we're actively working with the MCP and A2A communities to improve AI agents' functionality, their increased access to data and the explosion of app-to-app connections will create new identity security challenges,' said Arnab Bose, Chief Product Officer, Okta Platform at Okta. "With Cross App Access, Okta is excited to bring oversight and control to how agents interact across the enterprise. Since protocols are only as powerful as the ecosystem that supports them, we're also committed to collaborating across the software industry to help provide agents with secure, standardized access to all apps.'
What we're introducing - Cross App Access
Okta, working with industry-leading ISVs, is launching Cross App Access to help ISVs deliver secure, enterprise-ready integrations in an AI-powered world. Anticipated to be available for select Okta Platform customers as a feature in Q3 of this year, it will enable ISV's enterprise customers to better connect their AI tools to other apps and data, deliver more seamless experiences for the end user by removing repetitive authorization consent screens, and manage agent access for better security and compliance.
For example, an AI tool may need to access an internal communication app to retrieve information or take action on a user's behalf. Without Cross App Access, the user must log into the AI tool via their company's SSO and then manually approve each integration, logging into and consenting to the internal communication app separately. This process would then need to be repeated for other necessary applications, such as a file storage service or a project management application. Each consent and access is invisible to the enterprise customer.
With Cross App Access, the AI tool can instead request access to the internal communication app from Okta, which evaluates the request against enterprise policies and determines whether the tool is authorized to access that specific user's internal communication app data. If permitted, Okta issues a token to the AI tool, which it presents to the internal communication app for validation. Once validated, the internal communication app provides access—all without additional user interaction, and under enterprise-defined security controls. The enterprise has visibility into when the AI tool accesses the internal communication app on behalf of the user.
What challenges does this solve for ISVs?
ISVs face growing pressure to support secure, seamless cross-app experiences for their enterprise customers, but the underlying identity and access flows are often inconsistent, fragmented, and hard to scale. These integrations typically rely on risky token exchanges and user-granted access, leading to token sprawl and visibility gaps. As AI agents begin to autonomously connect across systems, this complexity and the risk only increases.
How Cross App access can help: Cross App Access enables ISVs to deliver secure, enterprise-grade integrations for AI agents and other autonomous systems, such as workflow automation tools. By shifting access control to the identity provider, like Okta, ISVs can reduce security risks, simplify integration complexity, and better support their customers' compliance and governance needs.
What challenges does this solve for enterprises?
Integrating AI tools with existing data and systems presents significant hurdles. Many businesses currently rely on ad hoc methods like long-lived tokens and fragmented access controls, making these integrations inherently risky. AI adoption is being stalled by this lack of visibility and control over how agents access data across apps.
Beyond security, the user experience is also impacted when agents can't act seamlessly on behalf of users, due to repetitive and outdated authorization flows.
How Cross App access can help: With Cross App Access, enterprises can enhance security and usability, empowering IT to manage agent access while enabling seamless, low-friction experiences for users. It supports secure interoperability between apps and AI systems, making it easier to adopt innovative ISV solutions without compromising oversight or performance.

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Canva now works directly inside ChatGPT with new integration: How it works for users
Canva now works directly inside ChatGPT with new integration: How it works for users

Mint

time3 days ago

  • Mint

Canva now works directly inside ChatGPT with new integration: How it works for users

Design platform Canva has announced two major product updates aimed at integrating its tools directly into artificial intelligence ecosystems. The company has rolled out a deep research connector for ChatGPT and introduced the Canva Model Context Protocol (MCP) Server, allowing AI assistants to access and generate designs using real-time user context. The deep research connector links Canva accounts with ChatGPT, enabling the AI assistant to pull from a user's existing design materials, such as presentations, brand documents, and reports. This allows for content analysis and generation within the same conversation, eliminating the need to switch between platforms or manually input references. This functionality targets professional users across industries. Marketers can extract messaging from campaign materials; business users can analyse planning documents; sales teams can prepare proposals using prior customer data; and educators can incorporate previous lesson content into new teaching material. In parallel, Canva has launched the MCP Server, a backend infrastructure that allows AI assistants to access a user's full design workspace, including templates, charts, and historical content. It supports features like generating on-brand visuals, resizing templates, importing PDFs via URL, and filling charts with formatted data generated by AI. These integrations are compatible with platforms including ChatGPT and Salesforce's Agentforce, with more expected to follow. According to the company, the tools are designed to operate within existing AI environments, turning Canva into a directly pluggable design component in broader digital workflows. The company said that the new features are secured under its internal AI safety framework, Canva Shield, which governs data access and privacy for users interacting with external AI tools. Notably, the launch comes as Canva continues to expand its AI offerings, which now include Canva AI, Canva Code, and AI-powered features in tools such as Canva Sheets.

Canva brings its design suite to ChatGPT with MCP server launch
Canva brings its design suite to ChatGPT with MCP server launch

Indian Express

time3 days ago

  • Indian Express

Canva brings its design suite to ChatGPT with MCP server launch

Canva has become the first design platform to integrate its full creative tools into ChatGPT, marking a significant milestone in AI-powered productivity. The launch includes two major tools: a deep research connector for ChatGPT and the Canva Model Context Protocol (MCP) server, enabling AI agents to access and generate Canva content in real time, said the company in a press release. The deep research connector allows users to interact with their past Canva designs directly within ChatGPT. In this way, the feature streamlines creative workflows without switching platforms, from summarising presentations to generating templates. Canva's AI integration is already gaining momentum – usage of Canva GPT has increased 375 per cent year-over-year, making it one of ChatGPT's most-used productivity tools. The second innovation, the MCP server (which is a tool that helps AI models better understand and share data with applications), introduces a backend system that gives AI assistants secure, real-time access to a user's Canva workspace. Unlike traditional APIs, the MCP server continuously shares relevant information between the AI assistant and Canva. This enables the assistant to generate better content faster based on ongoing conversations and past designs. With these tools in place, AI assistants can autofill templates, generate charts with formatted data, and import files from links – all without leaving the chat. The result is more fluid and offers an intelligent design experience. 'We're embedding Canva directly into the AI tools people use every day so they can brainstorm, create, and publish content faster,' said Anwar Haneef, GM and Head of Ecosystem at Canva. 'This is a major step in our vision to make the complex simple.' All interactions are protected by Canva Shield, the company's AI trust and safety framework. Users and developers can begin integrating Canva's capabilities into their AI tools through the Canva Developers community. (This article has been curated by Arfan Jeelany, who is an intern with The Indian Express)

Google releases Gemini CLI: A free AI powered command line for developers
Google releases Gemini CLI: A free AI powered command line for developers

Hindustan Times

time4 days ago

  • Hindustan Times

Google releases Gemini CLI: A free AI powered command line for developers

Jun 26, 2025 06:59 PM IST Google has launched Gemini CLI, an open-source AI-powered command line interface to revolutionise how developers interact with terminals. By integrating Gemini access directly into the terminal, Gemini CLI can streamline coding, debugging, automation and cloud operations through natural language commands. AI meets the command line, Google's Gemini CLI makes coding and cloud work effortlessly.(Google) Gemini CLI is an open-source project by Google available on GitHub, offering an intelligent AI assistant right into the terminal. It uses the capabilities of Google's Gemini AI models to help users code, debug, manage files, automate tasks and interact with Google Cloud services just with simple conversational prompts. AI-Powered coding and debugging: Gemini CLI can easily generate and debug code snippets. It can also answer technical questions and even help with complex tasks like code migration using natural conversational prompts. Integrate Google search: Google's new CLI can fetch real-time documentation and web results. This helps the developer to access relevant information without moving away from the terminal. Cloud operations: Users can deploy applications, manage resources and configure the cloud environment right from the command line. Automate tasks: Gemini CLI can automate repetitive tasks and run scripts automatically. Customisable: It is highly customisable for both individual uses and team workflows because it is open source and built on the Model Context Protocol (MCP). Free access: The tool is free to use for developers, offering generous usage limits in the preview phase. It offers up to 60 model requests per minute and 1000 requests per day. Daily coding tasks like writing, reviewing and debugging code can be done easily, and it can answer technical questions. It can help deploy an application to Google Cloud Run or App Engine. It can manage virtual machines, databases and other resources with simple commands. With web search and AI integration, it can quickly search for documentation or troubleshoot errors. Gemini CLI is a big leap in developer productivity, merging the terminal's flexibility with Artificial Intelligence. By making advanced coding, automation and cloud management accessible and free, Google is setting a new standard for what command line tools can achieve.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store