Solutions  ·  2026-10-12

Okta Agent Gateway reaches GA — identity-native runtime enforcement for AI agent-to-tool calls

SolutionsHigh impactGlobal
On Oct 8, 2026 Okta announced that Agent Gateway, the runtime enforcement layer within Okta for AI Agents, is now generally available. It validates every agent-to-tool (MCP) call against identity policies using RFC 8693 token exchange and will not process a request unless the credential names BOTH the acting agent and the human user, preventing confused-deputy attacks and unauthorized permission inheritance. It also isolates credentials at the moment of action and produces a unified audit trail.
This is one of the first major identity-vendor GA enforcement points that treats the agent-plus-user pair as the unit of authority — directly addressing the confused-deputy gap that plagues existing MCP gateways. For enterprises with agents on Claude Code/Copilot/Codex, it converts agent governance from logging to real runtime denial.
Enterprises using Okta for AI Agents that connect agents to MCP servers and SaaS tools should enable Agent Gateway for agent-to-tool runtime policy enforcement now that it is GA.
Okta Blog — Securing AI agents at runtime with Okta's Agent Gateway
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →