from/prod
← All companies

THE COMPANY INDEX TRACKED BLOG

Okta

Ideas, decisions, and lessons from the team.

developer.okta.com (opens on the source site)LinkedIn X
9Posts tracked
2 days agoLatest publication
0.8Posts / month over the last 12 months

Latest writing

9 of 9 posts

Build a Secure TypeScript MCP Client with Cross App Access (XAA) (opens on the source site)

Enterprise apps rarely work alone. Imagine this scenario: HR wants to ensure that a new employee completes their new hire onboarding, and they want this verification in the company’s HR app so it’s tied to the employee’s personnel file. But the onboarding tasks come from a task-tracking tool with requirements defined by each department, from a different vendor and on a different domain than the HR app. It’s on IT to bridge the two. Wiring the two together normally costs the user an OAuth consent screen or costs IT a shared service account. Cross App Access (XAA) removes that step. The…

Read at the source

Classic Engine Feature EOL: SSR, Desktop SSO, Device Trust (opens on the source site)

Starting March 5, 2027, Okta ends support for a few capabilities on Classic Engine. Identity and security requirements continue to evolve. Organizations expect authentication experiences that are more secure, flexible, and adaptable to changing users, devices, and applications. Okta invests in Okta Identity Engine, the modern foundation for passwordless authentication, device assurance, phishing-resistant multifactor authentication, and adaptive security policies. By moving to Okta Identity Engine, you access an environment aligned with modern security practices that is stronger, more…

Read at the source

Supercharge Auth with Signals and the New Okta Angular SDK (opens on the source site)

Have you noticed that the Okta Angular SDK went fully standalone? There’s no NgModule left to import, no importProvidersFrom wrapper to remember, and the guards are plain functions now. If you’ve been waiting for the SDK to look like the rest of your standalone Angular app, this is the release you were waiting for. In this post, we’ll pick up a small Angular v22 project and finish it. We’ll make the following changes: Add authentication using the new provideOktaAuth provider function Protect a route with the SDK’s functional guard Load each user’s groups with rxResource and a signal input…

Read at the source

Add Cross App Access to Your OIDC Resource Application (opens on the source site)

If you currently federate enterprise customers using OpenID Connect (OIDC) and want to allow applications to access your API on behalf of those users, this Cross App Access (XAA) guide is for you. The Identity Assertion Authorization Grant specification, the basis of XAA, was designed with OIDC in mind. Your authorization server already trusts the customer’s IdP for single sign-on (SSO), and XAA reuses that same trust for API access. This guide details what you need to support, how to validate the grant, and how to resolve the user at your resource authorization server. Table of Contents How…

Read at the source

Add Cross App Access to Your OIDC Requesting Application (opens on the source site)

If you currently federate enterprise customers using OpenID Connect (OIDC) and want to connect with third-party applications, this Cross App Access (XAA) guide is for you. The Identity Assertion Authorization Grant specification, the basis of XAA, was designed with OIDC in mind. Your app already holds an ID token after sign-in, but it’s the refresh token from that same sign-in that you exchange to reach a third-party app. This guide details what you need to support and how to make resource requests to a third-party app using XAA. Table of Contents How XAA in OIDC works XAA implementation…

Read at the source

I Found My Coordinates: Code, Community, and Okta (opens on the source site)

It all started with a phone call from an institute that reached out to recruit me for its campus ambassador program. I was navigating my first year of college, figuring things out. It was all new for me, a new city, far from home, and a hostel room. I was not aware of anything except books and lectures. A senior at my campus ambassador program advised me to create a LinkedIn account and start looking for opportunities from day one. As they say, “You don’t have to be great to start, but you have to start to be great.” So I started applying for random internships. Soon, I received my first…

Read at the source

Build a Flask App with Okta for Secure OIDC Login and Authorized API Calls (opens on the source site)

Python syntax and the flexibility of the Flask microframework make it a popular choice for quickly building web applications. While Flask provides the essentials to get you started, you’ll need to tackle two critical pieces yourself: secure user authentication and authorization for your backend services. After all, how do you securely sign users into your application? And once they’re signed in, how does your app fetch data from a backend service that only serves authorized requests? This tutorial shows you how to solve both. You’ll build a Flask dashboard app that signs users in with Okta…

Read at the source

Enable Your SAML Requesting App for Cross App Access (opens on the source site)

If you currently federate enterprise customers using Security Assertion Markup Language (SAML) and want to connect with third-party applications without migrating to OpenID Connect (OIDC), this Cross App Access (XAA) guide is for you. The Identity Assertion Authorization Grant specification, the basis of XAA, was originally designed with OIDC in mind. To use it in SAML applications, you must accommodate specific security and uniqueness requirements. This guide details what you need to support and how to make resource requests to a third-party app using XAA. Table of Contents How XAA in SAML…

Read at the source

Build a Secure C# MCP App with Cross App Access (XAA) (opens on the source site)

A few years ago, getting a user signed in to an application or multiple applications with Single Sign-On (SSO) was enough; OpenID Connect (OIDC) handled the login, JWTs carried the claims, and Proof Key for Code Exchange (PKCE) made it secure. Today, with evolving AI, agents act on behalf of users and seek multiple accesses across different resources to execute a task. And that is when you’ll hit the gap. The user has an identity, but the downstream service—like a Model Context Protocol (MCP) server, an API, or an agent tool has no way to trust it: the ID Token that proves the user’s identity…

Read at the source

Privacy choices

Reading never requires analytics. These choices last 90 days on this browser.

Essential sign-in and security storage always stays on. Read the privacy notice.