Blank white background with no objects or features visible.

We’re sharing complimentary access to the full Gartner Hype Cycle for AI Governance 2026. Get your copy →

TrueFoundry Joins Okta's Cross App Access Ecosystem to Bring Identity-Governed AI to the Enterprise AI Gateway

By TrueFoundry

Published: September 30, 2026

As AI agent adoption grows across the enterprise, so does the need for governance and secure connectivity. Agents require controlled access to the tools and systems they depend on, while platform and security teams need to retain visibility and control at scale.

TrueFoundry has joined the Cross App Access (XAA) ecosystem to help close that gap. XAA allows agent access to be governed by the same identity policies an organization already applies to its employees. This removes much of the security review and custom governance work that currently slows enterprise AI deployments.

The access problem with agents today

Most agents running in production authenticate using static API keys. Those keys typically do not expire, they are rarely scoped to a particular task, and produce little in the way of an audit trail. This leaves IT teams with limited visibility into what an agent actually accessed and when. Okta's research suggests this is already having consequences: 88% of organizations report confirmed or suspected AI agent security incidents, and 92% of those that experienced an AI-related breach did not have adequate AI access controls in place.

How Cross App Access works

Cross App Access, formally known as the Identity Assertion Authorization Grant, is an open protocol that extends OAuth and has been incorporated into MCP as an authorization extension. It is vendor-neutral and designed to work across cloud providers, frameworks, and SaaS applications.

Static key grants broad standing access and XAA issues a short-lived token scoped to the specific task an agent is carrying out. The token is issued in real time against the user's active Okta identity, it can be revoked at any point, and it is logged so the access remains auditable after the fact. Agent connections are evaluated against the organization's central identity policy in the same way a human user's access would be.

What this changes for platform and security teams

  • Existing identity policy extends to agents. Teams inherit the access rules they have already defined in Okta. After this, there is no separate governance framework to design and maintain for AI.
  • A shorter path to production. Because agent access is governed through an identity system the security team already trusts, the review that often holds up agent deployments becomes considerably simpler.
  • Less consent friction for end users. Users encounter fewer repeated OAuth prompts while the underlying access remains scoped and revocable.
  • Consistent access across the stack. Agents connect to the tools a team already uses under the same identity standards that govern the workforce.

Why TrueFoundry Adopted XAA

TrueFoundry sits directly in the path of agent traffic. Requests from agents pass through the gateway, through MCP servers, and through the orchestration layer, which makes it a natural place to apply identity and policy consistently. With XAA support, that traffic is evaluated against Okta's identity and policy engine, giving teams a standardized way to govern agent access at enterprise scale.

For developers building on TrueFoundry, access control is inherited from Okta rather than implemented project by project. That removes the need to build and maintain a separate governance layer alongside the application itself.

"Organizations shouldn't have to choose between adopting AI tools and maintaining visibility over enterprise access," says Aaron Parecki, Senior Director of Identity Standards at Okta. "By connecting apps with the Cross App Access protocol, security teams get more control and users get a better experience without all the OAuth consent prompts."

What This Means for TrueFoundry Customers

Agents can now interact with TrueFoundry without static keys and without repeated manual consent prompts. Access is governed by the Okta policies an organization already has in place, scoped to the task being performed, and auditable in real time.

Get Started

Cross App Access is included in your Okta workforce SSO plan. Agent SSO brings XAA into Okta workforce plans at no extra cost, treating agents as first-class identities. Learn more about Cross App Access →

See TrueFoundry's integration in the Okta Integration Network (OIN). Link

Try now.

One gateway for all your models, MCP servers, and agents.
No credit card needed.

Start free
Table of Contents

One Gateway for Every LLM, Agent and MCP Server

Book a 30-min with our AI expert

Book a Demo

The fastest way to build, govern and scale your AI

Book Demo
Summarize with
ChatGPT logo by OpenAI
Perplexity AI logo
Blurry red snowflake on white background, symmetrical frosty design with soft edges and abstract shape.

Discover More

No items found.
September 30, 2026
|
5 min read

TrueFoundry Joins Okta's Cross App Access Ecosystem to Bring Identity-Governed AI to the Enterprise AI Gateway

No items found.
September 30, 2026
|
5 min read

9 Takeaways from Gartner® 2026 Hype Cycle™ for AI Governance Technologies

No items found.
September 30, 2026
|
5 min read

What Is an AI Governance Framework?

No items found.
TrueFoundry AI gateway supports prompt engineering governance in enterprise deployments
September 30, 2026
|
5 min read

Top Prompt Engineering Techniques: A Practical Guide for Enterprise Teams

No items found.
No items found.

Recent Blogs

Black left pointing arrow symbol on white background, directional indicator.
Black left pointing arrow symbol on white background, directional indicator.
Take a quick product tour
Start Product Tour
Product Tour