Connect AI agents to resources
Connect an AI agent to a resource through a resource connection.
Before you begin
- You have an admin role with permission to manage AI agents and their resources.
- If you want to connect AI agents to secrets or service accounts, you have the Okta Privileged Access security admin role.
- You've completed the configuration tasks for the resources that you want to use. See AI agent resource connections.
- You've registered an AI agent in your org.
Start this task
- In the Admin Console, go to .
- Select an AI agent.
- Select the Resource connections tab.
- Click Add resource connection.
- Select a resource type.
- Authorization server: Select an authorization server from the dropdown list. Select Allow all to grant all available scopes to the AI agent. Or, select Only allow or Disallow and enter the scopes that you want to grant or deny the AI agent.
- Secret: Select the secret that you want to use, and then accept or modify the Resource Indicator. This is the identifier that the AI agent uses when it requests the secret from Okta.
- Service account: Select an app and a service account, and then accept or modify the Resource Indicator. This is the identifier that the AI agent uses when it requests the service account from Okta.
-
Application: Select App configured for AI agent access
or Custom resource server. Then select an app instance or custom resource
server, respectively.
- If you selected a custom resource server, the Resource indicator populates automatically. If you selected an app that's configured for AI agent access, enter its client ID.
- For apps that are configured for AI agent access, select Allow all to grant all available OAuth scopes to the AI agent. Or, select Only allow or Disallow and select the scopes that you want to grant or deny the AI agent.
- MCP server: Select an MCP server from the list. The Resource Indicator populates automatically.
- Connect to another AI agent: Select an AI agent from the list.
- If the AI agent already has a delegation link, the Authorization server and Audience/resource URL populate automatically. If the AI agent doesn't have a delegation link, select an Authorization server and enter the Audience/resource URL.
- Select Allow all to grant all available OAuth scopes to the AI agent. Or, select Only allow or Disallow and select the scopes that you want to grant or deny the AI agent.
- Click Add (or Connect agent if you connected the AI agent to another AI agent). The resource appears on the Resource connections tab.
- To edit the resource connection, click the vertical ellipses that's next to the resource and select Edit connection. Make the required changes and click Save.
- To deactivate or remove the resource connection, click the vertical ellipses that's next to the resource
and select Deactivate connection. You can reactivate the connection by selecting
Activate connection from the vertical ellipsis. To delete a resource connection,
click the vertical ellipses and select Remove connection.
Note:
When you deactivate or remove a resource connection, Okta denies all future access requests from the AI agent to that resource.
For more details on securing Amazon Bedrock AgentCore AI agents, see Secure an Imported Amazon Bedrock AgentCore Agent.