Configure resource apps
Configure a resource app so you can create a resource connection between it and an AI agent.
Note: For apps that use Federation Broker Mode, SAML assertions must match the
Okta user's name ID (${user.login}) or user ID (${user.id}) to avoid token exchange failures.
Resource apps have a Machine Assignments tab where you can configure the following access methods:
- Cross App Access (XAA) (recommended): Allows AI agents to connect to the app without prompting users for consent.
- Brokered Consent: Uses admin-configured credentials to connect an AI agent to the app, and then prompts users for their consent.
Note:
If a resource app has more than 500 scopes, you can't view or edit them from the Machine Assignments tab. If the client app doesn't support scopes, the resource app inherits the client's permissions. You can't view or edit the inherited scopes in Okta.
Before you begin
- You have an admin role with permission to manage apps.
- You've registered a client app with the third party app provider. See Prerequisites for common resource apps.
- You've integrated the resource app in your org. See Add existing app integrations.
Procedure
-
In the Admin Console, go to .
- Search for and select a resource app.
- Go to the Machine Assignments tab.
- Select the Callers tile.
- Select Cross App Access (XAA) to configure this access method.
- Select Enable to grant access to the app through Cross App Access.
- Complete the following fields:
- Resource URL: The base URL of the app's resource server.
- Issuer URL: The base URL of the app's authorization server. Okta uses this URL to detect token verification requests.
- Audience/tenant ID: A unique identifier or audience claim for the authorization server that protects the resource.
- Click Save.
- Select Brokered Consent to configure this access method.
- Select Enable to grant access to the app through a security token service.
- Enter a Client ID and Client secret for the client app that you registered with the resource server connector.
- If the client app supports scopes, the Scopes field appears. Add the scopes that you want to grant to the resource app.
- Click Save.
- Click Save.
- Optional. Use Edit button to modify your configurations. Note:
If you modify the Brokered Consent scopes later, any users who are in an active session with that AI agent must re-authenticate and accept consent. Then the AI agent can perform subsequent actions on their behalf.