Configure an Agent Gateway in Okta.
About this task
When you add an Agent Gateway, you configure its unique URL path and authorize the AI agents that are allowed to route requests through it. Then you customize the MCP server tools that you want to include.
Before you begin
- You have an admin role with permission to manage Agent Gateways.
- You’ve configured the MCP servers whose tools you want to use. See Add MCP servers.
- You’ve registered an AI agent in your org.
Procedure
Create a profile
-
In the Admin Console, go to .
-
Click Create agent gateway.
-
On the Profile tab, enter a display name and description.
-
The Agent Gateway URL path displays an Okta-hosted URL for the gateway. Click
Customize URL path to modify it.
Note: You can't change this URL after you save it. To use a different URL, delete the Agent Gateway and recreate it.
-
Click Create.
-
Click Next.
Add AI agents
Select the AI agents that can call the Agent Gateway. The AI agents page displays this gateway name next to your selections and on the AI agent's Resource connections tab.
-
On the AI Agents tab, click Edit.
-
Select the AI agents that are allowed to call the gateway.
-
Click Save.
-
Click Next.
Add resource connections
Select the MCP servers that you want to include in the gateway.
-
On the Resource connections tab, click Add connection.
-
Select the MCP servers that you want to include in the gateway.
-
Click Save.
-
Click Next.
Customize your tools
Define the MCP server tools that you want to include.
-
On the Tool customization tab, click Manage tools next
to an MCP server.
-
Select the tools that you want to connect to the gateway. You can add up to 200 tools per
gateway.
Note: Click Rediscover tools at any time to refresh the list of
available tools.
-
Click Save.
Activate the Agent Gateway
-
When the Agent Gateway is ready for activation, an Activate now link appears.
Click this link, or select .
-
To deactivate the agent gateway, select .
-
Click Finish.
Note: You can also activate and deactivate the gateway from the main Agent Gateway page.
Select the vertical ellipsis next to a gateway, and then select Activate or
Deactivate.
Configure the AI agent client
After you've activated the Agent Gateway, configure the AI agent client to send requests through Okta instead of your MCP servers.
Note: This process takes place outside of Okta and varies by AI agent provider. Refer to your AI agent provider's documentation for specific instructions. See
AI agent client configurations for documentation links to common AI agent clients.
-
Go to the tab and copy the Agent Gateway URL path. Store it in a safe
location.
-
Go to the tab and copy the client credential
(Client ID, Client secret, or Public/private
key). Store it in a safe location.
-
In the AI agent client, add the Agent Gateway URL path as the remote MCP server endpoint.
Note: Use an admin-managed or central deployment path whenever possible. Centralized deployment ensures that all AI agent requests are sent through the Agent Gateway and saves developers from having to configure settings manually.