Add an Agent Gateway

Configure an Agent Gateway in Okta.

About this task

When you add an Agent Gateway, you configure its unique URL path and authorize the AI agents that are allowed to route requests through it. Then you customize the MCP server tools that you want to include.

Before you begin

  • You have an admin role with permission to manage Agent Gateways.
  • You’ve configured the MCP servers whose tools you want to use. See Add MCP servers.
  • You’ve registered an AI agent in your org.

Procedure

  • Create a profile

    1. In the Admin Console, go to Security > Agent Gateway.
    2. Click Create agent gateway.
    3. On the Profile tab, enter a display name and description.
    4. The Agent Gateway URL path displays an Okta-hosted URL for the gateway. Click Customize URL path to modify it.
    5. Click Create.
    6. Click Next.
  • Add AI agents

    Select the AI agents that can call the Agent Gateway. The AI agents page displays this gateway name next to your selections and on the AI agent's Resource connections tab.

    1. On the AI Agents tab, click Edit.
    2. Select the AI agents that are allowed to call the gateway.
    3. Click Save.
    4. Click Next.
  • Add resource connections

    Select the MCP servers that you want to include in the gateway.

    1. On the Resource connections tab, click Add connection.
    2. Select the MCP servers that you want to include in the gateway.
    3. Click Save.
    4. Click Next.
  • Customize your tools

    Define the MCP server tools that you want to include.

    1. On the Tool customization tab, click Manage tools next to an MCP server.
    2. Select the tools that you want to connect to the gateway. You can add up to 200 tools per gateway.
    3. Click Save.
  • Activate the Agent Gateway

    1. When the Agent Gateway is ready for activation, an Activate now link appears. Click this link, or select Actions > Activate.
    2. To deactivate the agent gateway, select Actions > Deactivate.
    3. Click Finish.
  • Configure the AI agent client

    After you've activated the Agent Gateway, configure the AI agent client to send requests through Okta instead of your MCP servers.

    1. Go to the Agent Gateway > Profile tab and copy the Agent Gateway URL path. Store it in a safe location.
    2. Go to the AI Agent > Client registration tab and copy the client credential (Client ID, Client secret, or Public/private key). Store it in a safe location.
    3. In the AI agent client, add the Agent Gateway URL path as the remote MCP server endpoint.