Configure the AI agent (requesting app)

To configure an AI agent as the requesting app for Cross App Access (XAA), register the AI agent, add client registration details, then assign users to the requesting app. You can activate your AI agent after it's configured.

Before you begin

  • You have permission to manage your org's AI agents.
  • See AI agent configuration settings - supported requesting apps for requesting app requirements.
  • If the AI agent was built in a third-party provider platform, you know the AI agent's external ID. See External IDs for AI agent providers.
  • If you want to use the public/private key client registration method, you have a public JSON Web Key (JWK). If you don't have one already, you can generate one when you register the AI agent.

Procedure

  • Register an AI agent
    1. Register the AI agent from one of these entry points:
      1. In the Admin Console, go to Directory > AI Agents, and click Register AI Agent.
      2. Alternatively, you can go to Applications and Resources > Applications and select an app integration that's configured for Cross App Access. Select Machine Assignments > Resources, and then click Register AI Agent.
    2. Under Profile, add a name and description for your AI Agent.
    3. Click Next.
    4. Under User access and authentication > Allow users to access this agent, select one of the following options.
      • Create a new OIDC app linked to this AI agent: To create a custom OIDC app integration instance for users to sign in to access the AI agent.
      • Select an existing app: To select an existing app integration instance in your org for users to sign in to access the AI agent. If you register an AI agent from an existing app, the existing app is prepopulated in this section.

      For details, see AI agent configuration settings - supported requesting apps.

      The app that you select in the User access tab acts as the requesting app role for the XAA flow. It allows your users to sign in to the agentic app through Okta. After the user is signed in, the agentic app can access resource apps on behalf of the signed in user.

    5. Click Next. Your AI agent appears in the AI agents list with the STAGED status.
  • Add client registration details

    You can stage multiple client registration methods, but you can only activate one method at a time.

    1. On the Client registration tab, click Configure next to the a client registration method that you want to use:
      1. Client ID Metadata Document (CIMD): Recommended for AI agents that are identified by a developer-hosted URL.
        1. Enter the CIMD URL.
        2. Click Activate CIMD client registration.
        3. Click Activate. The CIMD URL activates and appears on the Client registration tab for the AI agent and on the General tab of the app that's linked to the AI agent.
      2. Client ID only: Recommended for public clients that can't store a secret, like local coding agents.
      3. Client secret: Recommended for server-side AI agents. Click Generate secret and provide it to the AI agent builder or developer.
      4. Public/private key: Recommended for AI agents that have builder-managed key pairs.
        1. Click Add public key.
        2. Enter your public key, or click Generate new key. Okta creates a public key that's associated with a private key that you can view in JSON or PEM.
        3. Click Copy to clipboard and store the private key safely.
        4. Click Done.
    2. Copy the identifier that appears in the Client ID field and provide it to the AI agent builder or developer.
    3. Click Activate.
    4. Click Enable on the dialog that appears.
    5. To deactivate a client secret or public key, click the vertical ellipses and select Deactivate. To remove it, click the vertical ellipses again and select Delete.
  • Assign users to the requesting app
    1. Select your AI Agent from the list of Directory > AI Agents.
    2. Click the User access tab.
    3. Under User access > Users and groups assigned to this agent, click Application > Assignments. The Assignments tab appears for your linked SSO app.
    4. In the Assignments tab, select the users or groups who can access the AI agent. See Assign an app integration to a user and Assign an app integration to a group.
  • Activate the AI agent
    1. On the AI agent page, select Actions > Activate.
      You can also activate the AI agent indirectly by activating the linked requesting app.
      1. Go to Applications and Resources > Applications.
      2. Select the Inactive tab from the STATUS column, and find the linked requesting app that you want to activate.
      3. Select Activate from the dropdown menu beside your app integration. The AI agent is automatically activated when you activate the linked app.

      To deactivate the AI agent, go to the AI agent page and select Actions > Deactivate.

    What to do next

    Configure the resource app