Configure the resource app

The resource app contains the protected resources that your AI agent can access on behalf of the user. Create the app integration instance that represents your resource app in Okta before configuring the resource connection.

Before you begin

  • Ensure that the resource app instance exists in your Okta org.
  • Ensure that the app you're registering as the resource server supports Cross App Access (XAA).
    The following resource apps are supported:

Procedure

  1. In the Admin Console, go to Applications and Resources > Applications.
  2. Select your SSO resource app. Confirm that the app you're registering as the resource server supports XAA.
  3. In the Machine Assignments tab of your app page, select the Callers tile. The Callers page appears for you to specify the access method for callers to your resource app.
  4. Click Edit next to Cross App Access (XAA).
  5. Select Enable to grant access to the app through XAA.
  6. Specify the following fields:
    1. Issuer URL: The base URL of the app's authorization server. Okta uses this URL for token verification requests.
    2. Audience/tenant ID: A unique identifier or audience claim for the authorization server that protects the resource.
    3. Scopes: The scopes that the resource app allows the callers to access. Specify one scope in the text field. Click + Add to add more scopes. You can add up to 100 scopes.
  7. Click Save.

What to do next

Configure the Cross App Access connection