Configure the Cross App Access connection

For each XAA-enabled resource app that you want to connect to your AI agent, configure the connection on the AI agent page

About this task

Use of Cross App Access (XAA) as part of SSO is limited to 250 ID-JAG tokens per user, per resource app, per month. For the purposes of this limit, a User must be a licensed User of Single Sign-On in an Active Status, and the total number of users using XAA can't exceed the org's total purchased SSO users. One ID-JAG token is consumed each time an AI agent uses XAA to access a resource app. If you require ID-JAG token volumes above the limit, contact your Okta account team to subscribe to Okta for AI Agents for a platform-wide agentic identity security solution.

Procedure

  1. In the Admin Console, go to Directory > AI Agents.
  2. Select an AI agent.
  3. Select the Resource connections tab.
  4. Click Add resource connection.
  5. From the Application > Application instance dropdown, select the XAA-enabled resource app that you configured from Configure the resource app. Select Enable to grant access to the app through XAA.
  6. Specify the following fields:
    • Resource indicator: Specify the URLs of the protected resources.
    • AI agent's client ID registered in this app: The external client ID of the AI agent registered in the resource app.
    • Scopes: Specify the scopes the AI agent is allowed to request from the resource app.
  7. Click Add.