Okta Identity Engine Production release notes
Version 2026.09.2. Deployed on October 5, 2026.
Generally Available features
- Unique MCP server names
When you register an MCP server, it must now have a unique display name.
- Sign-In Widget, version 7.49.1
For details about this release, see Sign-In Widget Release Notes. For more information about the widget, see Okta Sign-In Widget.
- Automatic phishing resistance for FastPass in authentication chains
When you include Okta FastPass in an authentication method chain, the Phishing resistant characteristic is now selected by default.
- Access Requests decision justification
Okta Identity Governance now supports configurable justification controls for access request decisions, providing requesters more transparency into their approvals and denials. Admins can configure the approval sequence or request type settings to include the decision justification field for approval tasks, allowing approvers the option to provide a rationale for their decision. All submitted justification text is captured on the request ticket and made available to the requester, providing insight into access decisions. See Request type settings.
- Provisioning for Kong AI
Provisioning is now available for the Kong AI integration. See Integrate Kong AI with Okta.
- Editable resource URL for MCP servers
Admins can now edit the resource URL and re-trigger metadata discovery for an MCP server.
- AI agent profile and attribute sourcing
You can now use profile sourcing to manage AI agent identities. Okta supports base, custom, and extendable attributes that you can define to create standardize tracking and visibility to your org's AI agents. See AI agent profile sourcing.
Fixes
-
When accessing apps through a SAML IDP redirect, some device-bound SSO users experienced a continuous loop in Okta FastPass. (OKTA-1242455)
-
For users not created through self-service registration, clicking Forgot Password on a Staged account sent an activation email and not a password reset email. This also changed the account status to Pending user action without logging a lifecycle event. (OKTA-1244542)
-
In some orgs, the Sign-In Widget (third generation) displayed "Set up another" instead of "Set up" on the email enrollment prompt button. (OKTA-1245836)
-
Users couldn't sign in with an NFC authenticator when Device-Bound Single Sign-On was enabled on their Windows devices. (OKTA-1274233)
-
When an import job reconciled existing active admin users, Okta incorrectly logged false ROLE_ASSIGNED_USER_ACTIVATION audit events. This issue created misleading records when no role changes occurred. (OKTA-1274235)
-
Enrolling the NFC authenticator failed with an error when the Sign-in with NFC option was disabled, both from the End-User Dashboard and through an enrollment policy that required the NFC authenticator. (OKTA-1275952)
-
App-scoped identity provider (IdP) routing rules could route authentication requests to the wrong IdP, causing sign-in failures for users who should have been redirected to a different IdP or the default sign-in page. (OKTA-1176869)
-
After Universal Logout revoked a user's session, clicking Sign In on the Session Revoked page redirected users to the Okta Dashboard instead of the app that they were trying to access. (OKTA-1182886)
-
On the End-User Dashboard, the Set up button for the NFC authenticator incorrectly appeared for users on non-Windows devices. (OKTA-1255785)
-
The User Sources page loaded slowly if there was a large number of profile sources. (OKTA-1265698)
-
When the Flexible Okta Verify authenticator configuration was enabled, user verification recovery failed for Okta FastPass and Push. Users without an enrolled verification method weren't prompted to add one and users with an invalidated verification method weren't signed in even after completing recovery. (OKTA-1268512)
-
In orgs with the early access feature "Support for re-authentication with an external IdP" enabled, users who tried to sign in to an app through an IdP saw an error message if they already had an active session on the upstream IdP. (OKTA-1276837)
-
When generating the Out-of-the-Box Admin Role Assignment report, the third-party admin status appeared inconsistently for users with multiple admin roles assigned through group memberships. (OKTA-1278183)
-
Admins experienced page performance errors and unexpected MFA prompts due to access tokens expiring during tasks. (OKTA-1281712)
Okta Integration Network
-
Ansi Standards Connect (OIDC) is now available. Learn more.
-
Antenna (API Service) is now available. Learn more.
-
Availity (SWA) was updated.
-
ClearVector (OIDC) is now available. Learn more.
-
Corma (API Service) has a new logo and the following new scopes: okta.users.manage, okta.roles.read, okta.groups.manage.
-
Cursor (SAML) is now available. Learn more.
-
dbt Cloud (SAML) is now available. Learn more.
-
DevArmor (OIDC) is now available. Learn more.
-
Domo (OIDC) is now available. Learn more.
-
Goldman Sachs Research (SWA) was updated.
-
HelpJuice Lifecycle Management Connector by Redblock (SCIM) is now available. Learn more.
-
Hexnode (API Service Integration) has a new integration guide. Learn more.
-
Hgraph (SAML) is now available. Learn more.
-
Honeycomb (SAML) is now available. Learn more.
-
iCompaas - Compliance & Security Automation Platform (API Service) is now available. Learn more.
-
Infomaniak (SAML) is now available. Learn more.
-
Infomaniak (SCIM) is now available. Learn more.
-
Kluster (OIDC) has a new redirect URI.
-
Metano (OIDC) is now available. Learn more.
-
Metano (SAML) is now available. Learn more.
-
Metano (SCIM) is now available. Learn more.
-
Metano (Universal Logout) is now available. Learn more.
-
Metano has a new logo.
-
Netskope User Enrollment (SCIM) now supports OIDC.
-
PaperCut Hive and Pocket directory sync (API Service) is now available. Learn more.
-
Pensero (SAML) is now available. Learn more.
-
Pensero (SCIM) is now available. Learn more.
-
PipeDrive (SWA) was updated.
-
Progress Chef (OIDC) is now available. Learn more.
-
Pulumi Cloud (SAML) is now available. Learn more.
-
Pulumi Cloud is now available in the Okta Integration Network (OIN) with SCIM 2.0 provisioning support. Administrators can automate user onboarding, profile updates, and offboarding between Okta and Pulumi Cloud. Group push support enables role-based access by syncing Okta groups to Pulumi Cloud teams.
-
Qualtrics XM (SWA) was updated.
-
Skillcast (SCIM) was updated. Learn more.
-
Tines (OIDC) is now available. Learn more.
-
TrueFoundry (OIDC) is now available. Learn more.
-
Visitly (SAML) has a new logo and description.
-
Visitly (SCIM) has new SCIM features: Push New Users Without Password and Push Groups.
-
Your360 (SAML) was updated with a new app name.