Skip to content
Protocol

XAA (Cross App Access)

Updated Aug 2026 1 min read
Definition

Cross App Access (XAA) is an open protocol backed by Okta that extends OAuth to secure agent-driven and app-to-app interactions across the enterprise. It shifts authorization control from individual applications to the identity provider, enabling centralized visibility and policy enforcement over how AI agents connect to downstream apps.

Why It Matters

MCP defines how agents connect to tools. XAA defines how agents prove they are authorized to use those tools, with the identity provider serving as the trust anchor.

XAA's strength is alignment with existing enterprise identity infrastructure. Its limitation: XAA requires adoption by downstream app vendors (ISVs) to enforce anything. Until an ISV implements XAA support, the protocol cannot govern access to that app.

This ISV dependency mirrors the SCIM adoption curve: years of vendor-by-vendor integration work before coverage becomes meaningful. For organizations that need agent governance today, a protocol-gateway approach provides enforcement without waiting for ISV cooperation.