Cross App Access
Cross App Access (XAA).
Cross App Access (XAA) is Okta's name for the ID-JAG pattern: an enterprise IdP decides, by admin policy, whether one app or AI agent may get a token for another app's API on a user's behalf.
Cross App Access solves a governance problem more than a login problem. When an AI agent or SaaS app connects to Slack, a CRM, or a ticketing tool through ordinary OAuth, each user grants consent individually. IT sees none of it. XAA routes the decision through the company's identity provider, so an admin can allow, deny, and later revoke app-to-app access in one place.
The pattern converged quickly across vendors in 2026. Per WorkOS, Okta, Auth0, and Descope all shipped support within eight days, from August 24 to September 1, 2026. Auth0's requesting-app support runs on Auth0 Token Vault over ID-JAG and is available on its Enterprise, B2B Pro, and B2B Essential plans. Descope's support lives in its Agentic Identity Hub, where tenant admins can configure XAA themselves. The changelog entry has the timeline.
Use the term carefully. XAA is the product name, ID-JAG is the IETF draft, and enterprise-managed authorization is the MCP extension name for the wider pattern. For a B2B SaaS team, all three point at the same build: accept ID-JAGs from your customers' IdPs at your authorization server.
Common questions
What is Cross App Access?
Cross App Access (XAA) is Okta's name for letting an enterprise identity provider broker access between apps. Instead of each user clicking through an OAuth consent screen, the IdP checks admin policy and issues an ID-JAG that the requesting app trades for an access token at the target app.
Which vendors support Cross App Access?
According to WorkOS's analysis, Okta's Agent SSO reached general availability on August 24, 2026. Auth0 moved the requesting-app side of XAA to early access on August 31, 2026, with the resource-app side already in early access. Descope announced both ID-JAG validation and issuance on September 1, 2026.
Is Cross App Access a standard?
The standard is the IETF OAuth Working Group draft for the Identity Assertion JWT Authorization Grant (ID-JAG). Cross App Access is a product name for that pattern. It is still a draft, not a published RFC.
How is Cross App Access related to MCP?
The Model Context Protocol publishes the same pattern as an optional extension named Enterprise-Managed Authorization (io.modelcontextprotocol/enterprise-managed-authorization). MCP extensions are never on by default, so a client and server must both opt in.
Related terms
In the guides
Authentication for AI Agents: OAuth Patterns for Non-Human Identity
How AI agents authenticate in 2026. The on-behalf-of pattern, delegated agent identity, OAuth 2.1 Dynamic Client Registration, and where the patterns are still being invented.
B2B SaaS Identity: Organizations, SSO, SCIM, and the Enterprise Sales Checklist
How to design B2B SaaS identity: Organizations, Enterprise SSO with SAML and OIDC, SCIM provisioning, audit logs, and the IT-admin features that close enterprise deals.
Enterprise-Managed Authorization: Cross App Access, ID-JAG, and CIMD for B2B SaaS
How enterprise customers let AI agents reach your SaaS API or MCP server under their IdP policy. ID-JAG, CIMD, and Cross App Access explained for B2B builders.