Enterprise-Managed Authorization.
Enterprise-managed authorization is the pattern where an AI agent proves what software it is with a Client ID Metadata Document, and the customer's identity provider decides, through an ID-JAG, which apps it may reach.
Definition. Enterprise-managed authorization means two things are checked before an AI agent touches a business app. CIMD establishes who the agent software is. An ID-JAG from the customer's identity provider establishes whether that software may reach this app for this user. Neither check alone is enough. CIMD without the IdP gives you a known client with no policy. The IdP without CIMD gives you policy over a client you cannot name.
The shift is about who decides. Consumer OAuth asks the end user. Enterprise-managed authorization asks the company, because the company owns the data and already runs single sign-on through its IdP. That is the same reason workforce SSO replaced per-app passwords.
The term is young. The Model Context Protocol uses it as the name of an optional extension, and Auth0 uses it in its documentation. Okta's Cross App Access is the same pattern under a product name. Expect the vocabulary to settle as more vendors ship.
For B2B SaaS teams, the build is covered in the enterprise-managed authorization and Cross App Access guide. For why agents need their own identity model in the first place, see AI agents don't have passwords.
Common questions
What is enterprise-managed authorization?
It is the pattern where an AI agent identifies its software with a Client ID Metadata Document (CIMD) and the customer's identity provider decides, by issuing or refusing an ID-JAG, which apps the agent may reach for each user. The company's admin, not each end user, holds the access decision.
Is enterprise-managed authorization part of the MCP specification?
It is an MCP extension, not part of the core specification. Its id is io.modelcontextprotocol/enterprise-managed-authorization and it lives in the MCP ext-auth repository. MCP extensions are optional and never on by default, so both client and server must explicitly support it.
How does enterprise-managed authorization relate to Cross App Access?
They describe the same pattern. Cross App Access (XAA) is Okta's product name, enterprise-managed authorization is the MCP extension name, and ID-JAG is the IETF draft that defines the token. Auth0 and Descope ship support under the XAA label as well.
Why not just use OAuth consent for agents?
Per-user OAuth consent leaves the company's IT team blind. Each employee grants an agent access separately, and nobody can review or revoke those grants centrally. Enterprise-managed authorization moves the decision into the IdP, where access policy for everything else already lives.
Related terms
In the guides
Authorization Patterns for Agentic Workflows: Delegation, Constraints, and Just-in-Time Permissions
AI agents need authorization models that handle delegated permissions, multi-step workflows, and least-privilege at machine speed. The patterns that work and the ones being invented.
Enterprise-Managed Authorization: Cross App Access, ID-JAG, and CIMD for B2B SaaS
How enterprise customers let AI agents reach your SaaS API or MCP server under their IdP policy. ID-JAG, CIMD, and Cross App Access explained for B2B builders.
MCP Server Identity Model: Authentication, Authorization, and Trust for the Model Context Protocol
MCP is OAuth 2.1 with discovery. How MCP clients identify themselves (CIMD first, DCR as fallback), how servers scope access, and what the spec leaves to you.