Skip to content

Enterprise-Managed Authorization.

Enterprise-managed authorization is the pattern where an AI agent proves what software it is with a Client ID Metadata Document, and the customer's identity provider decides, through an ID-JAG, which apps it may reach.

Definition. Enterprise-managed authorization means two things are checked before an AI agent touches a business app. CIMD establishes who the agent software is. An ID-JAG from the customer's identity provider establishes whether that software may reach this app for this user. Neither check alone is enough. CIMD without the IdP gives you a known client with no policy. The IdP without CIMD gives you policy over a client you cannot name.

The shift is about who decides. Consumer OAuth asks the end user. Enterprise-managed authorization asks the company, because the company owns the data and already runs single sign-on through its IdP. That is the same reason workforce SSO replaced per-app passwords.

The term is young. The Model Context Protocol uses it as the name of an optional extension, and Auth0 uses it in its documentation. Okta's Cross App Access is the same pattern under a product name. Expect the vocabulary to settle as more vendors ship.

For B2B SaaS teams, the build is covered in the enterprise-managed authorization and Cross App Access guide. For why agents need their own identity model in the first place, see AI agents don't have passwords.

Common questions

What is enterprise-managed authorization?

It is the pattern where an AI agent identifies its software with a Client ID Metadata Document (CIMD) and the customer's identity provider decides, by issuing or refusing an ID-JAG, which apps the agent may reach for each user. The company's admin, not each end user, holds the access decision.

Is enterprise-managed authorization part of the MCP specification?

It is an MCP extension, not part of the core specification. Its id is io.modelcontextprotocol/enterprise-managed-authorization and it lives in the MCP ext-auth repository. MCP extensions are optional and never on by default, so both client and server must explicitly support it.

How does enterprise-managed authorization relate to Cross App Access?

They describe the same pattern. Cross App Access (XAA) is Okta's product name, enterprise-managed authorization is the MCP extension name, and ID-JAG is the IETF draft that defines the token. Auth0 and Descope ship support under the XAA label as well.

Why not just use OAuth consent for agents?

Per-user OAuth consent leaves the company's IT team blind. Each employee grants an agent access separately, and nobody can review or revoke those grants centrally. Enterprise-managed authorization moves the decision into the IdP, where access policy for everything else already lives.

Related terms

In the guides

Last updated 2026-10-05.