- The agent exchanges the user’s Okta token for a short-lived ID-JAG (Identity Assertion JWT Authorization Grant) issued by your Okta org.
- The agent sends the ID-JAG to Opal’s token endpoint and receives an Opal access token for the MCP servers.
Prerequisites
- Okta Cross App Access enabled for your organization in Opal. Contact Opal support.
- An Okta tenant with Cross App Access and AI agents available, and an Okta admin.
- An Opal admin.
- Each user the agent acts for exists in Opal, with the same primary email address as their Okta profile. Opal doesn’t create users through Cross App Access.
Step 1: Connect your Okta tenant in Opal
- In Opal, go to Settings → Authentication → Okta Cross App Access and click Configure.
- Set Okta Issuer URL to your Okta org’s issuer, for example
https://your-org.okta.com. Use the org itself, not a custom authorization server such ashttps://your-org.okta.com/oauth2/default. - Make sure Connection enabled is on.
- Copy the Okta Audience/tenant ID value. This is your Opal organization ID, and you’ll paste it into Okta in step 3.
- Click Submit.
Step 2: Register the agent in Opal
Opal authenticates the agent with its own client credentials when the agent redeems an ID-JAG.- Under Settings → Authentication → Okta Cross App Access requesting apps, click Add requesting client.
- Enter a Label that identifies the agent, such as its Okta name.
- Copy the Client ID and Client secret. The secret is shown only once.
Step 3: Add Opal as a resource app in Okta
- In the Okta Admin Console, go to Applications → Applications → Create App Integration, choose OIDC - OpenID Connect and Web Application, and create the app with the Authorization Code grant. The sign-in redirect URI isn’t used by Cross App Access, so a placeholder is fine.
- Assign the users the agent will act for to this app.
- Open the app’s Resource Server tab, edit Cross-app access (XAA), and enable it with these values:
The Audience/tenant ID tells Opal which Opal organization an ID-JAG is for. Several Opal organizations can use the same Okta tenant, each with its own resource app and its own organization ID.
Step 4: Connect the AI agent to Opal in Okta
- In the Okta Admin Console, go to Directory → AI Agents and open your agent. Under User access, link it to the app your users sign in to the agent with.
- Under Resource connections, click Add resource connection, choose Application, and select the Opal resource app from step 3.
- Set the client ID to the Client ID from step 2.
- Choose the scopes the agent may use. See Scopes.
- Make sure the agent’s status is Active.
Step 5: Redeem the ID-JAG for an Opal access token
These details are for whoever builds or configures the agent. When the agent requests an ID-JAG from your Okta org’s token endpoint (https://your-org.okta.com/oauth2/v1/token), it sets audience to https://opal.dev/mcp and scope to the Opal scopes it needs.
The agent then sends the ID-JAG to Opal’s token endpoint, authenticating with the client ID and secret from step 2 (HTTP Basic or client_id and client_secret in the body):
Authorization: Bearer header to any of Opal’s MCP servers, for example https://app.opal.dev/mcp/end-user. Self-hosted deployments replace https://app.opal.dev with their own domain.
Opal doesn’t issue refresh tokens for Cross App Access. When the access token expires, the agent redeems its ID-JAG again, or gets a new one from Okta. The access token lifetime follows the Settings → Authentication → MCP OAuth token lifetime setting, which defaults to 1 hour.
Scopes
Opal never grants more than the scopes in the ID-JAG:
Full access means the user’s complete Opal permissions, read and write. Read-only access rejects every write, as described in Scopes.
Troubleshooting
Beta limitations
- Okta is the only supported identity provider. The issuer must be an Okta org on
okta.com,oktapreview.com, orokta-emea.com; Okta custom domains and Okta for Government aren’t supported. - Users are matched by primary email address. Opal system users and service users can’t be used.
- Each Opal organization connects one Okta issuer.