Auth0 published guidance for Cross App Access (XAA), describing how enterprise identity providers can centrally authorize AI agents and applications to reach APIs and MCP servers without repeated per-user OAuth consent prompts. In the documented flow, a requesting application authenticates a user with an enterprise IdP such as Okta, receives an ID-JAG identity assertion, and exchanges that assertion with Auth0 for a standard access token that can be used against the target resource.
The implementation aligns with the emerging IETF work on the OAuth identity assertion authorization grant, which defines how identity assertions can be exchanged for OAuth tokens. Auth0 said the model supports both OIDC and SAML environments through a SAML compatibility layer, with Auth0 acting as the resource application's authorization server and Okta serving as the enterprise IdP; the company also outlined setup steps for Okta, Auth0, and its XAA Inspector, and said organizations can scale deployments by publishing integrations through the Okta Integration Network.

See the reporting duties and controls this puts on the clock.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.