Cross App Access (XAA) is an Okta identity framework that replaces static API keys and scattered OAuth consent with token-based identity propagation between applications. It defines three roles: requesting app, resource app, and identity provider (Okta). ISVs building on this standard must support OIDC or SAML SSO, implement ID-JAG token exchange flows, and pass verification tests before submitting to the Okta Integration Network (OIN). The guide covers prerequisites, implementation steps for both SAML and OIDC apps, and a detailed questionnaire required to request XAA enablement via email to the Okta OIN team.
Table of contents
What is Cross App Access (XAA)?Why Cross App Access (XAA) matters for ISVs and their customersPrerequisites for supporting Cross App Access (XAA) in your appImplementation and testing guide for Cross App Access (XAA) with Okta as IdPGetting listed in the Okta Integration Network (OIN)Need help with your Cross App Access (XAA) submission?Learn more about Cross App Access and the Okta Integration Network145 Impressions