Recap of Okta Developer Connect San Francisco 2026, focused on securing AI agents with identity governance. Key announcements include the general availability of Okta for AI Agents, which addresses agent discovery, scoped credential management, and lifecycle governance. The event also covered Cross App Access (XAA), a protocol enabling enterprise identity providers to mediate app-to-app access via policy rather than per-user consent. Sessions highlighted practical identity patterns for AI applications: authenticating users agents act on behalf of, using token vaults instead of long-lived credentials, asynchronous authorization, and fine-grained authorization at the data layer. Core takeaways include treating agents as first-class identities with lifecycle controls, designing consent models before integrations, and pushing authorization closer to the data.