The Sandbox for testing Cross App Access (XAA)
Test secure agent-to-app and app-to-app authorizations
Cross App Access (XAA) implements OAuth Identity Assertion Authorization Grant (ID-JAG).
Run a live XAA flow in seconds
No accounts, no config, no waiting. Watch a real IDP issue an ID-JAG, exchange it for an access token, and call a protected API. All pre-configured and running live in your browser.
Launch demoReady to bring your own actors?
Tell us what you've got and where you want to take it — we'll point you to the right tool.
I have a…
The Problem
Repeated consent prompts across apps frustrate users, pushing them to share credentials or adopt unsanctioned tools and creating Shadow IT.
The Mechanism
XAA uses OAuth ID-JAG, a signed delegation token the Identity Provider issues once so apps can securely act on a user's behalf without re-prompting.
The Outcome
Apps connect seamlessly under enterprise control with no repeated sign-ins, no manual approvals, and no reason for users to resort to Shadow IT.
How Cross App Access Works
XAA Actors
Click on an actor to highlight their role in the flow below
The 4-step XAA flow