Okta Developer · XAA.dev

NewSAML XAA flow now supported

The Sandbox for testing Cross App Access (XAA)

Test secure agent-to-app and app-to-app authorizations

Cross App Access (XAA) implements OAuth Identity Assertion Authorization Grant (ID-JAG).

Run a live XAA flow in seconds

No accounts, no config, no waiting. Watch a real IDP issue an ID-JAG, exchange it for an access token, and call a protected API. All pre-configured and running live in your browser.

Launch demo

Ready to bring your own actors?

Tell us what you've got and where you want to take it — we'll point you to the right tool.

I have a…

The Problem

Repeated consent prompts across apps frustrate users, pushing them to share credentials or adopt unsanctioned tools and creating Shadow IT.

The Mechanism

XAA uses OAuth ID-JAG, a signed delegation token the Identity Provider issues once so apps can securely act on a user's behalf without re-prompting.

The Outcome

Apps connect seamlessly under enterprise control with no repeated sign-ins, no manual approvals, and no reason for users to resort to Shadow IT.

How Cross App Access Works

XAA Actors

Click on an actor to highlight their role in the flow below

The 4-step XAA flow

See it run live

Read the original on xaa.dev ↗