Case Study: Okta enables enterprise-managed authorization for MCP with WorkOS

A WorkOS Case Study

Preview of the Okta Case Study

Okta enables Enterprise-Managed Authorization in 300 seconds with WorkOS

Okta, a leading enterprise identity provider, sought to eliminate the friction of repeated user consent screens when employees connect AI-powered clients, like code editors, to internal MCP servers. The challenge was to enable centralized, admin-level control over these connections without interrupting individual users. To address this, Okta implemented the Enterprise-Managed Authorization (EMA) extension for MCP, becoming the first Identity Provider (IdP) to support the new standard using a product from the vendor WorkOS.

The solution from WorkOS introduced a new token type called an ID-JAG, which allows Okta's admin console to authorize connections based on policy. This meant that after a one-time setup, applications like Claude and VS Code could connect to servers like Linear or Figma automatically. The result was the removal of consent screens for end-users, streamlining onboarding and providing IT with centralized governance over tool access. By adopting the WorkOS solution, Okta established itself as the pioneering IdP for this new enterprise authorization model.


View this case study…

WorkOS

82 Case Studies