Skip to content

Blocks.ai vs Okta for AI Agents

Blocks.ai

Network for AI agents: a free public network, and a private network for each company

Okta for AI Agents

Okta offering that gives AI agents a first-class identity so organizations can discover, onboard, protect, and govern them

Short answer

Okta says Okta for AI Agents gives AI agents a first-class identity: it registers them in an Okta org, with credentials and optional owners, and admins define what each can access.⁠Source 1, Source 2, Source 3, Source 4, Source 5 Blocks.ai is a network agents join by connecting out; on the Pro tier, partners join as their own organizations.⁠Source 6, Source 7, Source 8, Source 9

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both keep a registry of agents with owners, decide who may call each agent, and log agent events.⁠Source 2, Source 3, Source 4, Source 10, Source 11, Source 12, Source 13, Source 14
Where they differ
Okta gives agents credentials and issues the tokens they present.⁠Source 4, Source 10, Source 15 Blocks.ai is the network agents connect to, including, on the Pro tier, partners’ agents.⁠Source 6, Source 7, Source 8, Source 9
Running both
Neither vendor publicly documents using the two together.
Public sources · checked 2 October 2026
  • Offered
  • Preview
  • Not included
  • Not publicly documented

Blocks.ai

  • Build agents: Not includedUse LangChain or CrewAI⁠Source 16
  • Host and run agents: Not includedYou run your agent⁠Source 17
  • Identity and access: OfferedMachine identity per agent⁠Source 18
  • Registry and governance: OfferedPrivate registry and Admin Console⁠Source 11
  • Traffic between agents, tools, and models: OfferedPrivate network for every agent⁠Source 11
  • Agents across organizations: OfferedPartners share only chosen agents⁠Source 19

Okta for AI Agents

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedAgent identity and credentials⁠Source 4
  • Registry and governance: OfferedUniversal Directory with human owners⁠Source 20
  • Traffic between agents, tools, and models: PreviewAgent Gateway for MCP tools⁠Source 21
  • Agents across organizations: Not publicly documented

At a glance

TopicBlocks.aiOkta for AI Agents
What it doesA network agents join by connecting out; on a company’s private network, they join its private registry and are reached by grant.⁠Source 6, Source 7, Source 11, Source 13, Source 22Okta says it gives AI agents a first-class identity in an Okta org, with credentials and optional owners; admins can define which resources each one can access.⁠Source 1, Source 2, Source 4, Source 5
How agents connectOutbound HTTPS on port 443.⁠Source 7 No inbound ports.⁠Source 7For agent-to-agent calls, Okta issues scoped tokens, and the caller sends its token to the agent it calls.⁠Source 10, Source 15 Agent Gateway, in preview, puts MCP tools behind one Okta endpoint.⁠Source 21
Finding agentsOn your company’s private network, agents are listed in your private registry when they connect and register.⁠Source 11, Source 22, Source 23 Blocks.ai does not publicly document a way to find agents that haven’t connected.Okta’s ISPM discovers shadow agents in managed browsers; discovery on endpoints is in early access.⁠Source 24, Source 25 Agents can also be imported from builder platforms.⁠Source 3
Agents at other companiesOn the Pro tier, a partner company joins your private network as its own organization.⁠Source 8, Source 9 You can call only the agents it shares with you.⁠Source 12, Source 19Not publicly documented (checked 2 October 2026)
PricingThe public network is free.⁠Source 9 Pro pricing is set with each customer.⁠Source 9A separate subscription that can be added to an Okta suite plan.⁠Source 1, Source 26 A list price is not publicly documented.

What each one is

Blocks.ai

Blocks.ai is a network: a free public network, and a private network for each company.⁠Source 9, Source 11 A company’s private network gives it one place to connect, govern, and audit its agents, whoever built them and wherever they run.⁠Source 11 Blocks.ai does not build, host, or orchestrate agents.⁠Source 16, Source 17

Okta for AI Agents

Okta for AI Agents helps an organization discover, manage, and secure the AI agent lifecycle in its Okta org; Okta says it gives agents a first-class identity.⁠Source 1, Source 2 It is a separate subscription, Okta says.⁠Source 1 Agent Gateway, its gateway for MCP tool calls, is in preview.⁠Source 21, Source 27

The differences that matter

  1. Agents at other companies

    Blocks.ai

    On the Pro tier, a partner company joins your private network as its own organization.⁠Source 8, Source 9 You can call only the agents it shares with you.⁠Source 12, Source 19

    Okta for AI Agents

    Okta says it federates with existing identity providers over OIDC or SAML.⁠Source 28 Bringing in another organization’s agents under access it controls isn’t publicly documented.

    On Blocks.ai, your administrators can see a partner’s registered agents and, on the Pro tier, take one offline.⁠Source 12, Source 19

  2. How agents connect

    Blocks.ai

    Every Blocks.ai agent connects out over HTTPS on port 443, and its host needs no inbound ports, DNS records, or static IP.⁠Source 7

    Okta for AI Agents

    For agent-to-agent calls, Okta issues expiring, resource-scoped tokens, and the calling agent sends its token to the agent it calls.⁠Source 10, Source 15

    Agent Gateway, in preview, puts tools from multiple remote MCP servers behind one Okta-hosted endpoint.⁠Source 21, Source 29 Okta does not publicly document whether an agent needs an inbound endpoint.

  3. Finding agents

    Blocks.ai

    On your company’s private network, agents are listed in your private registry when registered; whoever registers one owns it.⁠Source 11, Source 12, Source 22, Source 23

    Okta for AI Agents

    Okta says it discovers unregistered and shadow agents and assigns them named human owners.⁠Source 1 Its docs say Okta ISPM discovers agents from several sources.⁠Source 25

    Okta’s Core SKU for regulated environments excludes ISPM.⁠Source 25, Source 30 Blocks.ai does not publicly document a way to find agents that haven’t connected.

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicBlocks.aiOkta for AI Agents
Network exposureAgent hosts open no inbound ports, and all Blocks.ai traffic is TLS on port 443.⁠Source 7Whether an agent needs an inbound endpoint is not publicly documented. Agent Gateway, in preview, runs at an Okta-hosted URL.⁠Source 29
IdentityEach agent gets its own identity.⁠Source 18 Handler code never sees a credential.⁠Source 31Manually added agents identify with a client ID, secret, key pair, or CIMD; agent-to-agent tokens are resource-scoped and expire.⁠Source 4, Source 10
Access changes and revocationRevoked grants are rejected on the next request.⁠Source 31 A user removed from an organization is rejected within about 5 seconds.⁠Source 31Okta says deactivating an agent immediately blocks new sessions and that expanded runtime kill switch controls are planned for Q4.⁠Source 32
Audit trailThe Pro tier logs control-plane changes and grants.⁠Source 33 Log entries on your company’s private network are kept for 2,555 days.⁠Source 33Agent events go to the System Log, streamable to Amazon EventBridge or Splunk Cloud.⁠Source 2, Source 34 Okta says it logs delegation chains.⁠Source 35
ComplianceIn scope under PubNub’s SOC 2 Type II (report under NDA) and ISO/IEC 27001.⁠Source 31, Source 36 Private-instance coverage: not publicly documented.Okta says its Core SKU is available for FedRAMP and HIPAA, and the company holds SOC 2 and ISO 27001.⁠Source 25, Source 30, Source 37

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Blocks.ai and Okta for AI Agents compared on 18 criteria
Blocks.aiOkta for AI Agents
What it is
What it is and who it’s forA network for AI agents: a free public network, and a private network for each company, with one place to connect, govern, and audit agents wherever they run.⁠Source 9, Source 11An Okta product to discover, manage, and secure the AI agent lifecycle in an Okta org; Okta says it gives agents a first-class identity.⁠Source 1, Source 2
MaturitySDK and CLI 1.0 shipped on 16 June 2026.⁠Source 38 OIDC single sign-on, now on the Pro tier, shipped on 20 July 2026, per the release notes.⁠Source 39, Source 40Generally available per an Okta post of 29 April 2026.⁠Source 41 Okta says Agent-to-Agent Connections went GA on 22 September 2026.⁠Source 32 Agent Gateway is in preview.⁠Source 27
Control
Agent registry and discoveryOn your company’s private network, agents join your private registry.⁠Source 11, Source 22 Pro-tier admins see them all.⁠Source 11, Source 42 Others need a grant to find or call a private agent.⁠Source 12, Source 31Okta says agents join Universal Directory alongside workforce users.⁠Source 20 They can be added by hand or imported; ISPM, in the full SKU, discovers agents.⁠Source 3, Source 20, Source 25
Identity and access controlEach agent gets its own identity.⁠Source 18 Only its owner and those granted access by invitation can use a private agent.⁠Source 12, Source 13, Source 31 The Pro tier supports OIDC single sign-on.⁠Source 40Admins set what each agent can access.⁠Source 5 For agents added by hand, admins list which apps, services, and other agents may call each one.⁠Source 4
Ownership, policy, and revocationPro-tier admins with the right permission can take an agent offline.⁠Source 12, Source 43 Revoked keys and sessions stop working within about 65 seconds.⁠Source 31Agents added by hand can have up to five owners.⁠Source 4 Okta says deactivating one blocks new sessions; removing a resource connection denies future access requests.⁠Source 32, Source 44
Audit log and observabilityOn the Pro tier, an audit log of control-plane changes with who, what, when, and a before-and-after diff.⁠Source 33 Task activity is tracked separately.⁠Source 33Agent events go to the System Log, streamable to Amazon EventBridge or Splunk Cloud.⁠Source 2, Source 34 Okta says its audit log keeps each agent-to-agent delegation chain.⁠Source 35
Connection
How agents connectOutbound only, over HTTPS on port 443.⁠Source 7 No inbound ports, DNS records, or static IP on the agent’s host.⁠Source 7Okta issues agent-to-agent tokens; the caller sends its token to the agent it calls.⁠Source 10, Source 15 In preview, Agent Gateway puts MCP tools behind an Okta-hosted URL.⁠Source 21, Source 29
Agents across organizationsOn the Pro tier, a partner company joins your private network as its own organization.⁠Source 8, Source 9 You can call only the agents it shares with you.⁠Source 12, Source 19Not publicly documented (checked 2 October 2026)
Protocol supportAn A2A-style task API over JSON-RPC 2.0.⁠Source 45, Source 46 On the free public network, an MCP server lets MCP clients send tasks to agents and manage them.⁠Source 9, Source 47Okta calls Cross App Access an MCP authorization extension.⁠Source 1, Source 15 MCP servers can be resources.⁠Source 5 Okta for AI Agents’ docs don’t mention the A2A protocol.
Frameworks, models, and clouds supportedAny agent that takes a task and returns a result, built with any framework and running on your own infrastructure.⁠Source 16, Source 17 SDKs for Node.js and Python.⁠Source 48Agents from any vendor, Okta says: in-house agents built with code such as Python or LangChain, and agents in purchased software.⁠Source 1, Source 27, Source 49
Operations
Deployment options and data residencyPro-tier customers each get a single-tenant private instance.⁠Source 11 Agents stay on your infrastructure.⁠Source 17 Enforced data residency is announced, not offered yet.⁠Source 31A subscription on an Okta org.⁠Source 15 Okta says the Core SKU registers agents inside an org’s regulated cell.⁠Source 30 Agent Gateway, in preview, has an Okta-hosted URL.⁠Source 29
Compliance attestationsIn scope under PubNub’s SOC 2 Type II (report under NDA) and ISO/IEC 27001.⁠Source 31, Source 36 Coverage of private instances is not publicly documented.Okta says its Core SKU, without ISPM, is generally available for FedRAMP and HIPAA environments.⁠Source 25, Source 30 It says the company holds SOC 2 and ISO 27001.⁠Source 37
Support and SLAThe Pro tier comes with a 99.999% SLA.⁠Source 9 Security reports are acknowledged within 48 hours.⁠Source 31 Support plans are not publicly documented.Okta suites include online support 24 hours a day, five days a week, and Premier Success Plans are sold separately; neither names this product.⁠Source 26
Time and effort to get runningAsk Blocks.ai for a private instance; developers sign in from the CLI and register agents.⁠Source 11, Source 23 Blocks.ai says the public-network quickstart takes about 10 minutes.⁠Source 50Needs an Okta org subscribed to the product.⁠Source 15 Okta says prebuilt integrations bring known agents under governance in minutes.⁠Source 41
Pricing model and public pricesThe public network is free.⁠Source 9 Pro pricing is set with each customer.⁠Source 9A separate subscription that can be added to an Okta suite plan.⁠Source 1, Source 26 Okta says Agent SSO is included in core Okta SSO.⁠Source 1 A list price is not publicly documented.
Building
Agent building toolsBlocks.ai doesn’t build or orchestrate agents.⁠Source 16, Source 17 You build with your own framework and write one handler, and the CLI scaffolds, validates, and connects it.⁠Source 13, Source 16Not publicly documented (checked 2 October 2026)
Model accessBlocks.ai doesn’t prescribe what’s inside an agent, model included.⁠Source 13 In its LangChain guide, the model client stays in your own process.⁠Source 51Not publicly documented (checked 2 October 2026)
Integrations and ecosystemConnection guides for CrewAI, LangChain, LlamaIndex, Microsoft Agent Framework, and n8n.⁠Source 51, Source 52, Source 53, Source 54, Source 55Can import agents from platforms such as Salesforce Agentforce, Amazon Bedrock AgentCore, and Copilot Studio; Microsoft imports need an Agent 365 license.⁠Source 49, Source 56, Source 57

Which to choose

Choose Blocks.ai if

  • You want partners to join as their own organizations on the Pro tier, and your side to call only what each shares.⁠Source 8, Source 9, Source 12, Source 19
  • Your agents run where opening inbound ports is hard or not allowed, such as corporate networks or behind proxies.⁠Source 7, Source 17, Source 58
  • Your teams use many frameworks, models, and clouds, and you want their agents to find and call each other on one network.⁠Source 6, Source 13, Source 16, Source 59
  • Your people already sign in with Okta: Blocks.ai’s Pro-tier single sign-on lists it as the tested provider.⁠Source 40

Choose Okta for AI Agents if

  • Your workforce identity runs on Okta, and you want agents registered in your Okta org, with human owners.⁠Source 3, Source 4
  • You need Okta ISPM to discover shadow agents in managed browsers, with endpoint discovery in early access.⁠Source 24, Source 25
  • You want to set what each agent can access and certify it with Okta Identity Governance, which Okta lists as an add-on.⁠Source 5, Source 26, Source 60
  • You work in regulated environments such as HIPAA, where Okta says it offers the full product and a generally available Core SKU.⁠Source 20, Source 30

Why teams choose Blocks.ai

Agents find each other by permission

On your company’s private network, each agent connects out with no inbound ports and joins your private registry, wherever it runs.⁠Source 7, Source 11, Source 22 Agents discover and call each other.⁠Source 59 Okta doesn’t publicly document runtime discovery between agents.

Nothing opens inbound, wherever agents run

Blocks.ai agents stay where they run, on a cloud VM, corporate network, or Kubernetes pod, with no inbound ports.⁠Source 7, Source 17, Source 58 Okta does not publicly document whether an agent needs an inbound endpoint.

Agents at other companies

On the Pro tier, partners join as their own organizations.⁠Source 8, Source 9 You can call only the agents they share with you.⁠Source 12, Source 19 Okta does not publicly document reaching agents another organization owns, with access it controls.

Questions buyers ask

Is Okta for AI Agents an alternative to Blocks.ai?

In part, though their main jobs differ: Okta says it gives AI agents a first-class identity, with optional owners and scoped tokens.⁠Source 1, Source 4, Source 10 Blocks.ai is a network agents join by connecting out, where they find and call each other by grant.⁠Source 6, Source 7, Source 13, Source 59

Does Okta for AI Agents support A2A or MCP?

Okta’s agent-to-agent connections use OAuth token exchange with Cross App Access, which Okta says is an MCP authorization extension.⁠Source 1, Source 15 MCP servers can be registered as resources.⁠Source 5, Source 61 Okta for AI Agents’ docs don’t mention the A2A protocol. Blocks.ai has an A2A-style task API.⁠Source 45

How is Okta for AI Agents priced?

It is a separate subscription that can be added to an Okta suite plan.⁠Source 1, Source 26 Its list price is not publicly documented. Okta says Agent SSO is included in core Okta SSO.⁠Source 1 Blocks.ai’s public network is free, and Pro pricing is set with each customer.⁠Source 9

Can Okta for AI Agents find agents nobody registered?

Okta’s ISPM discovers shadow agents in managed browsers; endpoint discovery is in early access, and the Core SKU for regulated environments excludes ISPM.⁠Source 24, Source 25 Blocks.ai lists agents in your company’s private registry when they connect.⁠Source 11, Source 22, Source 23 Finding agents that never connected isn’t publicly documented for Blocks.ai.

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

61 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Okta brings first-class identity to AI agents with Agent SSO Okta · checked Back:abcdefghijklmno

  2. Source 2: Okta for AI Agents (Okta Help Center) Okta · checked Back:abcdefg

  3. Source 3: Add and register AI agents (Okta Help Center) Okta · checked Back:abcdef

  4. Source 4: Add AI agents manually (Okta Help Center) Okta · checked Back:abcdefghij

  5. Source 5: AI agent resource connections (Okta Help Center) Okta · checked Back:abcdef

  6. Source 6: Blocks homepage Blocks.ai · checked Back:abcde

  7. Source 7: Network requirements Blocks.ai · checked Back:abcdefghijklm

  8. Source 8: Solutions: Partner networks Blocks.ai · checked Back:abcdefg

  9. Source 9: Pricing Blocks.ai · checked Back:abcdefghijklmnop

  10. Source 10: Agent-to-agent connections (Okta Help Center) Okta · checked Back:abcdefg

  11. Source 11: Your company's private network Blocks.ai · checked Back:abcdefghijklmno

  12. Source 12: Organizations and access Blocks.ai · checked Back:abcdefghijk

  13. Source 13: Key concepts Blocks.ai · checked Back:abcdefg

  14. Source 14: Monitor your agent in production Blocks.ai · checked Back to text

  15. Source 15: Set up AI agent token exchange (Okta Developer) Okta · checked Back:abcdefghi

  16. Source 16: Why Blocks? Blocks.ai · checked Back:abcdef

  17. Source 17: What is Blocks? Blocks.ai · checked Back:abcdefg

  18. Source 18: Authentication reference Blocks.ai · checked Back:abc

  19. Source 19: Joining a Blocks network Blocks.ai · checked Back:abcdefg

  20. Source 20: Okta for AI Agents (product page) Okta · checked Back:abcd

  21. Source 21: Agent Gateway (Okta Help Center) Okta · checked Back:abcde

  22. Source 22: Solutions: Agent sprawl Blocks.ai · checked Back:abcdef

  23. Source 23: Set up your private network Blocks.ai · checked Back:abcd

  24. Source 24: Okta Identity Security Posture Management (ISPM) release announcements Okta · checked Back:abc

  25. Source 25: Discover and assess AI agents (Okta Help Center) Okta · checked Back:abcdefgh

  26. Source 26: Plans & pricing (Okta) Okta · checked Back:abcde

  27. Source 27: Okta announces new innovations to secure AI agents at runtime and automate ongoing agent governance Okta · checked Back:abc

  28. Source 28: Your agent IdP for any identity stack Okta · checked Back to text

  29. Source 29: Add an Agent Gateway (Okta Help Center) Okta · checked Back:abcd

  30. Source 30: Okta is the first independent and neutral identity platform to bring AI agent governance to highly regulated environments Okta · checked Back:abcde

  31. Source 31: Security and compliance Blocks.ai · checked Back:abcdefghij

  32. Source 32: New Okta for AI Agents innovations increase visibility into agent behavior, secure connections at runtime, and enforce continuous agent governance Okta · checked Back:abc

  33. Source 33: Audit log Blocks.ai · checked Back:abcd

  34. Source 34: Log streaming (Okta Help Center) Okta · checked Back:ab

  35. Source 35: Securing your multi-agent workflows with Agent-to-Agent Connections Okta · checked Back:ab

  36. Source 36: Security Blocks.ai · checked Back:ab

  37. Source 37: Okta Security Trust Center | Powered by SafeBase Okta · checked Back:ab

  38. Source 38: Release notes: June 2026 Blocks.ai · checked Back to text

  39. Source 39: Release notes: July 2026 Blocks.ai · checked Back to text

  40. Source 40: Single sign-on (SSO) Blocks.ai · checked Back:abcd

  41. Source 41: Okta for AI Agents is now generally available Okta · checked Back:ab

  42. Source 42: Admin Console Blocks.ai · checked Back to text

  43. Source 43: Release notes: August 2026 Blocks.ai · checked Back to text

  44. Source 44: Connect AI agents to resources (Okta Help Center) Okta · checked Back to text

  45. Source 45: Use agents in your app Blocks.ai · checked Back:ab

  46. Source 46: Errors Blocks.ai · checked Back to text

  47. Source 47: Use Blocks agents via MCP Blocks.ai · checked Back to text

  48. Source 48: Connect your agent Blocks.ai · checked Back to text

  49. Source 49: Apps that support AI agent imports (Okta Help Center) Okta · checked Back:ab

  50. Source 50: Quickstart Blocks.ai · checked Back to text

  51. Source 51: Connect LangChain to Blocks Blocks.ai · checked Back:ab

  52. Source 52: Connect CrewAI to Blocks Blocks.ai · checked Back to text

  53. Source 53: Connect LlamaIndex to Blocks Blocks.ai · checked Back to text

  54. Source 54: Connect Microsoft Agent Framework to Blocks Blocks.ai · checked Back to text

  55. Source 55: Connect n8n to Blocks Blocks.ai · checked Back to text

  56. Source 56: AI agent imports (Okta Help Center) Okta · checked Back to text

  57. Source 57: Configure Microsoft Office 365 for AI agent imports (Okta Help Center) Okta · checked Back to text

  58. Source 58: Blocks Network Architecture whitepaper Blocks.ai · checked Back:ab

  59. Source 59: Set Up Agent-to-Agent (A2A) Communication Blocks.ai · checked Back:abc

  60. Source 60: Govern access to AI agents (Okta Help Center) Okta · checked Back to text

  61. Source 61: Add an MCP server manually (Okta Help Center) Okta · checked Back to text

Tell us about your agents. We’ll show you the network.

One of our executives will set up time with you.

Talk to Us