Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

DIY vs Okta for AI Agents: an in-house build or a first-class identity for AI agents

Build it yourself (DIY)

Building agent connections and controls in-house from open protocols, existing infrastructure, and open-source tools

Okta for AI Agents

Okta offering that gives AI agents a first-class identity so organizations can discover, onboard, protect, and govern them

Short answer

DIY is not a product: you build agent identity, access rules, and a registry on A2A and MCP, which leave authorization to you.⁠Source 1, Source 2, Source 3 Okta says Okta for AI Agents gives AI agents a first-class identity: agents get credentials and optional owners in an Okta org, and admins set their access.⁠Source 4, Source 5, Source 6, Source 7, Source 8

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both cover agent identity and access: DIY through authorization you implement on MCP and A2A, and Okta, which says it gives AI agents a first-class identity.⁠Source 1, Source 4, Source 9
Where they differ
For agent-to-agent calls, Okta issues a scoped token that the caller sends to the agent it calls.⁠Source 10, Source 11 DIY also covers the network path: gateways, service meshes, or private links.⁠Source 12, Source 13
Running both
Okta’s docs cover custom-built agents registered by hand, including agents built in-house with code such as Python or LangChain.⁠Source 6, Source 14
Public sources · checked 2 October 2026
  • Offered
  • Preview
  • You build it
  • Not publicly documented

DIY

  • Build agents: You build itOpen-source frameworks like ADK⁠Source 15
  • Host and run agents: You build itSelf-hosted, like LangGraph⁠Source 16
  • Identity and access: You build itYour own identity provider⁠Source 17
  • Registry and governance: You build itYour own agent registry⁠Source 18
  • Traffic between agents, tools, and models: You build itYour gateway and service mesh⁠Source 12
  • Agents across organizations: You build itA2A with API management⁠Source 19

Okta for AI Agents

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedAgent identity and credentials⁠Source 7
  • Registry and governance: OfferedUniversal Directory with human owners⁠Source 20
  • Traffic between agents, tools, and models: PreviewAgent Gateway for MCP tools⁠Source 21
  • Agents across organizations: Not publicly documented

At a glance

TopicDIYOkta for AI Agents
What it isAn in-house build on open protocols such as A2A and MCP, which the A2A specification calls complementary.⁠Source 1, Source 2Okta says it gives AI agents a first-class identity in an Okta org, so they can be discovered, onboarded, protected, and governed.⁠Source 4, Source 5
Agent identityIn A2A, identity is established at the HTTP layer; MCP makes authorization optional.⁠Source 9, Source 19 Keycloak’s MCP authorization support is Experimental (in preview) from MCP 2025-06-18.⁠Source 17An agent added by hand identifies to Okta with a client ID, client secret, public and private key, or Client ID Metadata Document.⁠Source 7
Agent registryBuild your own: A2A prescribes no standard API for curated registries, and the official MCP Registry, in preview, does not support private servers.⁠Source 18, Source 22Okta says agents sit in Universal Directory alongside workforce users.⁠Source 20 Owners are optional; Okta recommends at least two.⁠Source 7
Where it runsWherever you run it: Pinterest, for example, optimized for MCP servers hosted in its internal cloud.⁠Source 23A subscription on an Okta org.⁠Source 11 Agent Gateway, in preview, has an Okta-hosted URL.⁠Source 24
PricingThe A2A and MCP specifications are openly licensed, A2A under Apache 2.0.⁠Source 1, Source 2 Build and running costs are not publicly documented.A separate subscription that can be added to an Okta suite plan.⁠Source 4, Source 25 A list price is not publicly documented.

What each one is

Build it yourself (DIY)

DIY means governing agents without buying an agent platform: open protocols such as A2A and MCP combined in-house, an existing identity provider or service mesh stretched to cover agents, an in-house platform, self-hosted open-source frameworks, or no central approach; Pinterest runs its own MCP registry.⁠Source 23

Okta for AI Agents

Okta says Okta for AI Agents registers agents in Universal Directory alongside workforce users, with credentials and optional owners, and lets admins define which apps, APIs, MCP servers, and other agents each can access.⁠Source 7, Source 8, Source 20, Source 26 It is a separate subscription on an Okta org.⁠Source 4, Source 11

The differences that matter

  1. Registering agents

    DIY

    You build a registry: A2A prescribes no standard API for curated registries, and Uber and Pinterest each describe their own MCP registry.⁠Source 12, Source 18, Source 23

    Okta for AI Agents

    Okta says agents go into Universal Directory alongside workforce users; custom-built ones are added by hand, others imported from builder platforms.⁠Source 6, Source 20

    Okta’s ISPM discovers shadow agents in managed browsers, with endpoint discovery in early access; Okta’s Core SKU for regulated environments excludes ISPM.⁠Source 27, Source 28

  2. Who may call an agent

    DIY

    You set the rules: each A2A server applies its own policies, and Pinterest and Uber check MCP calls with their own auth systems.⁠Source 1, Source 12, Source 23

    Okta for AI Agents

    For agents added by hand, admins list which apps, services, and other agents may call each one.⁠Source 7 Okta checks token requests against its rules.⁠Source 10

    Okta says Cross App Access, which its agent-to-agent token exchange uses, is the official Enterprise-Managed Authorization extension for MCP.⁠Source 4, Source 11

  3. Agents at other companies

    DIY

    A2A is designed for agents built by different companies, on separate servers; each server authorizes requests under its own policies.⁠Source 1, Source 29

    Okta for AI Agents

    Okta’s docs describe managing agents in your own Okta org.⁠Source 5, Source 11 Reaching agents another organization owns, with access it controls, is not publicly documented.

    The A2A docs highly recommend API management for A2A servers exposed across organizational boundaries.⁠Source 19

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicDIYOkta for AI Agents
Network exposureMCP servers on Streamable HTTP expose an HTTP endpoint; A2A agents declare a URL, HTTPS in production over HTTP.⁠Source 1, Source 30Whether agents need an inbound endpoint is not publicly documented. Agent Gateway, in preview, has an Okta-hosted URL.⁠Source 24
IdentityIn A2A, identity is set at the HTTP layer and credentials come out of band.⁠Source 1, Source 19 MCP authorization is optional.⁠Source 9Manually added agents identify with a client ID, secret, key pair, or metadata document.⁠Source 7 Agent-to-agent tokens are scoped and expire.⁠Source 10
Access changes and revocationEach A2A server authorizes requests under its own policies, and the specification calls that logic implementation-specific.⁠Source 1Okta says deactivating an agent immediately blocks new sessions.⁠Source 31 Removing a resource connection denies future access requests to it.⁠Source 32
Audit trailA2A docs advise auditing significant events, such as task creation and agent actions, and tracing, for example with OpenTelemetry.⁠Source 19Agent events go to the System Log, streamable to Amazon EventBridge or Splunk Cloud.⁠Source 5, Source 33 Okta says it logs delegation chains.⁠Source 34
ComplianceSits with the implementer: A2A docs say to ensure compliance with regulations such as GDPR, CCPA, and HIPAA.⁠Source 19Okta says its Core SKU is available for FedRAMP and HIPAA, and the company holds SOC 2 and ISO 27001.⁠Source 28, Source 35, Source 36

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

DIY and Okta for AI Agents compared on 18 criteria
DIYOkta for AI Agents
What it is
What it is and who it’s forAn in-house build on protocols such as A2A, an open standard for communication between agent systems, and MCP, which A2A’s specification calls complementary.⁠Source 1Okta says it gives AI agents a first-class identity so organizations can discover, onboard, protect, and govern them, in their Okta org.⁠Source 4, Source 5
MaturityVaries by component: MCP’s latest specification revision is 2026-07-28.⁠Source 3 The official MCP Registry is in preview and may have breaking changes.⁠Source 22Okta announced general availability in a post dated 29 April 2026.⁠Source 26 Agent Gateway is in preview; Okta said on 22 September 2026 that GA was planned for Q3.⁠Source 31, Source 37
Control
Agent registry and discoveryBuild your own: A2A prescribes no standard API for curated registries.⁠Source 18 The official MCP Registry is in preview and does not support private servers.⁠Source 22Okta says agents join Universal Directory alongside workforce users.⁠Source 20 They can be added by hand or imported.⁠Source 6 Okta ISPM, in the full SKU, discovers agents.⁠Source 20, Source 28
Identity and access controlIn A2A, identity is established at the HTTP layer and authorization logic is implementation-specific.⁠Source 1, Source 19 MCP authorization is optional.⁠Source 9Admins set what each agent can access.⁠Source 8 For agents added by hand, admins list which apps, services, and other agents may call each one.⁠Source 7
Ownership, policy, and revocationMCP says implementers should build consent and authorization flows.⁠Source 3 Uber starts every MCP server and tool disabled until its owning team reviews and enables it.⁠Source 12Hand-added agents take up to five optional owners.⁠Source 7 Okta says deactivating one blocks new sessions; removing a resource connection denies future access requests.⁠Source 31, Source 32
Audit log and observabilityA2A docs advise auditing significant events and tracing, for example with OpenTelemetry.⁠Source 19 MCP documents trace context propagation.⁠Source 38Agent events go to the System Log, streamable to Amazon EventBridge or Splunk Cloud.⁠Source 5, Source 33 Okta says its audit log keeps each agent-to-agent delegation chain.⁠Source 34
Connection
How agents connectMCP servers on Streamable HTTP expose an endpoint; A2A agents declare a URL, HTTPS in production over HTTP.⁠Source 1, Source 30 AWS PrivateLink privately connects VPCs to services.⁠Source 13Okta issues agent-to-agent tokens; the caller sends its token to the agent it calls.⁠Source 10, Source 11 In preview, Agent Gateway puts MCP tools behind one Okta endpoint.⁠Source 21
Agents across organizationsA2A is designed for agents built by different companies, on separate servers.⁠Source 29 Each server authorizes requests under its own policies.⁠Source 1Not publicly documented (checked 2 October 2026)
Protocol supportMCP defines stdio and Streamable HTTP transports.⁠Source 39 A2A maps to JSON-RPC, gRPC, and HTTP/REST bindings.⁠Source 1MCP servers can be resources.⁠Source 8 Agent-to-agent calls use OAuth token exchange with Cross App Access, which Okta calls an MCP authorization extension.⁠Source 4, Source 11
Frameworks, models, and clouds supportedA2A gives agents built with different frameworks, languages, or vendors a common language.⁠Source 1 Google’s ADK says it is model-agnostic and deployment-agnostic.⁠Source 15Agents from any vendor, Okta says, including agents built in-house with code such as Python or LangChain, and agents in purchased software.⁠Source 4, Source 14, Source 37
Operations
Deployment options and data residencyWherever you run it: Pinterest optimized for MCP servers in its internal cloud.⁠Source 23 A2A leaves protecting stored data to your own policies.⁠Source 19A subscription on an Okta org.⁠Source 11 Okta says the Core SKU registers agents inside an org’s regulated cell.⁠Source 35 Agent Gateway, in preview, has an Okta-hosted URL.⁠Source 24
Compliance attestationsSits with the implementer: A2A docs cite regulations such as GDPR, CCPA, and HIPAA, and MCP leaves access controls and data protection to implementers.⁠Source 3, Source 19Okta says its Core SKU, without ISPM, is generally available for FedRAMP and HIPAA environments.⁠Source 28, Source 35 It says the company holds SOC 2 and ISO 27001.⁠Source 36
Support and SLADepends on the component: MCP SDKs are tiered partly by maintenance commitments.⁠Source 40 The official MCP Registry, in preview, gives no uptime guarantees.⁠Source 41Okta suites include online support 24 hours a day, five days a week.⁠Source 25 Premier Success Plans are sold separately.⁠Source 25
Time and effort to get runningA curated A2A registry is a service you deploy and maintain.⁠Source 18 Pinterest built a unified deployment pipeline after new MCP servers took too much setup.⁠Source 23Needs an Okta org subscribed to Okta for AI Agents.⁠Source 11 A client secret works only once the agent’s developer implements it.⁠Source 7
Pricing model and public pricesThe A2A and MCP specifications are openly licensed, A2A under Apache 2.0.⁠Source 1, Source 2 Build and running costs are not publicly documented.A separate subscription that can be added to an Okta suite plan.⁠Source 4, Source 25 Okta says Agent SSO is included in core Okta SSO.⁠Source 4 A list price is not publicly documented.
Building
Agent building toolsFrameworks such as LangGraph and Google’s open-source Agent Development Kit build and deploy agents.⁠Source 15, Source 16 A2A has SDKs in six languages.⁠Source 42Not publicly documented (checked 2 October 2026)
Model accessChosen by whoever builds the agents: Google’s ADK says it is optimized for Gemini and model-agnostic.⁠Source 15Not publicly documented (checked 2 October 2026)
Integrations and ecosystemThe official MCP Registry, in preview, has a REST API for clients and aggregators to discover MCP servers.⁠Source 22Can import agents from platforms such as Salesforce Agentforce, Amazon Bedrock AgentCore, and Copilot Studio; Microsoft imports need an Agent 365 license.⁠Source 14, Source 43, Source 44

Which to choose

Choose DIY if

  • You want no agent platform contract: the A2A and MCP specifications are openly licensed, A2A under Apache 2.0.⁠Source 1, Source 2
  • Other companies’ agents need to call yours: A2A is designed for agents built by different companies, and its docs cover cross-organization servers.⁠Source 19, Source 29
  • You already run a service mesh or access-control system and want it to check agent calls, as Pinterest and Uber do.⁠Source 12, Source 23
  • You want your own review rules: Uber starts every MCP server and tool disabled until its owning team reviews and enables it.⁠Source 12

Choose Okta for AI Agents if

  • You run an Okta org and want agents registered there, with human owners.⁠Source 6, Source 7, Source 11
  • You need Okta ISPM to discover shadow agents in managed browsers, with endpoint discovery in early access.⁠Source 27, Source 28
  • You want access requests and certifications for agents through Okta Identity Governance, which Okta lists as an add-on.⁠Source 25, Source 45
  • You work in regulated environments such as HIPAA, where Okta says it offers the full product and a generally available Core SKU.⁠Source 20, Source 35

Questions buyers ask

Is Okta for AI Agents an alternative to building it yourself?

For agent identity and access, yes: it registers agents, gives them credentials, and lets admins set what each can access.⁠Source 6, Source 7, Source 8 Agent Gateway, which Okta says checks each MCP tool call, is in preview.⁠Source 21, Source 37 Reaching other organizations’ agents under their control isn’t publicly documented.

Does Okta for AI Agents support MCP and A2A?

MCP servers can be registered as resources an agent is granted.⁠Source 8 In preview, Agent Gateway puts tools from several remote MCP servers behind one Okta endpoint.⁠Source 21 Agent-to-agent connections use token exchange.⁠Source 11 Okta for AI Agents’ docs don’t mention the A2A protocol.

What do A2A and MCP say about agent identity?

In A2A, identity is established at the HTTP layer, and clients get credentials outside the protocol.⁠Source 1, Source 19 MCP makes authorization optional and leaves the authorization server’s implementation out of scope; Keycloak documents its use as one, Experimental (in preview) from MCP 2025-06-18.⁠Source 9, Source 17

How do the costs compare?

Okta for AI Agents is a separate subscription that can be added to an Okta suite plan.⁠Source 4, Source 25 Its list price is not publicly documented. For DIY, the A2A and MCP specifications are openly licensed.⁠Source 1, Source 2 Build and running costs are not publicly documented.

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

50 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Agent2Agent (A2A) Protocol Specification a2a-protocol.org · checked Back:abcdefghijklmnopqrs

  2. Source 2: modelcontextprotocol/modelcontextprotocol LICENSE (GitHub) github.com · checked Back:abcdef

  3. Source 3: Specification - Model Context Protocol 2026-07-28 modelcontextprotocol.io · checked Back:abcd

  4. Source 4: Okta brings first-class identity to AI agents with Agent SSO Okta · checked Back:abcdefghijkl

  5. Source 5: Okta for AI Agents (Okta Help Center) Okta · checked Back:abcdef

  6. Source 6: Add and register AI agents (Okta Help Center) Okta · checked Back:abcdef

  7. Source 7: Add AI agents manually (Okta Help Center) Okta · checked Back:abcdefghijkl

  8. Source 8: AI agent resource connections (Okta Help Center) Okta · checked Back:abcdefg

  9. Source 9: Authorization - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back:abcde

  10. Source 10: Agent-to-agent connections (Okta Help Center) Okta · checked Back:abcd

  11. Source 11: Set up AI agent token exchange (Okta Developer) Okta · checked Back:abcdefghijk

  12. Source 12: Designing MCP Gateway Uber's MCP Management Platform - Uber Blog uber.com · checked Back:abcdefg

  13. Source 13: What is AWS PrivateLink? - Amazon Virtual Private Cloud docs.aws.amazon.com · checked Back:ab

  14. Source 14: Apps that support AI agent imports (Okta Help Center) Okta · checked Back:abc

  15. Source 15: google/adk-python README (GitHub) github.com · checked Back:abcd

  16. Source 16: langchain-ai/langgraph README (GitHub) github.com · checked Back:ab

  17. Source 17: Integrating with Model Context Protocol (MCP) - Keycloak keycloak.org · checked Back:abc

  18. Source 18: Agent Discovery - A2A Protocol a2a-protocol.org · checked Back:abcde

  19. Source 19: Enterprise Features - A2A Protocol a2a-protocol.org · checked Back:abcdefghijkl

  20. Source 20: Okta for AI Agents (product page) Okta · checked Back:abcdefg

  21. Source 21: Agent Gateway (Okta Help Center) Okta · checked Back:abcd

  22. Source 22: The MCP Registry - Model Context Protocol modelcontextprotocol.io · checked Back:abcd

  23. Source 23: Building an MCP Ecosystem at Pinterest - Pinterest Engineering Blog medium.com · checked Back:abcdefg

  24. Source 24: Add an Agent Gateway (Okta Help Center) Okta · checked Back:abc

  25. Source 25: Plans & pricing (Okta) Okta · checked Back:abcdef

  26. Source 26: Okta for AI Agents is now generally available Okta · checked Back:ab

  27. Source 27: Okta Identity Security Posture Management (ISPM) release announcements Okta · checked Back:ab

  28. Source 28: Discover and assess AI agents (Okta Help Center) Okta · checked Back:abcde

  29. Source 29: a2aproject/A2A README (GitHub) github.com · checked Back:abc

  30. Source 30: Streamable HTTP - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back:ab

  31. Source 31: New Okta for AI Agents innovations increase visibility into agent behavior, secure connections at runtime, and enforce continuous agent governance Okta · checked Back:abc

  32. Source 32: Connect AI agents to resources (Okta Help Center) Okta · checked Back:ab

  33. Source 33: Log streaming (Okta Help Center) Okta · checked Back:ab

  34. Source 34: Securing your multi-agent workflows with Agent-to-Agent Connections Okta · checked Back:ab

  35. Source 35: Okta is the first independent and neutral identity platform to bring AI agent governance to highly regulated environments Okta · checked Back:abcd

  36. Source 36: Okta Security Trust Center | Powered by SafeBase Okta · checked Back:ab

  37. Source 37: Okta announces new innovations to secure AI agents at runtime and automate ongoing agent governance Okta · checked Back:abcd

  38. Source 38: Key Changes - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back to text

  39. Source 39: Transports - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back to text

  40. Source 40: SDK Tiers - Model Context Protocol modelcontextprotocol.io · checked Back to text

  41. Source 41: MCP Registry Aggregators - Model Context Protocol modelcontextprotocol.io · checked Back to text

  42. Source 42: A2A protocol roadmap a2a-protocol.org · checked Back to text

  43. Source 43: AI agent imports (Okta Help Center) Okta · checked Back to text

  44. Source 44: Configure Microsoft Office 365 for AI agent imports (Okta Help Center) Okta · checked Back to text

  45. Source 45: Govern access to AI agents (Okta Help Center) Okta · checked Back to text

  46. Source 46: Your agent IdP for any identity stack Okta · checked Back to text

  47. Source 47: Your company's private network Blocks.ai · checked Back to text

  48. Source 48: Network requirements Blocks.ai · checked Back to text

  49. Source 49: Solutions: Agent sprawl Blocks.ai · checked Back to text

  50. Source 50: Single sign-on (SSO) Blocks.ai · checked Back to text