Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

LangSmith vs Okta for AI Agents

LangSmith

Platform for observing, evaluating, and deploying agents

Okta for AI Agents

Okta offering that gives AI agents a first-class identity so organizations can discover, onboard, protect, and govern them

Short answer

LangChain calls LangSmith a platform for observing, evaluating, and deploying agents; Okta says Okta for AI Agents gives AI agents a first-class identity, alongside workforce users.⁠Source 1, Source 2, Source 3 LangSmith builds agents and runs them in LangChain’s cloud (Plus plan or above) or, on Enterprise, your own infrastructure; Okta registers agents’ credentials, and admins define their access.⁠Source 4, Source 5, Source 6, Source 7, Source 8, Source 9

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both keep a registry of agents, control who can use each agent, and log agent events.⁠Source 8, Source 10, Source 11, Source 12, Source 13, Source 14, Source 15, Source 16
Where they differ
LangSmith also builds, runs, and traces agents.⁠Source 4, Source 5, Source 13 Okta registers agents built in-house or on other platforms; Okta says they sit alongside workforce users.⁠Source 3, Source 17, Source 18
Running both
Okta’s docs list LangSmith Deployments among the apps Okta can import agents from.⁠Source 18
Public sources · checked 2 October 2026
  • Offered
  • Preview
  • Not publicly documented

LangSmith

  • Build agents: OfferedFleet agent builder⁠Source 4
  • Host and run agents: OfferedLangSmith Deployment runtime⁠Source 5
  • Identity and access: OfferedFleet per-agent permissions⁠Source 12
  • Registry and governance: OfferedCentralized registry in Deployment⁠Source 10
  • Traffic between agents, tools, and models: OfferedFleet forwards MCP tool calls⁠Source 19
  • Agents across organizations: Not publicly documented

Okta for AI Agents

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedAgent identity and credentials⁠Source 8
  • Registry and governance: OfferedUniversal Directory with human owners⁠Source 3
  • Traffic between agents, tools, and models: PreviewAgent Gateway for MCP tools⁠Source 20
  • Agents across organizations: Not publicly documented

At a glance

TopicLangSmithOkta for AI Agents
Builds and runs agentsFleet builds agents without code, and LangSmith Deployment runs agents in production on the Plus plan or above, including ones built with other frameworks.⁠Source 4, Source 5, Source 21Agent-building tools are not publicly documented. Okta registers agents built in-house or on other platforms.⁠Source 17, Source 18
Where it runsLangChain’s cloud, on GCP or AWS; or, on Enterprise, BYOC on AWS, self-hosted, or hybrid.⁠Source 6, Source 7, Source 22, Source 23A subscription on an Okta org.⁠Source 24 Its Agent Gateway, in preview, has an Okta-hosted URL.⁠Source 25
Agent identity and accessHosted deployments require a LangSmith API key by default, or your own auth handler.⁠Source 26 Fleet agents act with fixed credentials or the user’s own.⁠Source 27Okta says agents get an identity in Universal Directory, alongside workforce users.⁠Source 3 Agents added by hand use a client ID, secret, key pair, or metadata document.⁠Source 8
Pricing modelA Developer plan with one free seat, Plus at $39 per seat per month, and Enterprise through sales.⁠Source 23 Usage is metered in LSUs, $1 each.⁠Source 23A separate subscription that can be added to an Okta suite plan.⁠Source 2, Source 28 A list price is not publicly documented.
Generally availableLangChain announced GA of LangGraph Platform (now Deployment) in May 2025 and Agent Builder (now Fleet) in January 2026.⁠Source 10, Source 29, Source 30, Source 31Okta announced general availability in a post dated 29 April 2026.⁠Source 15 Okta says customers can request Agent Gateway, in preview, as a research release.⁠Source 32

What each one is

LangSmith

LangChain describes LangSmith as a framework-agnostic platform for observing, evaluating, and deploying agents.⁠Source 1 LangSmith Deployment runs agents in production, and LangChain says Fleet lets teams, including non-technical ones, create and manage agents without code.⁠Source 1, Source 4, Source 5 Agents hosted elsewhere can send it traces.⁠Source 7

Okta for AI Agents

Okta for AI Agents helps a company discover, manage, and secure the lifecycle of its AI agents in its Okta org.⁠Source 33 Okta says agents are registered in Universal Directory alongside workforce users, with human ownership assigned; admins can define which resources each can access.⁠Source 3, Source 9

The differences that matter

  1. Agents built elsewhere

    LangSmith

    Deployment can run agents from other frameworks; agents hosted elsewhere can send traces, though listing them in a registry is not publicly documented.⁠Source 7, Source 21

    Okta for AI Agents

    Okta says it manages agents from any vendor: custom-built agents can be registered by hand, and builder-platform agents imported.⁠Source 17, Source 32

    Okta ISPM discovers agents from several sources; the full SKU includes it, and the Core SKU for regulated environments excludes it.⁠Source 3, Source 34, Source 35

  2. How access is controlled

    LangSmith

    Hosted agents require a LangSmith API key by default, or your own auth handler; Fleet has per-agent Clone, Run, and Edit permissions.⁠Source 12, Source 26

    Okta for AI Agents

    Admins set which resources each agent can access; for agents added by hand, they list which apps, services, and other agents may call it.⁠Source 8, Source 9

    Okta says its Agent Gateway, in preview, checks each tool call made through it: the agent, the user behind it, and the agent’s policies.⁠Source 32

  3. Owners and approvals

    LangSmith

    Fleet shows each agent’s owner and can make agents pause for human approval before specific actions.⁠Source 14, Source 31

    Okta for AI Agents

    An agent added by hand can have up to five owners; Okta says users can request access to an agent, and admins approve time-bound permissions.⁠Source 8, Source 15

    Okta’s docs say access requests and access certifications for agents and their linked apps use Okta Identity Governance, which Okta’s pricing page lists as an add-on.⁠Source 28, Source 36

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicLangSmithOkta for AI Agents
Network exposureAgent Server offers A2A and MCP endpoints; Enterprise customers can reach LangSmith Cloud without the public internet.⁠Source 6, Source 37, Source 38Whether agents need an inbound endpoint is not publicly documented. Okta’s Agent Gateway, in preview, has an Okta-hosted URL.⁠Source 25
IdentityHosted Agent Servers default to API keys; self-hosted ones have no default authentication.⁠Source 26 Cloud Enterprise adds SAML SSO and SCIM.⁠Source 39Manually added agents identify with a client ID, secret, key pair, or metadata document.⁠Source 8 Agent-to-agent tokens are scoped and expire.⁠Source 40
Access changes and revocationFleet sharing can be revoked at any time, and organization admins can deactivate any member’s personal access token.⁠Source 14, Source 41Okta says deactivating an agent immediately blocks new sessions; removing a resource connection denies future access requests to it.⁠Source 16, Source 42
Audit trailEnterprise audit logs of admin and configuration actions, kept up to 400 days, can be pulled hourly into a SIEM.⁠Source 43Agent events land in Okta’s System Log; log streaming sends them to Amazon EventBridge or Splunk Cloud.⁠Source 33, Source 44
ComplianceLangChain lists SOC 2 Type II, ISO 27001:2022, GDPR, and HIPAA for LangSmith.⁠Source 45, Source 46Okta says the company holds SOC 2 and ISO 27001; its Core SKU is generally available for FedRAMP and HIPAA.⁠Source 35, Source 47

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

LangSmith and Okta for AI Agents compared on 18 criteria
LangSmithOkta for AI Agents
What it is
What it is and who it’s forLangChain calls it a framework-agnostic platform for observing, evaluating, and deploying agents.⁠Source 1 Deployment runs agents; Fleet is for no-code agents.⁠Source 4, Source 5An Okta product to discover, manage, and secure the AI agent lifecycle in an Okta org; Okta says it gives agents a first-class identity.⁠Source 2, Source 33
MaturityLangChain announced GA of LangGraph Platform (now Deployment) on 14 May 2025 and Agent Builder (now Fleet) on 13 January 2026.⁠Source 10, Source 29, Source 30, Source 31Okta announced general availability in a post dated 29 April 2026.⁠Source 15 On 22 July 2026, Okta said customers could request Agent Gateway, in preview.⁠Source 32
Control
Agent registry and discoveryLangChain says Deployment manages agents in a centralized registry with versioning.⁠Source 10, Source 48 Listing agents hosted elsewhere is not publicly documented.Agents can be registered in Universal Directory by hand or imported from builder platforms.⁠Source 15, Source 17 Okta ISPM, in the full SKU, discovers agents.⁠Source 3, Source 34
Identity and access controlHosted deployments use LangSmith API keys by default, or your own auth handler.⁠Source 26 Fleet agents use fixed or the user’s credentials.⁠Source 27 Enterprise adds RBAC.⁠Source 49Agents added by hand use a client ID, secret, key pair, or metadata document, and admins list which apps, services, and other agents may call each one.⁠Source 8
Ownership, policy, and revocationFleet shows each agent’s owner, has per-agent Clone, Run, and Edit permissions you can revoke at any time, and can make agents pause for approval.⁠Source 12, Source 14, Source 31Agents added by hand take optional owners, up to five individuals.⁠Source 8 Okta says deactivating an agent immediately blocks new sessions.⁠Source 16
Audit log and observabilityEnterprise audit logs of admin and configuration actions, kept up to 400 days.⁠Source 43 Each deployment gets a tracing project; Fleet traces include tool calls.⁠Source 13, Source 14Agent events land in Okta’s System Log, which can stream to Amazon EventBridge or Splunk Cloud.⁠Source 33, Source 44 Okta says agent-to-agent delegation chains are logged.⁠Source 50
Connection
How agents connectAgent Server has A2A and MCP endpoints.⁠Source 37, Source 38 On self-hosted LangSmith with Deployment, agents run behind an ingress you configure.⁠Source 51Okta issues agent-to-agent tokens, and the caller sends its token to the agent it calls.⁠Source 24, Source 40 Okta’s Agent Gateway, in preview, puts MCP tools behind one endpoint.⁠Source 20
Agents across organizationsFleet can share agents in your workspace; Agent Server agents can talk to other A2A agents.⁠Source 14, Source 37 A cross-organization access model is not publicly documented.Not publicly documented (checked 2 October 2026)
Protocol supportAgent Server supports A2A over JSON-RPC, with documented gaps, and can expose agents as MCP tools.⁠Source 37, Source 38 Fleet discovers tools from remote MCP servers.⁠Source 19MCP servers can be agent resources.⁠Source 9 Agent-to-agent calls use token exchange with Cross App Access.⁠Source 24 Okta for AI Agents’ docs don’t mention the A2A protocol.
Frameworks, models, and clouds supportedDeployment runs agents from other frameworks, such as Google ADK, CrewAI, and AutoGen.⁠Source 21 Agents hosted elsewhere can send traces to LangSmith.⁠Source 7Okta says it manages agents from any vendor, agents built in-house with code such as Python or LangChain, and agents in purchased software.⁠Source 2, Source 18, Source 32
Operations
Deployment options and data residencyCloud on GCP (US, EU, APAC) or AWS (US).⁠Source 6 BYOC on AWS, or self-hosted or hybrid, on Enterprise.⁠Source 7, Source 22, Source 23A subscription on an Okta org.⁠Source 24 Okta says its Core SKU registers agents inside an org’s regulated cell.⁠Source 35 Okta’s Agent Gateway, in preview, has an Okta-hosted URL.⁠Source 25
Compliance attestationsLangChain’s Trust Center lists SOC 2 Type II, ISO 27001:2022, GDPR, and HIPAA, with a 2026 SOC 2 Type II report and ISO 27001 certificate.⁠Source 45Okta says the company holds SOC 2 and ISO/IEC 27001 certifications.⁠Source 47 It says its Core SKU is generally available for FedRAMP and HIPAA environments.⁠Source 34, Source 35
Support and SLABase, Standard, and Premium support plans.⁠Source 52 Reasonable commercial efforts toward 99.5% API uptime for SaaS, measured quarterly.⁠Source 52Okta suites include online support 24 hours a day, five days a week; Premier Success Plans are sold separately.⁠Source 28
Time and effort to get runningCloud: Plus or above and an API key.⁠Source 53 Self-hosting the Deployment control plane: Kubernetes and Enterprise.⁠Source 5 Fleet agents start from a description or template.⁠Source 4Needs an Okta org subscribed to the product.⁠Source 24 An agent can’t use a client secret until its developer implements it.⁠Source 8
Pricing model and public pricesDeveloper plan with one free seat; Plus $39 per seat per month; Enterprise via sales.⁠Source 23 Usage is metered in LSUs, $1 each.⁠Source 23Okta says it is a separate subscription; Agent SSO is in core Okta SSO.⁠Source 2 It can be added to a suite plan.⁠Source 28 A list price is not publicly documented.
Building
Agent building toolsFleet builds no-code agents from a description or template.⁠Source 4 Code-first agents can be deployed with the LangGraph CLI and app templates.⁠Source 5Not publicly documented (checked 2 October 2026)
Model accessLangChain says LangSmith works with closed or open models.⁠Source 1 Fleet’s managed picker has three tiers (Fast, Pro, Max), not custom models.⁠Source 54Not publicly documented (checked 2 October 2026)
Integrations and ecosystemFleet has built-in tools such as Gmail; LangChain says its agents work in Slack, Teams, and Gmail.⁠Source 54, Source 55 Tracing integrates with OpenAI, Anthropic, and more.⁠Source 56Imports agents from apps such as LangSmith Deployments and Salesforce Agentforce.⁠Source 18 Okta lists Slack and Notion among Cross App Access apps.⁠Source 2

Which to choose

Choose LangSmith if

  • You want to build agents without code, from a description or a template, and use them in Slack, Teams, or Gmail.⁠Source 4, Source 55
  • You want agents run for you in LangChain’s cloud on Plus or above, or self-hosted on Enterprise, including air-gapped.⁠Source 5
  • You want traces of what agents did, whether LangSmith hosts them or they send traces from any OpenTelemetry-compatible app.⁠Source 7, Source 13, Source 14, Source 57
  • You want Fleet agents to pause before specific actions so a person can approve, edit, or reject them from one place.⁠Source 14

Choose Okta for AI Agents if

  • You want agents registered in Okta, which Okta says puts them alongside workforce users, with optional human owners.⁠Source 3, Source 8
  • Your agents come from many vendors and from in-house code, and you want one place to register them.⁠Source 15, Source 18, Source 32
  • You want admins to deactivate an agent, which Okta says blocks new sessions immediately, or remove a single resource connection.⁠Source 16, Source 42
  • You want to set exactly which agents may call other agents, with tokens scoped to one resource that expire.⁠Source 32, Source 40

Questions buyers ask

What does each one record about agent activity?

LangSmith traces capture a Fleet agent’s tool calls, decisions, and outputs, and every deployment gets a tracing project.⁠Source 13, Source 14 Okta captures agent events in its System Log and can stream them to SIEMs; its Agent Gateway, in preview, shows tool calls from the last 30 days.⁠Source 16, Source 58

How is each one priced?

LangSmith has a Developer plan with one free seat, Plus at $39 per seat per month, and Enterprise through sales; usage is metered in LSUs, $1 each.⁠Source 23 Okta says Okta for AI Agents is a separate subscription.⁠Source 2 A list price is not publicly documented.

Do they support MCP and A2A?

LangSmith’s Agent Server supports A2A, with documented gaps, and can expose agents as MCP tools.⁠Source 37, Source 38 Okta can grant agents resources behind MCP servers; its Agent Gateway, in preview, puts several servers’ tools behind one endpoint.⁠Source 9, Source 20 Okta for AI Agents’ docs don’t mention the A2A protocol.

Can either one reach agents at another organization?

Agents on LangSmith’s Agent Server can talk to other A2A-compatible agents, and Fleet can share agents within your workspace; a cross-organization access model is not publicly documented.⁠Source 14, Source 37 Okta’s docs describe agents in the customer’s own org; reaching another organization’s agents is not publicly documented.⁠Source 33

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

63 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: LangSmith: The Agent Engineering Platform LangChain · checked Back:abcde

  2. Source 2: Okta brings first-class identity to AI agents with Agent SSO Okta · checked Back:abcdefg

  3. Source 3: Okta for AI Agents (product page) Okta · checked Back:abcdefgh

  4. Source 4: No-code agents with LangSmith Fleet LangChain · checked Back:abcdefghi

  5. Source 5: LangSmith Deployment LangChain · checked Back:abcdefghi

  6. Source 6: Cloud (SaaS) LangChain · checked Back:abcd

  7. Source 7: Set up LangSmith LangChain · checked Back:abcdefg

  8. Source 8: Add AI agents manually (Okta Help Center) Okta · checked Back:abcdefghijk

  9. Source 9: AI agent resource connections (Okta Help Center) Okta · checked Back:abcde

  10. Source 10: LangSmith Deployment LangChain · checked Back:abcde

  11. Source 11: Manage agent settings LangChain · checked Back to text

  12. Source 12: Agent platform comparison LangChain · checked Back:abcd

  13. Source 13: LangSmith control plane LangChain · checked Back:abcde

  14. Source 14: Access & oversight LangChain · checked Back:abcdefghij

  15. Source 15: Okta for AI Agents is now generally available Okta · checked Back:abcdef

  16. Source 16: New Okta for AI Agents innovations increase visibility into agent behavior, secure connections at runtime, and enforce continuous agent governance Okta · checked Back:abcde

  17. Source 17: Add and register AI agents (Okta Help Center) Okta · checked Back:abcd

  18. Source 18: Apps that support AI agent imports (Okta Help Center) Okta · checked Back:abcdefgh

  19. Source 19: Remote MCP servers LangChain · checked Back:ab

  20. Source 20: Agent Gateway (Okta Help Center) Okta · checked Back:abc

  21. Source 21: Deploy other frameworks LangChain · checked Back:abc

  22. Source 22: Bring Your Own Cloud (BYOC) LangChain · checked Back:ab

  23. Source 23: LangSmith Plans and Pricing LangChain · checked Back:abcdefg

  24. Source 24: Set up AI agent token exchange (Okta Developer) Okta · checked Back:abcde

  25. Source 25: Add an Agent Gateway (Okta Help Center) Okta · checked Back:abc

  26. Source 26: Authentication & access control LangChain · checked Back:abcd

  27. Source 27: Agent identity LangChain · checked Back:ab

  28. Source 28: Plans & pricing (Okta) Okta · checked Back:abcd

  29. Source 29: LangGraph Platform is now Generally Available: Deploy & manage long-running, stateful Agents LangChain · checked Back:ab

  30. Source 30: Now GA: LangSmith Agent Builder LangChain · checked Back:ab

  31. Source 31: LangSmith Fleet changelog LangChain · checked Back:abcd

  32. Source 32: Okta announces new innovations to secure AI agents at runtime and automate ongoing agent governance Okta · checked Back:abcdefg

  33. Source 33: Okta for AI Agents (Okta Help Center) Okta · checked Back:abcde

  34. Source 34: Discover and assess AI agents (Okta Help Center) Okta · checked Back:abc

  35. Source 35: Okta is the first independent and neutral identity platform to bring AI agent governance to highly regulated environments Okta · checked Back:abcd

  36. Source 36: Govern access to AI agents (Okta Help Center) Okta · checked Back to text

  37. Source 37: A2A endpoint in Agent Server LangChain · checked Back:abcdef

  38. Source 38: MCP endpoint in Agent Server LangChain · checked Back:abcd

  39. Source 39: Authentication methods LangChain · checked Back to text

  40. Source 40: Agent-to-agent connections (Okta Help Center) Okta · checked Back:abc

  41. Source 41: Overview (administration) LangChain · checked Back to text

  42. Source 42: Connect AI agents to resources (Okta Help Center) Okta · checked Back:ab

  43. Source 43: Audit logs LangChain · checked Back:ab

  44. Source 44: Log streaming (Okta Help Center) Okta · checked Back:ab

  45. Source 45: Trust Center - LangChain LangChain · checked Back:ab

  46. Source 46: LangSmith shared responsibility model LangChain · checked Back to text

  47. Source 47: Okta Security Trust Center | Powered by SafeBase Okta · checked Back:ab

  48. Source 48: Assistants LangChain · checked Back to text

  49. Source 49: Role-based access control LangChain · checked Back to text

  50. Source 50: Securing your multi-agent workflows with Agent-to-Agent Connections Okta · checked Back to text

  51. Source 51: Enable additional LangSmith features LangChain · checked Back to text

  52. Source 52: Support Plans LangChain · checked Back:ab

  53. Source 53: Deploy your app to cloud LangChain · checked Back to text

  54. Source 54: Essentials LangChain · checked Back:ab

  55. Source 55: LangSmith Fleet LangChain · checked Back:ab

  56. Source 56: LangSmith Observability LangChain · checked Back to text

  57. Source 57: Trace with OpenTelemetry LangChain · checked Back to text

  58. Source 58: View Agent Gateway activity (Okta Help Center) Okta · checked Back to text

  59. Source 59: Your company's private network Blocks.ai · checked Back to text

  60. Source 60: Network requirements Blocks.ai · checked Back to text

  61. Source 61: Solutions: Agent sprawl Blocks.ai · checked Back to text

  62. Source 62: Solutions: Partner networks Blocks.ai · checked Back to text

  63. Source 63: Pricing Blocks.ai · checked Back to text