Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

MuleSoft Agent Fabric vs Okta for AI Agents

MuleSoft Agent Fabric

Control plane for agents, MCP servers, and APIs across platforms

Okta for AI Agents

Okta offering that gives AI agents a first-class identity so organizations can discover, onboard, protect, and govern them

Short answer

MuleSoft Agent Fabric is a control plane for agents, MCP servers, and APIs, enforcing policy at its Omni Gateway; Okta says Okta for AI Agents gives AI agents a first-class identity, alongside workforce users.⁠Source 1, Source 2, Source 3, Source 4 Agent Fabric orchestrates A2A-compliant agents; admins set which resources each agent can access in Okta, whose Agent Gateway is in preview.⁠Source 2, Source 5, Source 6, Source 7

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both register agents built on other platforms, control what agents can access, can switch an agent off, and log agent events.⁠Source 2, Source 6, Source 8, Source 9, Source 10
Where they differ
Agent Fabric puts Omni Gateway in managed agents’ request path and orchestrates agents with brokers; Okta says it gives agents identities and credentials, and issues scoped tokens for agent-to-agent calls.⁠Source 2, Source 3, Source 4, Source 5, Source 11, Source 12
Running both
Neither vendor publicly documents using the two together. MuleSoft’s docs say rogue-agent detection needs an identity provider that issues JWTs naming each agent.⁠Source 1, Source 8
Public sources · checked 2 October 2026
  • Offered
  • Preview
  • Not publicly documented

MuleSoft Agent Fabric

  • Build agents: OfferedAgent brokers in Agent Script⁠Source 2
  • Host and run agents: OfferedAgent brokers on CloudHub 2.0⁠Source 2
  • Identity and access: OfferedOmni Gateway authentication and authorization⁠Source 2
  • Registry and governance: OfferedAgent Registry in Anypoint Exchange⁠Source 2
  • Traffic between agents, tools, and models: OfferedOmni Gateway in request path⁠Source 2
  • Agents across organizations: Not publicly documented

Okta for AI Agents

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedAgent identity and credentials⁠Source 11
  • Registry and governance: OfferedUniversal Directory with human owners⁠Source 4
  • Traffic between agents, tools, and models: PreviewAgent Gateway for MCP tools⁠Source 7
  • Agents across organizations: Not publicly documented

At a glance

TopicMuleSoft Agent FabricOkta for AI Agents
What it isMuleSoft documents it as a control plane for agents, MCP servers, and APIs across platforms.⁠Source 1Okta says it gives agents a first-class identity, registering them in Universal Directory alongside workforce users.⁠Source 3, Source 4
Where it runsAgent Fabric runs on MuleSoft-hosted Anypoint control planes in supported geographies.⁠Source 13 Omni Gateway can be managed or self-managed.⁠Source 1In an Okta org subscribed to it.⁠Source 14 Agent Gateway, in preview, has an Okta-hosted URL.⁠Source 15
Agent identityFor rogue-agent detection, agents are set up as service identities in your enterprise identity provider.⁠Source 8 In API Manager, GoDaddy ANS registration gives an agent a verifiable identity based on domain ownership.⁠Source 16Okta says agents are identities in Universal Directory; manually added ones identify to Okta with a client ID, secret, key pair, or metadata document.⁠Source 4, Source 11
Pricing modelMuleSoft packages start at $2,000 a month, billed annually, with usage metered in Mule Credits.⁠Source 17 MuleSoft lists the Agent Fabric package with no price: contact sales.⁠Source 17A separate subscription that can be added to an Okta suite plan.⁠Source 3, Source 18 A list price is not publicly documented.
Generally availableYes, MuleSoft says, with new capabilities each month.⁠Source 19 The first release note is dated 3 October 2025.⁠Source 5Okta announced general availability in a post dated 29 April 2026.⁠Source 20 Okta says Agent Gateway, a research release in preview, could be requested as of 22 July 2026.⁠Source 21

What each one is

MuleSoft Agent Fabric

MuleSoft documents Agent Fabric as a control plane for agents, MCP servers, and APIs across platforms.⁠Source 1 Scanners and manual registration fill its registry, Omni Gateway enforces policy in managed agents’ request path, and agent brokers orchestrate A2A-compliant agents.⁠Source 2, Source 5, Source 22

Okta for AI Agents

Okta for AI Agents, sold as a separate Okta subscription, helps an organization discover, manage, and secure the AI agent lifecycle in its Okta org.⁠Source 3, Source 23 Okta says agents are registered in Universal Directory alongside workforce users; admins can define which resources each agent can access.⁠Source 4, Source 6

The differences that matter

  1. How access is checked

    MuleSoft Agent Fabric

    Omni Gateway sits in the request path of each managed agent, API, or MCP server, and can require authentication and limit which tools agents call.⁠Source 2

    Okta for AI Agents

    For agent-to-agent calls, Okta checks configured rules and issues an expiring, resource-scoped token; the caller sends it to the agent it calls.⁠Source 12, Source 14

    Okta’s Agent Gateway, in preview, puts tools from several remote MCP servers behind one Okta endpoint and, Okta says, checks each tool call through it.⁠Source 7, Source 21

  2. Agents from other platforms

    MuleSoft Agent Fabric

    Scanners register agents, APIs, and MCP servers they find on supported platforms; agents can also be added by uploading an agent card.⁠Source 2, Source 22

    Okta for AI Agents

    Custom-built agents can be registered by hand; agents from apps such as Salesforce Agentforce and Amazon Bedrock AgentCore can be imported.⁠Source 9, Source 24

    Okta Identity Security Posture Management, which the full SKU includes, discovers agents from several sources; MuleSoft’s scanners run at most once a day.⁠Source 4, Source 25, Source 26

  3. Agents acting for users

    MuleSoft Agent Fabric

    MuleSoft says an agent calling other agents, MCP servers, or APIs still acts as a specific user, through your existing OAuth setup and identity provider.⁠Source 19

    Okta for AI Agents

    An agent can act for a user only if that user is signed in to its linked app.⁠Source 11

    Okta’s docs say access requests and access certifications for agents and their linked apps use Okta Identity Governance, which Okta’s pricing page lists as an add-on.⁠Source 18, Source 27

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicMuleSoft Agent FabricOkta for AI Agents
Network exposureOmni Gateway sits in managed agents’ request path; agent-network ingress gateways get a public endpoint, egress gateways none.⁠Source 2, Source 28Whether agents need an inbound endpoint is not publicly documented. Agent Gateway, in preview, has an Okta-hosted URL.⁠Source 15
IdentityFor rogue-agent detection, agents are service identities in your identity provider; an Omni Gateway policy supports OAuth token exchange.⁠Source 8, Source 29Manually added agents identify with a client ID, secret, key pair, or metadata document; agent-to-agent tokens are resource-scoped and expire.⁠Source 11, Source 12
Access changes and revocationAfter review, quarantine stops a flagged agent from acting and blocks it at model proxies with the Kill Switch policy.⁠Source 8Okta says deactivating an agent immediately blocks new sessions; removing a resource connection denies future access requests to it.⁠Source 10, Source 30
Audit trailOmni Gateway can keep a traffic audit trail; Anypoint Platform audit logs are kept one year by default.⁠Source 2, Source 31Agent events land in Okta’s System Log; log streaming sends them to Amazon EventBridge or Splunk Cloud.⁠Source 23, Source 32
ComplianceMuleSoft says Anypoint Platform meets ISO 27001, SOC 2, PCI DSS, and HIPAA.⁠Source 33 Agent Fabric’s own scope: not publicly documented.Okta says the company holds SOC 2 and ISO 27001; its Core SKU is generally available for FedRAMP and HIPAA.⁠Source 34, Source 35

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

MuleSoft Agent Fabric and Okta for AI Agents compared on 18 criteria
MuleSoft Agent FabricOkta for AI Agents
What it is
What it is and who it’s forControl plane for agents, MCP servers, and APIs across platforms.⁠Source 1 MuleSoft says it discovers, governs, orchestrates, and observes agents.⁠Source 36An Okta product to discover, manage, and secure the AI agent lifecycle in an Okta org; Okta says it gives agents a first-class identity.⁠Source 3, Source 23
MaturityMuleSoft says it is generally available, with new capabilities each month.⁠Source 19 Its first release note is dated 3 October 2025.⁠Source 5Okta announced general availability in a post dated 29 April 2026.⁠Source 20 Okta says Agent Gateway, in preview, could be requested as of 22 July 2026.⁠Source 21
Control
Agent registry and discoveryOne inventory of agents, MCP servers, and APIs, whichever platform built them.⁠Source 2 Scanners on supported platforms fill it; agents can also be added by agent card.⁠Source 2, Source 22Agents can be registered in Universal Directory, by hand or imported from builder platforms; admins see them in one list.⁠Source 9, Source 20
Identity and access controlOmni Gateway can require authentication and authorization and limit which tools and APIs an agent can call.⁠Source 2 User roles come from Anypoint access management.⁠Source 1Agents added by hand use a client ID, secret, key pair, or metadata document, and admins list which apps, services, and other agents may call each one.⁠Source 11
Ownership, policy, and revocationGovernance strategies set rules for in-scope agents, APIs, and MCP servers and can block or flag noncompliance.⁠Source 2 A flagged agent can be quarantined after review.⁠Source 8Agents added by hand take up to five optional owners.⁠Source 11 Okta says admins can deactivate an agent or one resource connection and set which agents may call others.⁠Source 10, Source 21, Source 30
Audit log and observabilityOmni Gateway can keep a traffic audit trail.⁠Source 2 Platform audit logs are kept a year by default; Integration Advanced or Titanium adds export to third-party tools.⁠Source 31Agent events land in Okta’s System Log, which can stream to Amazon EventBridge or Splunk Cloud.⁠Source 23, Source 32 Agent Gateway, in preview, shows 30 days of tool calls.⁠Source 37
Connection
How agents connectOmni Gateway sits in the request path of each managed agent, API, or MCP server.⁠Source 2 An egress gateway carries agent networks’ calls to agents outside the network.⁠Source 28For agent-to-agent calls, the caller sends its Okta-issued token to the agent it calls.⁠Source 12, Source 14 Agent Gateway, in preview, can be an agent’s remote MCP endpoint.⁠Source 15
Agents across organizationsAn egress gateway enforces policy on agent networks’ calls to agents outside the network.⁠Source 28 Partner-held access controls: not publicly documented.Not publicly documented (checked 2 October 2026)
Protocol supportOmni Gateway supports MCP and A2A, and A2A powers orchestration in agent networks.⁠Source 38, Source 39 MCP Bridge turns an existing API into an MCP server without custom code.⁠Source 2MCP-protected resources can be granted to agents.⁠Source 6 Agent-to-agent calls use Cross App Access.⁠Source 14 Okta for AI Agents’ docs don’t mention the A2A protocol.
Frameworks, models, and clouds supportedMuleSoft calls it vendor agnostic and says its scanners cover Amazon, Google, Microsoft, Databricks, and more.⁠Source 19, Source 36 Brokers orchestrate only A2A-compliant agents.⁠Source 2Okta says it manages agents from any vendor, including agents in purchased software.⁠Source 3, Source 21 In-house agents built with Python or LangChain can be registered.⁠Source 24
Operations
Deployment options and data residencyAgent Fabric runs on MuleSoft-hosted regional control planes; Omni Gateway can be self-managed.⁠Source 13, Source 40 Self-hosting its control plane isn’t publicly documented.A subscription on an Okta org.⁠Source 14 Okta says its Core SKU registers agents in the org’s regulated cell.⁠Source 35 Agent Gateway, in preview, has an Okta-hosted URL.⁠Source 15
Compliance attestationsMuleSoft says Anypoint Platform meets ISO 27001, SOC 2, PCI DSS, HIPAA, and GDPR.⁠Source 33 An attestation naming Agent Fabric is not publicly documented.Okta says the company holds SOC 2 and ISO/IEC 27001 certifications.⁠Source 34 It says its Core SKU is generally available for FedRAMP and HIPAA environments.⁠Source 25, Source 35
Support and SLAMuleSoft’s Cloud Offerings SLA commits to 99.95% monthly for covered services, on subscriptions started by 1 May 2025.⁠Source 41 Anypoint plans include Premier Success.⁠Source 42Okta suites include online support 24 hours a day, five days a week; Premier Success Plans are available to buy.⁠Source 18
Time and effort to get runningWith product access, an admin turns Agent Fabric on.⁠Source 1 Agent networks need a Managed Omni Gateway; rogue-agent detection needs an IdP that issues JWTs.⁠Source 1An Okta org subscribed to it.⁠Source 14 Okta lists prebuilt integrations with Salesforce Agentforce, Amazon Bedrock AgentCore, and ServiceNow AI Platform.⁠Source 20
Pricing model and public pricesMuleSoft packages start at $2,000 a month, billed annually, with usage in Mule Credits.⁠Source 17 MuleSoft lists the Agent Fabric package with no price: contact sales.⁠Source 17Okta says it is a separate subscription, which its pricing page lists as an add-on to suite plans.⁠Source 3, Source 18 A list price is not publicly documented.
Building
Agent building toolsAgent networks are defined in YAML, brokers in Agent Script.⁠Source 2, Source 43 MuleSoft says Salesforce’s separate Agentforce is for building agents within Salesforce.⁠Source 19Not publicly documented (checked 2 October 2026)
Model accessBrokers support OpenAI, Azure OpenAI, Bedrock OpenAI, and Gemini models.⁠Source 43 Model Proxy is one access layer for several providers, with spend caps.⁠Source 2, Source 44Not publicly documented (checked 2 October 2026)
Integrations and ecosystemCurated public MCP servers from the Official MCP Registry and Informatica.⁠Source 2 Policies can apply to APIs on Apigee, Kong Gateway, or Azure API Management.⁠Source 45Imports agents from Salesforce Agentforce, Amazon Bedrock AgentCore, Copilot Studio, and more.⁠Source 24 Okta lists Slack and Notion among Cross App Access apps.⁠Source 3

Which to choose

Choose MuleSoft Agent Fabric if

  • You want policy enforced in managed agents’ request path, by a gateway you can self-manage in a data center or on Kubernetes.⁠Source 2, Source 40
  • You want one inventory of agents, MCP servers, and APIs, with scanners that MuleSoft says cover Amazon, Google, Microsoft, and more.⁠Source 2, Source 36
  • You want brokers to orchestrate A2A-compliant agents, with caps on each caller’s model spend.⁠Source 2, Source 5
  • You already use MuleSoft: Agent Fabric uses Anypoint Platform access management, and MuleSoft says it has hundreds of enterprise connectors.⁠Source 1, Source 19

Choose Okta for AI Agents if

  • You want agents registered in Okta, which Okta says puts them alongside workforce users, with optional human owners.⁠Source 4, Source 11
  • You want to control which agents may call other agents, with Okta issuing tokens scoped to one resource that expire.⁠Source 12, Source 21
  • You want access requests and certifications for agents, which Okta’s docs say use Okta Identity Governance, an add-on on Okta’s pricing page.⁠Source 18, Source 27
  • You want to deactivate an agent, which Okta says blocks new sessions immediately, or cut a single resource connection.⁠Source 10, Source 30

Questions buyers ask

Do both work with Salesforce Agentforce agents?

MuleSoft says Salesforce’s separate Agentforce is for building agents within Salesforce.⁠Source 19 Agent Fabric’s scanners cover it, MuleSoft says, and an A2A bridge lets Agent Fabric orchestrate Agentforce agents.⁠Source 1, Source 46, Source 47 Okta can import Agentforce agents and says it has a prebuilt Agentforce integration.⁠Source 20, Source 24

How is each one priced?

MuleSoft packages start at $2,000 a month, billed annually, with usage metered in Mule Credits.⁠Source 17 MuleSoft lists the Agent Fabric package with no price: contact sales.⁠Source 17 Okta says Okta for AI Agents is a separate subscription.⁠Source 3 Its list price is not publicly documented.

Do they support MCP and A2A?

Agent Fabric’s Omni Gateway supports both; MCP Bridge turns an existing API into an MCP server.⁠Source 2, Source 38 Okta can grant agents resources behind MCP servers, and its Agent Gateway for MCP tools is in preview.⁠Source 6, Source 7 Okta for AI Agents’ docs don’t mention the A2A protocol.

Can either one connect agents across organizations?

Agent Fabric’s egress gateway enforces policy on agent networks’ calls to agents outside the network.⁠Source 28 For both products, a way for another organization to bring in its own agents while keeping control of their access is not publicly documented.

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

52 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Get Started with Agent Fabric Salesforce · checked Back:abcdefghijk

  2. Source 2: Agent Fabric Overview Salesforce · checked Back:abcdefghijklmnopqrstuvwxyz272829

  3. Source 3: Okta brings first-class identity to AI agents with Agent SSO Okta · checked Back:abcdefghij

  4. Source 4: Okta for AI Agents (product page) Okta · checked Back:abcdefgh

  5. Source 5: Agent Fabric Release Notes Salesforce · checked Back:abcdef

  6. Source 6: AI agent resource connections (Okta Help Center) Okta · checked Back:abcde

  7. Source 7: Agent Gateway (Okta Help Center) Okta · checked Back:abcd

  8. Source 8: Detect and Contain Rogue Agents Salesforce · checked Back:abcdef

  9. Source 9: Add and register AI agents (Okta Help Center) Okta · checked Back:abc

  10. Source 10: New Okta for AI Agents innovations increase visibility into agent behavior, secure connections at runtime, and enforce continuous agent governance Okta · checked Back:abcd

  11. Source 11: Add AI agents manually (Okta Help Center) Okta · checked Back:abcdefgh

  12. Source 12: Agent-to-agent connections (Okta Help Center) Okta · checked Back:abcde

  13. Source 13: Salesforce Hyperforce Overview Salesforce · checked Back:ab

  14. Source 14: Set up AI agent token exchange (Okta Developer) Okta · checked Back:abcdef

  15. Source 15: Add an Agent Gateway (Okta Help Center) Okta · checked Back:abcd

  16. Source 16: Register Agents with GoDaddy ANS Salesforce · checked Back to text

  17. Source 17: MuleSoft Pricing | Plans From $2,000 a Month Salesforce · checked Back:abcdef

  18. Source 18: Plans & pricing (Okta) Okta · checked Back:abcde

  19. Source 19: See Every Agent. Govern Every Agent. Control AI Costs. (mulesoft.com home page) Salesforce · checked Back:abcdefg

  20. Source 20: Okta for AI Agents is now generally available Okta · checked Back:abcde

  21. Source 21: Okta announces new innovations to secure AI agents at runtime and automate ongoing agent governance Okta · checked Back:abcdef

  22. Source 22: Register Services Manually Salesforce · checked Back:abc

  23. Source 23: Okta for AI Agents (Okta Help Center) Okta · checked Back:abcd

  24. Source 24: Apps that support AI agent imports (Okta Help Center) Okta · checked Back:abcd

  25. Source 25: Discover and assess AI agents (Okta Help Center) Okta · checked Back:ab

  26. Source 26: Discovering and Cataloging External Services with Scanners Salesforce · checked Back to text

  27. Source 27: Govern access to AI agents (Okta Help Center) Okta · checked Back:ab

  28. Source 28: Deploying Agent Network Ingress and Egress Managed Omni Gateways Salesforce · checked Back:abcd

  29. Source 29: OAuth 2.0 OBO Credential Injection Policy Salesforce · checked Back to text

  30. Source 30: Connect AI agents to resources (Okta Help Center) Okta · checked Back:abc

  31. Source 31: Audit Logging in Anypoint Platform Salesforce · checked Back:ab

  32. Source 32: Log streaming (Okta Help Center) Okta · checked Back:ab

  33. Source 33: Anypoint Platform Trust Center Salesforce · checked Back:ab

  34. Source 34: Okta Security Trust Center | Powered by SafeBase Okta · checked Back:ab

  35. Source 35: Okta is the first independent and neutral identity platform to bring AI agent governance to highly regulated environments Okta · checked Back:abc

  36. Source 36: MuleSoft Agent Fabric | Agent Governance and Orchestration Salesforce · checked Back:abc

  37. Source 37: View Agent Gateway activity (Okta Help Center) Okta · checked Back to text

  38. Source 38: Securing Agent Interactions with Omni Gateway Salesforce · checked Back:ab

  39. Source 39: Using A2A Protocol in Agent Networks Salesforce · checked Back to text

  40. Source 40: Requirements and Limits for Omni Gateway Salesforce · checked Back:ab

  41. Source 41: MuleSoft Cloud Offerings Service Level Agreement (SLA) for subscriptions with an Order Start Date on or before May 1, 2025 Salesforce · checked Back to text

  42. Source 42: MuleSoft Subscription Plans - effective for Customer purchases made from Salesforce on or after June 27, 2025 Salesforce · checked Back to text

  43. Source 43: Building Agent Networks for Agent Fabric Salesforce · checked Back:ab

  44. Source 44: Creating and Managing Model Proxies Salesforce · checked Back to text

  45. Source 45: Enhanced MuleSoft Experience Overview Salesforce · checked Back to text

  46. Source 46: Salesforce Expands MuleSoft Agent Fabric with Automated Discovery for Any AI Agent or Tool Salesforce · checked Back to text

  47. Source 47: Enhanced MuleSoft Experience Release Notes Salesforce · checked Back to text

  48. Source 48: Your company's private network Blocks.ai · checked Back to text

  49. Source 49: Network requirements Blocks.ai · checked Back to text

  50. Source 50: Solutions: Agent sprawl Blocks.ai · checked Back to text

  51. Source 51: Solutions: Partner networks Blocks.ai · checked Back to text

  52. Source 52: Pricing Blocks.ai · checked Back to text