avatar-sohail-pathan.jpeg Sohail Pathan

Sohail is a Senior Developer Advocate at Okta with roots in mobile app development and hands-on experience designing, building, and publishing APIs. Now, he helps developers secure their apps by turning complex OAuth and API topics into clear, actionable guides. When he's not coding or speaking at conferences, you'll find him on a quest for the perfect plate of biryani.

All Posts by Sohail Pathan

Add Cross App Access to Your OIDC Resource Application

If you currently federate enterprise customers using OpenID Connect (OIDC) and want to allow applications to access your API on behalf of those users, this Cross App Access (XAA) guide is for you. The Identity Assertion Authorization Grant specification, the basis of XAA, was designed with OIDC in mind. Your authorization server already trusts the customer’s IdP for single sign-on (SSO), and XAA reuses that same trust for API access. This guide details what you...

Read more

Add Cross App Access to Your OIDC Requesting Application

If you currently federate enterprise customers using OpenID Connect (OIDC) and want to connect with third-party applications, this Cross App Access (XAA) guide is for you. The Identity Assertion Authorization Grant specification, the basis of XAA, was designed with OIDC in mind. Your app already holds an ID token after sign-in, but it’s the refresh token from that same sign-in that you exchange to reach a third-party app. This guide details what you need to...

Read more

Enabling Cross App Access for SAML-Based Resource Apps

If you currently federate enterprise customers using Security Assertion Markup Language (SAML) and want to allow applications to access your API without migrating to OpenID Connect (OIDC), this Cross App Access (XAA) guide is for you. The Identity Assertion Authorization Grant specification, the basis of XAA, was originally designed with OIDC in mind. To use it in SAML applications, you must accommodate specific security and uniqueness requirements. This guide details what you need to support...

Read more

Introducing xaa.dev: A Playground for Cross App Access

AI agents are quickly becoming part of everyday enterprise development. They summarize emails, coordinate calendars, query internal systems, and automate workflows across tools. But once an AI agent needs to access an enterprise application on behalf of a user, things get complicated. How do you securely let an AI-powered app act for a user without exposing credentials, spamming consent prompts, or losing administrative control? This is the problem Cross App Access (XAA) is designed to...

Read more

Build Secure Agent-to-App Connections with Cross App Access (XAA) Using OIDC

⚠️ This guide is out of date The Okta Admin Console steps in this guide no longer work: the XAA Resource App and XAA Requesting App App Catalog integrations, along with the Manage Connections tab, have been replaced by AI agent registration under Directory > AI Agents. Building the app that owns the API, validates the ID-JAG, and issues its own access token? Read Add Cross App Access to Your OIDC Resource Application. Building the...

Read more

Superheroes, Startups, and Security: Sohail's Path to Developer Advocacy at Okta

“Sometimes, all it takes is a spark of curiosity to ignite a lifelong journey.” - Unknown Hello OktaDev community 👋! Let me tell you a story – a story of dreams, passion, and the continuous pursuit of curiosity. My name is Sohail Pathan, and I’m thrilled to join Okta as a Senior Developer Advocate. It all started in Nagpur, a quaint city nestled in central India. As a child, I eagerly peered through my window,...

Read more