On this page
Okta Access Gateway API release notes (2026)
Access Gateway is available for both Okta Classic Engine and Okta Identity Engine.
September
Weekly release 2026.09.1
| Change | Expected in Preview Orgs |
|---|---|
| Smart Card authentication for Access Gateway offline mode is Limited EA in Preview | September 4, 2026 |
| Access policies for Access Gateway offline mode is Limited EA in Preview | September 4, 2026 |
Smart Card authentication for Access Gateway offline mode is Limited EA in Preview
Admins can now require users to sign in with a Smart Card to access apps when Access Gateway is in offline mode. Access Gateway offline mode supports a certificate-based Smart Card authenticator, such as a Personal Identity Verification (PIV) or Common Access Card (CAC), alongside the existing password authenticator. See Configure Smart Card authentication and access policies.
Access policies for Access Gateway offline mode is Limited EA in Preview
Admins can now create access policies that control which authentication methods a group of users must use when they sign in to an app when Access Gateway is in offline mode. A policy assigns a chain of authenticators, such as a password, a Smart Card, or both, to a group of users for a given app. See Configure Smart Card authentication and access policies.
As part of this change, the Assign a group to an application's offline mode policy endpoint (opens new window) is deprecated and returns an HTTP 405 error. Use the Assign an offline mode access policy to an application endpoint (opens new window) instead.
August
Monthly release 2026.08.0
| Change | Expected in Preview Orgs |
|---|---|
| OpenID Connect apps in offline mode is Limited EA in Preview | August 6, 2026 |
OpenID Connect apps in offline mode is Limited EA in Preview
Access Gateway now supports OpenID Connect (OIDC) apps in offline mode, providing authentication resiliency when your Access Gateway instance is disconnected from Okta or temporarily offline. OIDC apps can be configured with the authorization code with PKCE and client credentials flows. See Add apps for offline mode.
May
Monthly release 2026.05.0
| Change | Expected in Preview Orgs |
|---|---|
| Bug fixed in 2026.05.0 | May 13, 2026 |
Bug fixed in 2026.05.0
The Access Gateway API was disabled when upgrading from version 2025.10.0 to 2026.03.0 or 2026.04.0. (OKTA-1153987)
April
Monthly release 2026.04.0
| Change | Expected in Preview Orgs |
|---|---|
| Bugs fixed in 2026.04.0 | April 8, 2026 |
Bugs fixed in 2026.04.0
- The
postLogoutUrlfor an app couldn’t be updated using the Replace the application behavior configuration endpoint (opens new window). (OKTA-1125316) - The List all applications endpoint (opens new window) returned an error if an app had
STATUS_CODE_403as thepolicyDeniedvalue in its app behavior settings and the request was used with?expand=behavioras a query parameter. (OKTA-1128154) - When you used the Replace a protected resource endpoint (opens new window), it incorrectly returned an HTTP 404 Not Found error. (OKTA-1126600)
March
Monthly release 2026.03.0
| Change | Expected in Preview Orgs |
|---|---|
| Temporary Offline Access (offline mode) is Limited EA in Preview | March 11, 2026 |
| Developer documentation update in 2026.03.0 | March 4, 2026 |
Temporary Offline Access (offline mode) is Limited EA in Preview
You can now configure offline mode settings for Access Gateway. When you configure offline mode, it allows users to authenticate locally to their on-premises apps when Access Gateway can’t connect to the internet and the Okta identity provider.
See:
Developer documentation update in 2026.03.0
Our API reference pages (opens new window) are undergoing a migration, which started on February 24. While the look and feel may vary across pages during this time, all technical documentation remains accurate and up to date.
February
Monthly release 2026.02.0
| Change | Expected in Preview Orgs |
|---|---|
| Developer documentation updates in 2026.02.0 | February 4, 2026 |
Developer documentation updates in 2026.02.0
The Okta developer portal search results now include the API references.
January
Monthly release 2026.01.0
| Change | Expected in Preview Orgs |
|---|---|
| Developer documentation update in 2026.01.0 | January 7, 2026 |
Developer documentation update in 2026.01.0
The Okta API release notes now provide an RSS feed for each API release note category: Classic Engine, Identity Engine, Identity Governance, Privileged Access, Access Gateway, and Aerial. Click the RSS icon to subscribe.