Okta targets AI agent token costs with MCP scoping

Okta targets AI agent token costs with MCP scoping

Okta says identity-scoped Mannequin Context Protocol (MCP) instrument lists can scale back AI agent token prices.

Every mannequin name made by an AI agent can embody schemas, names, descriptions and parameters for each instrument uncovered by a MCP server. Okta calls the ensuing immediate overhead the “instrument tax”: tokens consumed as a mannequin considers instruments, together with these it should by no means name.

The corporate argues that this price seems earlier than an agent makes an attempt a instrument name. A later rejection of an unauthorised request due to this fact can not get better immediate tokens already consumed. Okta’s proposed management filters the checklist of instruments earlier than it reaches the mannequin, utilizing permissions assigned to an agent identification and the person related to it.

Okta’s inside modelling discovered that some permission eventualities decreased the variety of seen instruments by greater than 90%. The corporate stated tool-schema prices fell by roughly the identical proportion, though it didn’t present absolute token or greenback figures.

MCP instrument schemas create immediate overhead on each flip

MCP servers have turn out to be a route for connecting AI brokers to instruments and knowledge. Okta cites connections to Google Workspace, Slack and inside MCP servers as examples. An MCP server can expose numerous instruments, and the mannequin receives a illustration of every obtainable instrument in its immediate on each flip.

That illustration features a schema. It additionally contains the instrument identify, description and parameters.

Okta says the fee compounds when a broadly used MCP server exposes many instruments. Every lively person incurs the immediate overhead every time their agent makes a mannequin name. The corporate frames this as each a tool-count drawback and a user-count drawback.

The difficulty additionally has an access-control dimension. An agent that sees instruments exterior its authorisation scope can try to make use of them. A management that rejects the decision at runtime can block execution, although the mannequin has already obtained the instrument definition and used tokens to course of it.

Okta filters instruments earlier than the agent immediate is constructed

Okta positions the aptitude inside its “blueprint for the safe agentic enterprise”, which asks organisations to establish their brokers, their permitted connections and their authorised actions.

Its strategy narrows the connection query from entry to an entire MCP server to entry to particular person instruments on that server. An administrator configures the instruments {that a} specific identification could use within the Okta dashboard. Okta then returns the scoped instrument set as an alternative of the server’s full catalogue.

The agent receives this shorter checklist in its immediate for every flip. Okta says it checks scope once more at runtime earlier than a instrument name executes.

This design applies least-privilege entry on the instrument stage. The corporate says an agent shouldn’t be conscious of assets, databases or instruments that it has not been expressly authorised to make use of. Eradicating unavailable instruments from the immediate additionally removes their schema price from the mannequin name.

Okta doesn’t describe a dwell buyer deployment within the submit. Its proof for the claimed discount comes from inside modelling utilizing Okta product knowledge and public vendor documentation, with no buyer knowledge used.

Inner mannequin used OAuth scopes and consultant roles

Okta modelled a single MCP consumer with entry to a list of enterprise instruments. It in contrast the variety of instruments seen to the mannequin earlier than and after identity-based scoping.

To estimate scoped publicity, the corporate mapped Okta MCP Server instruments to the OAuth scopes that unlock them. It then outlined consultant person segments. These included helpdesk read-only customers and helpdesk operators.

Different segments had been app directors, model and e-mail directors, and tremendous directors. Okta weighted every phase in keeping with an assumed share of month-to-month visitors.

The corporate calculated tool-count discount as one minus the ratio of scoped instruments to unscoped instruments. It stated some eventualities eliminated greater than 90% of seen instruments. Its submit states that tool-schema token price tracks instrument depend practically linearly as a result of every instrument contributes its identify, description and parameter schema to each immediate.

Okta says precise outcomes range in keeping with the instrument catalogue, distribution of permissions and mannequin chosen. Common schema measurement, request quantity and mannequin pricing additionally have an effect on absolute token and greenback prices.

Okta contrasts identification entitlements with gateway spending controls

The submit distinguishes identity-based scoping from gateway controls. Okta says gateways can cap spending by key, staff or group, and might assist routing and price limiting.

A gateway can meter tokens coming into and leaving a system, in addition to {dollars} spent. Okta says these controls can restrict prices after a mannequin choice turns into costly.

Id entitlements present a unique enter. Okta says per-user and per-agent entitlements can decide the instruments obtainable to a selected agent or the particular person behind that agent, somewhat than making use of entry data at group stage.

Paul Webber, Principal Cybersecurity Trade Analyst at Software Analyst Cyber Research, stated: “Value management for brokers is finest supplied utilizing identification governance instruments that provide extra granular management and precision with out disrupting enterprise processes.

“Okta’s strategy is a sublime method to do that as a result of it leverages the identical entitlement knowledge that governs safety, not a separate metering layer with out that perception.”

Okta’s account presents the gateway as a management for what passes by means of it. The identification layer filters the obtainable instrument set earlier than these instruments must be metered.

Software visibility additionally impacts MCP assault publicity

The submit ties the identical mechanism to safety publicity. Okta says eradicating instruments from an unauthorised identification’s view additionally removes actions that identification might take if it had been compromised.

Its proposed scope verify operates at two factors. The primary happens because the instrument checklist is assembled for the agent immediate. The second happens when the agent makes an attempt to execute a instrument name.

Okta describes the end result as a smaller blast radius for a compromised identification. The remaining uncovered instruments decide the set of actions obtainable to that identification. Within the firm’s mannequin, the immediate comprises solely instruments related to the identification’s authorised OAuth scopes.

For organisations assessing MCP entry, instrument stock and entitlement mapping are the principle operational inputs. Okta’s methodology maps MCP Server instruments to the OAuth scopes that unlock them, then compares the complete instrument catalogue with the scoped catalogue seen to every consultant person phase.

Okta is a key sponsor of this yr’s AI & Big Data Expo Europe held in Amsterdam on 19-20 October 2026.

See additionally: Meta Muse Glimmer brings native AI brokers to shopper GPUs

Need to be taught extra about AI and large knowledge from trade leaders? Try AI & Big Data Expo happening in Amsterdam, California, and London. The excellent occasion is a part of TechEx and is co-located with different main know-how occasions together with the Cyber Security & Cloud Expo. Click on here for extra data.

AI Information is powered by TechForge Media. Discover different upcoming enterprise know-how occasions and webinars here.