Skip to content
Open
Show file tree
Hide file tree
Changes from 3 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
25 changes: 24 additions & 1 deletion packages/@okta/vuepress-site/docs/concepts/mcp-server/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,10 +9,33 @@ meta:

The Okta Open Source Model Context Protocol (MCP) server securely connects AI agents and Large Language Models (LLMs) to an Okta org. This abstraction layer enables AI agents and LLMs to interact with Okta admin management APIs using natural language commands.

The Okta Open Source MCP Server translates natural language instructions into structured API calls between LLM clients and an Okta org using Okta's Python SDK v3.4.1. This approach reduces security risks and complexity when connecting autonomous AI agents to Identity and Access Management (IAM) systems. The architecture ensures that AI actions remain secure, properly scoped, and fully auditable.
The Okta Open Source MCP Server translates natural language instructions into structured API calls between LLM clients and an Okta org using Okta's Python SDK v3.4.1. This approach reduces security risks and complexity when connecting autonomous AI agents to IAM systems. The architecture ensures that AI actions remain secure, properly scoped, and fully auditable.

IT admins, developers, and security professionals use the Okta Open Source MCP Server to automate Okta admin tasks through AI-powered interfaces.

Okta offers two ways to deploy an MCP server: the Okta Open Source MCP Server and the Okta Managed MCP Server. The following section introduces each deployment option and helps you choose the one that fits your environment.

## Deployment options: Okta Open Source MCP Server and Okta Managed MCP Server

To integrate AI assistants securely with your identity infrastructure, the Okta Model Context Protocol (MCP) server can be deployed using two distinct hosting options: Okta Open Source MCP Server and Okta Managed MCP Server.
Comment thread
sophiajose-okta marked this conversation as resolved.
Outdated

You can choose the deployment track that matches your technical requirements:
Comment thread
sophiajose-okta marked this conversation as resolved.
Outdated
Comment thread
sophiajose-okta marked this conversation as resolved.
Outdated

* **Okta Open Source MCP Server**: You run the server software locally on your own infrastructure. This track is best for developers who want to modify the underlying server code. See [Okta Open Source MCP Server documentation](/docs/guides/mcp-server/main/).

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
* **Okta Open Source MCP Server**: You run the server software locally on your own infrastructure. This track is best for developers who want to modify the underlying server code. See [Okta Open Source MCP Server documentation](/docs/guides/mcp-server/main/).
* **Okta Open Source MCP Server**: You run the server software locally on your own infrastructure. This method is best for developers who want to modify the underlying server code. See [Okta Open Source MCP Server documentation](/docs/guides/mcp-server/main/).

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Who is "you"? Is it an admin or developer?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

developer

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

updated both as "you"

* **Okta Managed MCP Server**: Okta hosts and manages the server in the cloud. Your chat client streams instructions over secure HTTPS, which removes local software installations and hosting fees. This setup simplifies onboarding for nontechnical users, such as Okta Identity Governance (OIG) request approvers, who need a ready-made tool without local configuration. See Okta Managed MCP Server documentation.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Add a doc link.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will add link to okta managed mcp server doc from prod doc later, if I add now, the build will fail due to broken link


The following table compares the two hosting options:

| Feature | Okta Open Source MCP Server | Okta Managed MCP Server |
| --- | --- | --- |
| Where it runs | Your infrastructure (a computer, a company container, or a private cloud). | Okta cloud infrastructure. |
| Setup and operation | Install Python packages, clone repositories, configure tooling, and manage infrastructure (OS patches, updates, dependency management). | No installation required. Connect through an HTTPS endpoint. Okta manages infrastructure, updates, scaling, and security patches. |
| Transport protocol | Uses STDIO. | Uses a secure internet connection (HTTPS). |
| User authentication | Device Authorization code flow (interactive users). | OpenID Connect (OIDC) with Proof Key for Code Exchange (PKCE) for interactive users. |
| Service-to-service authentication | JWT private key (API Services for autonomous agents). | JWT private key (API Services for autonomous agents). |
| Cost model | You manage infrastructure, licensing, and operational costs. | Okta managed cloud service with predictable, consumption-based pricing. |
| Best for | Developers testing code in a sandbox or using a command-line interface. | Help Desk teams, IT admins, and automated workflows. |

## Benefits

The Okta Open Source MCP Server addresses security, automation, and integration requirements.
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
---
title: Okta Open Source MCP Server overview
meta:
- name: description
content: Learn about the Okta Open Source MCP Server, how it compares to the Okta Managed MCP Server, and how to choose the right deployment option.
layout: Guides
sections:
- main
---
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
---
title: Okta Open Source MCP Server overview
meta:
- name: description
content: Learn about the Okta Open Source MCP Server, how it compares to the Okta Managed MCP Server, and how to choose the right deployment option.
layout: Guides
---

The Model Context Protocol (MCP) connects AI agents and Large Language Models (LLMs) to your Okta org so you can manage it using natural language commands. Okta offers two ways to deploy an MCP server: the Okta Open Source MCP Server and the Okta Managed MCP Server.

## Okta Open Source MCP Server

Comment thread
sophiajose-okta marked this conversation as resolved.
The [Okta Open Source MCP Server](/docs/concepts/mcp-server/) is a self-hosted server that you download and run on your own computer or private cloud network. It's best for developers who want full control over the package environment or need to run isolated tests and sandboxes.

* **Hosting**: Self-hosted on local infrastructure that you manage.
* **Best for**: Developer testing, isolated sandboxes, and use cases that need full control over the runtime environment.
* **Get started**: See [Install and initialize the Okta Open Source MCP Server](/docs/guides/mcp-server/main/).

## Okta Managed MCP Server

The Okta Managed MCP Server is a cloud-hosted server where Okta hosts and manages the gateway on your behalf. Your chat client streams instructions over secure HTTPS, which removes the need for local software installation, hosting, and maintenance.

* **Hosting**: Cloud-hosted and managed by Okta.
* **Best for**: Deployment without managing local software dependencies, including nontechnical users, such as Okta Identity Governance (OIG) request approvers, who need a ready-made tool without local configuration. It also supports browser-based tools and lets you run clients and servers in separate containers for greater flexibility.
* **Get started**: See Okta Managed MCP Server documentation.

## Choose a deployment option

| | Okta Open Source MCP Server | Okta Managed MCP Server |
| --- | --- | --- |
| Hosting | Self-hosted (local infrastructure) | Cloud-hosted by Okta |
| Setup | Requires local installation and dependency management | No local installation required |
| Maintenance | You have to manage the updates and runtime environment | Okta manages updates and infrastructure |
| Best for | Developer testing and isolated sandboxes | Fast onboarding, nontechnical users, and browser-based tools |

## Next steps

* To deploy the self-hosted option, see [Install and initialize the Okta Open Source MCP Server](/docs/guides/mcp-server/main/).
* To deploy the cloud-hosted option, see Okta Managed MCP Server documentation.
Original file line number Diff line number Diff line change
Expand Up @@ -593,6 +593,7 @@ export const guides = [
},
{
title: "Okta Open Source MCP Server",
path: "/docs/guides/okta-open-source-mcp-server/main/",
subLinks: [
{
title: "Install and initialize",
Expand Down