LICENSEWARE

Okta Privileged Access and AI agents licensing

This article covers the Okta products licensed by units other than a plain user count, chiefly Okta Privileged Access (Resource Units), Advanced Server Access (Servers per Month), machine and non-human identity tokens, Multi-Org Deployment, and Okta for AI Agents (Users per Month), plus the Auth0 for AI Agents add-on.

On This Page

Okta Privileged Access and AI agents licensing covers the Okta products that are not licensed simply per workforce user. Okta Privileged Access protects servers, SaaS application accounts, Active Directory accounts and workloads, and is licensed in Resource Units. Advanced Server Access, an older server access product, is licensed per server.[1] Okta for AI Agents applies Okta’s directory, sign-on, API, privileged access, governance and posture products to AI agents, and is licensed in Users per Month under the Service-Specific Terms.[3] These products sit within the same Master Subscription Agreement as the rest of Okta; see Okta licensing.

Editions

Product Unit Prerequisite 
Okta Privileged Access Resource Units[1] Universal Directory[1] 
Advanced Server Access Servers per Month[1] Universal Directory and Single Sign-On[1] 
Machine-to-Machine Tokens Access tokens per subscription year[1] API Access Management context 
NHI Authentication Tokens Access tokens per subscription year[1] None stated 
Multi-Org Deployment Active orgs created with the Org Creation API[1] None stated 
Okta for AI Agents Users per Month[3] None stated 
Okta for AI Agents - Core Users per Month[3] Okta for FedRAMP Moderate or High[1] 

Okta Privileged Access is also bundled into the Workforce Identity Suites. Essentials includes 1 Resource Unit. Professional and Enterprise include 0.5 Resource Units “for each User per Month” of the suite.[1] The pricing page explains that the single Resource Unit in Essentials “can be used to cover 2 Privileged Access users”.[2] At 0.5 Resource Units per user, a Professional or Enterprise suite therefore covers each suite user as a Privileged Access user, but leaves no units over for servers or applications. Catalog: Professional and Enterprise Suites include 0.5 Resource Units per User.

Metrics

Resource Units

The Resource Unit converts different kinds of resource into one purchasable quantity. Activation “is measured by the number of active Resources enrolled in an Okta Privileged Access team”. The number of each Resource is multiplied by its Resource Unit Conversion Factor.[1]

Resource Resource Units per Resource How the Resource is counted 
User 0.5 Users in an Active Status provisioned to an Okta Privileged Access team[1] 
Server 1 Average number of actively managed servers available to the service[1] 
SaaS Application 35 SaaS applications that support active password management; only the first 25 non-Okta applications consume units[1] 
Active Directory Account 0.25 AD accounts managed by Okta Privileged Access (subject to the Early Access Subscription Agreement)[1] 
Workload Identity 0.25 Unique workload identities active in the previous 30 days[1] 

Before 2023-12-01 the conversion factor was called the “multiplier”.[1] Catalog: Privileged Access Resource Unit conversion factors.

Servers per Month

Servers per Month is “a per-Server subscription basis” for Advanced Server Access. The customer “may not exceed the number of Servers per Month specified on the Order Form”.[1]

Users per Month for AI agents

For Okta for AI Agents, the Service-Specific Terms state that the product “is licensed based on the number of Users per Month”.[3] The PSRG explains what is counted. Activation is the number of Users in an Active Status “who are assigned to a User sign-on application associated with an AI Agent in an Active Status”. This is the application a person signs in to in order to interact with the agent, and unique Users are summed across both ways of associating an agent.[1] The metric therefore counts the people who use agents, not the agents themselves. Subscriptions bought under an earlier model, priced on “Agent-to-Identity Connections per Month”, are described in the Legacy SKU guide.[1]

Counting / floors

Servers. Advanced Server Access takes “the median of a daily point-in-time count of all active servers” enrolled in an ASA team over a rolling 30-day period.[1] Okta Privileged Access uses the average number of actively managed servers, which Okta says “ensures that short-lived server resources, as commonly seen in elastic server environments, are accounted for fairly”.[1] A brief autoscaling spike therefore has little effect on either count, while a permanent increase in the server fleet does. Catalog: Advanced Server Access counts the 30-day median of enrolled servers.

SaaS applications. “Resource Units are only consumed for the first 25 non-Okta SaaS Applications.” Okta applications do not count, and several instances of the same application, such as Salesforce sandbox, acceptance and production, count as one.[1] At 35 Resource Units each, SaaS applications cost at most 875 Resource Units. Catalog: Only the first 25 non-Okta SaaS applications consume Resource Units.

Secrets. Users with access to secrets, or to passwords for SaaS applications with static password management, “can use an unlimited number of secrets”.[1]

Workloads and agents. A workload identity counts as active if it authenticated and used an access token to reach a protected resource at least once in the preceding 30 days. “AI Agents managed in Okta’s Universal Directory are not counted towards Workload Identity Resources.”[1]

Tokens. Machine-to-Machine Tokens count access tokens issued with the OAuth Client Credentials grant during each subscription year. NHI Authentication Tokens count tokens for On-Behalf-Of token exchanges under RFC 8693 and for machine-to-machine authorizations. Both years start on the Order Form start date.[1]

Orgs. Multi-Org Deployment counts Active orgs in Okta production cells created with the Org Creation API.[1]

Commitments. Servers per Month and Okta for AI Agents Users per Month follow the same pattern. The purchased quantity may not be decreased during the Term, and additions end with the current Term.[1][3] For Okta for AI Agents, added Users per Month are charged at the existing price, prorated.[3] If Advanced Server Access usage exceeds the purchased quantity, the customer “agrees to negotiate in good faith an additional upsell Order Form for the next applicable tier”.[1] Catalog: Okta for AI Agents Users per Month cannot be decreased during the Term.

Virtualization & partitioning

There are no processor or core rules. Virtual and cloud servers count as servers. The averaging and median methods above determine how elastic fleets are counted.[1] Okta for AI Agents is excluded from the Canada-Hosted and India-Hosted Cell Add-Ons and from HIPAA standards, and it is not available in the Okta for Government Moderate, Okta for Government High or Okta for US Military cells.[3] The Core variant serves public sector customers on FedRAMP. It excludes Okta Privileged Access, ISPM and other features that do not yet have FedRAMP authorisation, and “Customer” is limited to the single agency named on the Order Form.[3]

Cloud / BYOL

Not applicable. All of these products are Okta-hosted services.

Programs

Use restrictions for AI agents. Okta for AI Agents may be used only to manage AI agents. The customer may not use it to “identify, authenticate, govern or manage any employee, contractor, partner, customer or other human identity” for direct access to resources that are not AI agents.[3] Unlike most Okta Services, it is limited to the contracting customer. “Customer only means Customer and none of Customer’s Affiliates”, subsidiaries, parents or related entities, and the service may not be used for their benefit.[3] A group that wants agent coverage in several subsidiaries therefore needs separate contracts. Catalog: Okta for AI Agents is for the Customer only, not its Affiliates; Okta for AI Agents may not be used for human identities.

AI Agent Services generally. For any Okta or Auth0 AI Agent Service, the customer is responsible for its agents. “Any activity conducted by or on behalf of an AI Agent is deemed activity of the Customer” for compliance purposes.[3] Okta may monitor use, and the customer may not “falsify, undercount, obscure or otherwise manipulate” usage calculations.[3] Use beyond “Reasonable Use” may be subject to additional fees, throttling or suspension.[3] Catalog: AI agent activity counts as Customer activity and usage may be monitored.

Auth0 for AI Agents. On Auth0, AI agent features are an add-on SKU for Enterprise and Growth plans. The add-on raises the number of Token Vault connected applications, adds notification channels for Client-Initiated Backchannel Authentication (CIBA) and raises the On-Behalf-Of token exchange rate limit.[3] It is sized on the total MAUs of the Auth0 Primary Auth SKU.[5]

Free trials. AI Agent free trials, including the Okta for AI Agents Free Trial Service, carry their own terms. The customer acknowledges that deploying them “carries an inherent risk” and uses them at its own risk, including in production.[4]

Out of scope

  • Okta for AI Agents (Advanced) and Okta for AI Agents early access terms, and Legacy SKUs priced per Agent-to-Identity Connection.
  • Okta Privileged Access deployment architecture and gateway sizing, which the licensing documents do not address.
  • Identity Security Posture Management in depth. See Okta Workforce Identity licensing.

References

  1. Okta Product Subscription Reference GuideOkta guide dated 2026-09-23 (Advanced Server Access, Okta Privileged Access, Multi-Org Deployment, Machine to Machine, Okta for AI Agents). Catalog: Okta Product Subscription Reference Guide (September 2026)Effective 2026-09-23. Retrieved 2026-10-06.
  2. Okta Plans and PricingFAQ on Privileged Access Resource Units. Catalog: Okta Plans and PricingRetrieved 2026-10-06.
  3. Okta Service-Specific TermsRev 06/12/2026, s.2.1 AI Agent Services, s.3.4 Auth0 for AI Agents, s.4 Okta for AI Agents. Catalog: Okta Service-Specific TermsEffective 2026-06-12. Retrieved 2026-10-06.
  4. Okta Free Trial Service-Specific TermsRev 04202026, s.2.1 and s.3.2. Catalog: Okta Free Trial Service-Specific TermsEffective 2026-04-20. Retrieved 2026-10-06.
  5. Auth0 Product Subscription Reference GuideAuth0 guide dated May 2026. Catalog: Auth0 Product Subscription Reference Guide (May 2026)Retrieved 2026-10-06.

See also

Catalog Rows Cited

2SKUs8Rules6Metrics

Esc