Cross App Access builds on Okta OpenID Connect sign-in. Set up OIDC with Okta first. The Cross App Access section appears on your Gumloop Identity Provider settings page once OIDC is active.
Before you start
You need the Super Admin role in Okta and the Admin role in your Gumloop organization. Okta OpenID Connect sign-in must already be active in Gumloop.Older Okta versions may label the Machine Assignments tab Resource Server. If neither tab nor Directory > AI Agents appears, confirm that you have the Super Admin role and contact Okta Support.
- Slack. Slack Enterprise+ with Okta as its identity provider. A Slack Org Owner opens Organization settings > Security > SSO settings, presses Edit next to Enterprise-Managed Authorization, and turns on the toggle. Check that the ID-JAG issuer URL matches your Okta org URL, then press Save. The Gumloop Slack app must be installed at the organization level. See Enterprise-managed authorization.
- Asana. An Asana Organization Admin opens Admin Console > Security > Cross-app access (XAA) and turns on Cross-app access. Set Issuer URL to your Okta org’s base URL, JWKS URI to that URL followed by
/oauth2/v1/keys, and Expected Audience tohttps://app.asana.com. Do not use a custom authorization server path such as/oauth2/default. Press Save. See Cross-App Access for Asana’s setup requirements.
Allow refresh tokens on the Gumloop app
Gumloop asks Okta for app access with a refresh token from the member’s sign-in. The Gumloop app must be allowed to issue one. In the Okta Admin Console, select Applications and Resources > Applications and open the Gumloop OpenID Connect app you created for sign-in. On the General tab, press Edit next to General Settings. Under Grant type, check Refresh Token, then press Save.
Enable Refresh Token alongside Authorization Code on the Gumloop OIDC app.
Register Gumloop as an AI agent
Okta represents the Gumloop side of Cross App Access as an AI agent linked to the Gumloop app. On the Gumloop app page, open the Machine Assignments tab and select the Resources tile. Press Register AI agent. Under Profile, name the agent “Gumloop” and press Next. Under User access and authentication, the Gumloop app is already selected. Keep it and press Next. Leave Client registration as it is. Gumloop authenticates with the app’s existing client ID and secret. The new agent appears under Directory > AI Agents with the status Staged. Open it and select Actions > Activate.Connect each app to the Gumloop agent
Do this once for Slack and once for Asana.Turn on Cross App Access on the app
Slack and Asana must exist as app integrations in your Okta org. If one is missing, add it from Browse App Catalog and assign the same people who use Gumloop. Both catalog apps list Cross App Access among their features. Open the app in Okta. On the Machine Assignments tab, select the Callers tile. Next to Cross-app access (XAA), press Edit, select Enable, then press Save. The issuer and scopes are set by the vendor for catalog apps. Leave them as they are.Copy the client ID from Gumloop
In Gumloop, open gumloop.com/settings/organization/sso and scroll to Cross App Access. Each app row shows the client ID Okta needs, with a copy button next to it.Add the resource connection in Okta
Select Directory > AI Agents, open the Gumloop agent, and select the Resource connections tab. Press Add resource connection and choose the app under Application instance. Paste the client ID you copied from Gumloop into the field named for your AI agent and the resource app, such as Gumloop’s client ID registered in Slack. Okta uses your AI agent’s name in this label. Resource identifier is optional; the Slack connection shown below useshttps://mcp.slack.com/mcp. Under Scopes, select Allow any scope. If you prefer an allowlist, select Allow specific scopes and choose all the scopes listed for the app in Gumloop’s Cross App Access section.
Press Add.

An existing Slack resource connection showing the client ID and Allow any scope setting.
Confirm the connection from Gumloop
First connect your own Okta account. Use the same email as your Gumloop account, and ensure your Okta account is assigned to both the Gumloop app and the resource app you want to test. Open gumloop.com/settings/profile/connectors, press Connect Okta at the top of the page, and sign in as yourself. The banner then reads Connected to Okta as followed by your email. Then open Settings > Identity Provider, scroll to Cross App Access, and press Test connection on each app. The test uses your personal Okta connection to check that Okta grants access and the app accepts it. Connection works without warnings confirms the connection. A result with warnings is not a passing test: fix every warning and test again before telling members the app is ready. The switch next to each app stops Gumloop from using that app through Okta. It does not change anything in Okta, and the app stays off until you turn it back on.What members see
Members who sign in with Okta after the Refresh Token grant is enabled are connected automatically. Members who signed in earlier, or without Okta, connect once from their connectors page. When Okta-managed apps are available, the Connect your Okta account banner shows a Connect Okta button.
Connect your Okta account once from your personal connectors page.
Troubleshooting
Test connection in Gumloop These examples use Slack. Results for another app use that app’s name.
Members
Okta documents a limit of 250 XAA tokens per licensed active SSO user, per resource app, per month for Cross App Access included with SSO. See Configure AI agent-to-app with XAA. For higher-volume use, confirm your entitlement with your Okta account team.