Skip to content
Close Menu

    Subscribe to Updates

    Get the latest news from tastytech.

    What's Hot

    Okta targets AI agent token costs with MCP scoping

    August 13, 2026

    How Baidu Solved Long-Document AI

    August 13, 2026

    NLP in 2026: Trends, Use Cases & Future of Language AI | Shaip

    August 13, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    tastytech.intastytech.in
    Subscribe
    • AI News & Trends
    • Tech News
    • AI Tools
    • Business & Startups
    • Guides & Tutorials
    • Tech Reviews
    • Automobiles
    • Gaming
    • movies
    tastytech.intastytech.in
    Home»AI Tools»Okta targets AI agent token costs with MCP scoping
    Okta targets AI agent token costs with MCP scoping
    AI Tools

    Okta targets AI agent token costs with MCP scoping

    gvfx00@gmail.comBy gvfx00@gmail.comAugust 13, 2026No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Okta says identity-scoped Model Context Protocol (MCP) tool lists can reduce AI agent token costs.

    Each model call made by an AI agent can include schemas, names, descriptions and parameters for every tool exposed by a MCP server. Okta calls the resulting prompt overhead the “tool tax”: tokens consumed as a model considers tools, including those it will never call.

    The company argues that this cost appears before an agent attempts a tool call. A later rejection of an unauthorised request therefore cannot recover prompt tokens already consumed. Okta’s proposed control filters the list of tools before it reaches the model, using permissions assigned to an agent identity and the user associated with it.

    Okta’s internal modelling found that some permission scenarios reduced the number of visible tools by more than 90%. The company said tool-schema costs fell by roughly the same proportion, although it did not provide absolute token or dollar figures.

    Table of Contents

    Toggle
      • MCP tool schemas create prompt overhead on every turn
      • Okta filters tools before the agent prompt is built
      • Internal model used OAuth scopes and representative roles
      • Okta contrasts identity entitlements with gateway spending controls
      • Tool visibility also affects MCP attack exposure
      • Related posts:
    • England’s Quansah banned for two matches after World Cup last-16 red card | World Cup 2026
    • Jailed Gaza hospital chief in life-threatening condition, rights group says | Crimes Against Humanit...
    • Iran war: What’s happening on day 57 as Trump dispatches negotiating team? | US-Israel war on Iran N...

    MCP tool schemas create prompt overhead on every turn

    MCP servers have become a route for connecting AI agents to tools and data. Okta cites connections to Google Workspace, Slack and internal MCP servers as examples. An MCP server can expose a large number of tools, and the model receives a representation of each available tool in its prompt on every turn.

    That representation includes a schema. It also includes the tool name, description and parameters.

    Okta says the cost compounds when a widely used MCP server exposes many tools. Each active user incurs the prompt overhead whenever their agent makes a model call. The company frames this as both a tool-count problem and a user-count problem.

    The issue also has an access-control dimension. An agent that sees tools outside its authorisation scope can attempt to use them. A control that rejects the call at runtime can block execution, though the model has already received the tool definition and used tokens to process it.

    Okta filters tools before the agent prompt is built

    Okta positions the capability within its “blueprint for the secure agentic enterprise”, which asks organisations to identify their agents, their permitted connections and their authorised actions.

    Its approach narrows the connection question from access to a whole MCP server to access to individual tools on that server. An administrator configures the tools that a particular identity may use in the Okta dashboard. Okta then returns the scoped tool set instead of the server’s full catalogue.

    The agent receives this shorter list in its prompt for each turn. Okta says it checks scope again at runtime before a tool call executes.

    This design applies least-privilege access at the tool level. The company says an agent should not be aware of resources, databases or tools that it has not been expressly authorised to use. Removing unavailable tools from the prompt also removes their schema cost from the model call.

    Okta does not describe a live customer deployment in the post. Its evidence for the claimed reduction comes from internal modelling using Okta product data and public vendor documentation, with no customer data used.

    Internal model used OAuth scopes and representative roles

    Okta modelled a single MCP client with access to a catalogue of enterprise tools. It compared the number of tools visible to the model before and after identity-based scoping.

    To estimate scoped exposure, the company mapped Okta MCP Server tools to the OAuth scopes that unlock them. It then defined representative user segments. These included helpdesk read-only users and helpdesk operators.

    Other segments were app administrators, brand and email administrators, and super administrators. Okta weighted each segment according to an assumed share of monthly traffic.

    The company calculated tool-count reduction as one minus the ratio of scoped tools to unscoped tools. It said some scenarios removed more than 90% of visible tools. Its post states that tool-schema token cost tracks tool count nearly linearly because each tool contributes its name, description and parameter schema to every prompt.

    Okta says actual results vary according to the tool catalogue, distribution of permissions and model selected. Average schema size, request volume and model pricing also affect absolute token and dollar costs.

    Okta contrasts identity entitlements with gateway spending controls

    The post distinguishes identity-based scoping from gateway controls. Okta says gateways can cap spending by key, team or group, and can support routing and rate limiting.

    A gateway can meter tokens entering and leaving a system, as well as dollars spent. Okta says those controls can limit costs after a model decision becomes expensive.

    Identity entitlements provide a different input. Okta says per-user and per-agent entitlements can determine the tools available to a specific agent or the person behind that agent, rather than applying access information at group level.

    Paul Webber, Principal Cybersecurity Industry Analyst at Software Analyst Cyber Research, said: “Cost control for agents is best provided using identity governance tools that offer more granular control and precision without disrupting business processes.

    “Okta’s approach is an elegant way to do this because it leverages the same entitlement data that governs security, not a separate metering layer without that insight.”

    Okta’s account presents the gateway as a control for what passes through it. The identity layer filters the available tool set before those tools need to be metered.

    Tool visibility also affects MCP attack exposure

    The post ties the same mechanism to security exposure. Okta says removing tools from an unauthorised identity’s view also removes actions that identity could take if it were compromised.

    Its proposed scope check operates at two points. The first occurs as the tool list is assembled for the agent prompt. The second occurs when the agent attempts to execute a tool call.

    Okta describes the result as a smaller blast radius for a compromised identity. The remaining exposed tools determine the set of actions available to that identity. In the company’s model, the prompt contains only tools associated with the identity’s authorised OAuth scopes.

    For organisations assessing MCP access, tool inventory and entitlement mapping are the main operational inputs. Okta’s methodology maps MCP Server tools to the OAuth scopes that unlock them, then compares the full tool catalogue with the scoped catalogue visible to each representative user segment.

    Okta is a key sponsor of this year’s AI & Big Data Expo Europe held in Amsterdam on 19-20 October 2026.

    See also: Meta Muse Glimmer brings local AI agents to consumer GPUs

    Banner for the AI & Big Data Expo event series.

    Want to learn more about AI and big data from industry leaders? Check out AI & Big Data Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including the Cyber Security & Cloud Expo. Click here for more information.

    AI News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

    Related posts:

    US-Iran ceasefire deal: What are the terms, and what’s next? | US-Israel war on Iran News

    OpenAI Frontier puts enterprise AI agents on a collision course with SaaS

    SenseTime's Galaxy Project targets domestic AI chip scale-up

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHow Baidu Solved Long-Document AI
    gvfx00@gmail.com
    • Website

    Related Posts

    AI Tools

    Life and loss as a first responder in southern Lebanon | Israel attacks Lebanon News

    August 13, 2026
    AI Tools

    Siemens’ physics AI can run 1,000x faster. It still won’t sign off your airbag” for the meta field

    August 13, 2026
    AI Tools

    Thousands missing after Colombia quake as rescue continues | Newsfeed

    August 12, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025219 Views

    Every Clue That Tony Stark Was Always Doctor Doom

    October 20, 2025143 Views

    We let ChatGPT judge impossible superhero debates — here’s how it ruled

    December 31, 2025110 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from tastytech.

    About Us
    About Us

    TastyTech.in brings you the latest AI, tech news, cybersecurity tips, and gadget insights all in one place. Stay informed, stay secure, and stay ahead with us!

    Most Popular

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025219 Views

    Every Clue That Tony Stark Was Always Doctor Doom

    October 20, 2025143 Views

    We let ChatGPT judge impossible superhero debates — here’s how it ruled

    December 31, 2025110 Views

    Subscribe to Updates

    Get the latest news from tastytech.

    Facebook X (Twitter) Instagram Pinterest
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 TastyTech. Designed by TastyTech.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.