Primary record

Staff Software Engineer, Agent Gateway

Okta Indexed employerSan Francisco, California · San Francisco, CA, United States
Source-hosted applyChecked 4h agoInternship
Apply at Okta

Okta receives this application through Greenhouse. Babu Careers does not claim delivery.

Workplace

hybrid

Employment

Internship

Published

Aug 11, 2026

Closes

No date supplied

The role

Secure Every Identity, from AI to Human

Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.

This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.

The Agent Gateway Team

The Agent Gateway team owns the identity-aware infrastructure that connects enterprise AI agents to the tools, data, and services their organizations authorize. Every call from Claude, Agentforce,, Codex, and internal/homegrown agents to a resource flows through us. We enforce authorization, isolate credentials, mint the right token per target, and produce the audit trails that security teams rely on.

We are early in a rapidly evolving space. The standards (MCP, XAA, ID JAG, DCR for agents,CIMD) are being built under our feet. Our roadmap includes hardening the data plane for on-premises customer deployments, extending policy semantics beyond tool-level allowlists, adding native support for Agent-to-Agent brokered delegation, XAA and scaling to tenants with thousands of virtual MCP servers.

The Staff Software Engineer Opportunity

Okta is looking for a Staff Software Engineer to serve as a technical anchor for the Agent Gateway team. You will own critical parts of the data and control planes and drive architectural design as the MCP and agent identity specs evolve.

In this role, you will work close to the metal on request routing, token exchange, credential resolution, and policy evaluation. You will work equally close to the identity control plane on config bundles, tenant fanout, and

Requirements

Department: SW Eng - Core Identity-670