Blog
  • AI Gateway
  • AI Security
  • AIOps
  • API Security
  • API Gateway
|
    • API Management
    • API Development
    • API Design
    • Automation
    • Service Mesh
    • Insomnia
    • View All Blogs
  1. Home
  2. Blog
  3. News
  4. Kong and Okta Deliver Best-in-Class Identity for API Management
News
November 18, 2021
3 min read

Kong and Okta Deliver Best-in-Class Identity for API Management

Eric Gandhi

As organizations look to accelerate their digital transformation initiatives, a couple of key trends are prevalent. First, there is a movement from monolithic to smaller cloud native microservices. Second, there is more pressure to innovate, resulting in an explosion of APIs and connections to secure. To help organizations address these trends, Kong is joining forces with Okta to deliver the best-in-class identity for API management.

"We are pleased to have Kong join the Okta technology partner ecosystem,” said John Pritchard, VP of product management at Okta. "Kong is a leader in API management. Kong's integration with Okta helps our joint customers securely manage their APIs and microservices."

Kong's technology partnership with Okta helps organizations securely design, publish, and consume APIs and microservices.

"Kong and Okta are best-in-class solutions to support customers' API management and identity needs, enabling organizations to make it easier to secure identity at every step of the development lifecycle," said Ken Kim, vice president of business development at Kong.

Kong's API gateway was designed and built for modern application development platforms, optimized for microservices and distributed architectures. The main capabilities provided by Kong are:

  • Universal deployment to hybrid or multi-cloud infrastructure with sub-millisecond processing latency
  • Extensive library of plugins to implement request processing policies for north/south or edge API traffic, including commonly used plugins such as rate limiting, authentication and authorization, proxy caching, log processing, Kafka and GraphQL servers integration.
  • API developer portal to onboard developers and APIs, generate API documentation from OpenAPI, create custom web pages, manage API versions and secure API access

Okta API Access Management provides comprehensive identity provider (IdP) capabilities to secure enterprise-wide applications, including:

  • Single sign-on: Cloud and hybrid-based authentication processes
  • Universal directory: One directory abstraction for all users, groups and devices stored in multiple repositories
  • Multi-factor authentication (MFA): flexible authentication policies to support numerous credential types

The Kong API gateway is available in two form-factors, Kong Enterprise, which is self-managed, and a new cloud offering called Kong Konnect Cloud. Kong and Okta have created integrations for both editions, which leverage the same plugins and provide all the same benefits

Kong Gateway Integration With Okta API Access Management

The Kong API gateway and Okta identity provider relationship is based on OpenID Connect (OIDC) standards. Both products fully support OIDC and provide seamless integration to implement all flows and grants defined in the standard to give flexibility to the authentication and authorization processes.

In this sense, Kong and Okta offload request processing from the upstream services: Kong handles routing, transformation, observability and other policies while delegating authentication, authorization and role-mapping to Okta. The services sitting behind Kong and Okta, including legacy SOAP services, modern protocols such as REST, GraphQL and gRPC, as well as cutting-edge microservices running in Kubernetes, are free to focus on business logic alone, leading to a dramatically improved development velocity, an improved security posture and faster time to value.

Identity for API ManagementOkta Support in Kong Konnect Cloud

During Kong Summit 2021, Kong announced the availability of Okta support in Kong Konnect Cloud for Kong administrative SSO and authentication and authorization for API consumers. Kong announced a one-click button integration with Okta with complete role-mapping.

For more Information, check both Kong and Okta web sites as well as the blog video series describing four OIDC-based processes, including:

  • User authentication with authorization code grant
  • Application authentication with client credentials grant
  • Token issuing and strong validation processes with introspection flow
  • OIDC-based access control policies

Claudio Acquaviva also contributed to this article.

API ManagementAPI AuthenticationAPI Authorization

More on this topic

eBooks

Securing Web and Mobile Applications and APIs with Centralized Authorization and Authentication Policies

Videos

Okta and Kong: Integrate Identity into your APIs

See Kong in action

Accelerate deployments, reduce vulnerabilities, and gain real-time visibility. 

Get a Demo
Topics
API ManagementAPI AuthenticationAPI Authorization
Share on Social
Eric Gandhi

Recommended posts

What are API Keys? Overview and Use Cases

Kong Logo
Learning CenterMay 22, 2023

Application programming interfaces (APIs) allow software to communicate and share data. But how can those APIs confirm the identity of the clients theyre communicating with? API keys are one solution. API keys are unique codes for authenticating and

Eric Pulsifer

Konnect Wins InfoWorld's 2025 Technology of the Year for API Management

Kong Logo
NewsDecember 16, 2025

InfoWorld’s annual awards recognize the most innovative software development, DevOps, cloud, data management, and AI/ML products on the information technology landscape. We are extremely proud to see Kong Konnect recognized for its role in unifying

Kong

Kong Named Leader in Gartner® Magic Quadrant™ for API Management for Sixth Year

Kong Logo
NewsOctober 10, 2025

What is the Gartner Magic Quadrant? As defined by Gartner , the Gartner Magic Quadrant "offers visual snapshots, in-depth analyses and actionable advice that provide insight into a market’s direction, maturity and participants. The Magic Quadrant c

Kong

RBAC Explained: The Basics of Role-Based Access Control

Kong Logo
Learning CenterApril 14, 2025

As cybersecurity takes the main stage, organizations face a significant challenge: how do you strike a balance between maintaining a high level of security and ensuring employees have enough data access to perform their jobs properly?  Role-based ac

Kong

How to Implement Secure Access Control with OPA and Kong Gateway

Kong Logo
EngineeringJanuary 8, 2025

Ensuring secure access to applications and APIs is critical. As organizations increasingly adopt microservices architectures and cloud native solutions, the need for robust, fine-grained access control mechanisms becomes paramount. This is where the

Raja Ravi Varman

Adopt a Zero Trust Approach with OAuth 2.0 Mutual TLS Client Authentication

Kong Logo
EngineeringFebruary 19, 2024

In the modern IT stack, API gateways act as the first line of defense against attacks on backend services by enforcing authentication/authorization policies and validating and transforming requests. When backend services are protected with a token-b

Samuele Illuminati

Understanding Microsegmentation in Zero Trust Security

Kong Logo
EngineeringFebruary 6, 2024

With digital transformation shifting networks into the cloud — from remote workforces to online banking — cyberattacks are growing more prevalent and sophisticated. Legacy security models like VPNs and perimeter-based firewalls are proving inadequat

Kong

Ready to see Kong in action?

Get a personalized walkthrough of Kong's platform tailored to your architecture, use cases, and scale requirements.

Get a Demo
Powering the API world

Increase developer productivity, security, and performance at scale with the unified platform for API management, AI gateways, service mesh, and ingress controller.

Sign up for Kong newsletter

    • Platform
    • Kong Konnect
    • Kong Gateway
    • Kong AI Gateway
    • Kong Insomnia
    • Developer Portal
    • Gateway Manager
    • Cloud Gateway
    • Get a Demo
    • Explore More
    • Open Banking API Solutions
    • API Governance Solutions
    • Istio API Gateway Integration
    • Kubernetes API Management
    • API Gateway: Build vs Buy
    • Kong vs Postman
    • Kong vs MuleSoft
    • Kong vs Apigee
    • Documentation
    • Kong Konnect Docs
    • Kong Gateway Docs
    • Kong Mesh Docs
    • Kong AI Gateway
    • Kong Insomnia Docs
    • Kong Plugin Hub
    • Open Source
    • Kong Gateway
    • Kuma
    • Insomnia
    • Kong Community
    • Company
    • About Kong
    • Customers
    • Careers
    • Press
    • Events
    • Contact
    • Pricing
  • Terms
  • Privacy
  • Trust and Compliance
  • © Kong Inc. 2025