• The API Platform for AI.

      Explore More
      Platform Runtimes
      Kong Gateway
      • Kong Cloud Gateways
      • Kong Ingress Controller
      • Kong Operator
      • Kong Gateway Plugins
      Kong AI Gateway
      Kong Event Gateway
      Kong Mesh
      Platform Core Services
      • Gateway Manager
      • Mesh Manager
      • Service Catalog
      Platform Applications
      • Developer Portal
      • API and AI Analytics
      • API Products
      Development Tools
      Kong Insomnia
      • API Design
      • API Testing and Debugging
      Self-Hosted API Management
      Kong Gateway Enterprise
      Kong Open Source Projects
      • Kong Gateway OSS
      • Kuma
      • Kong Insomnia OSS
      • Kong Community
      Get Started
      • Sign Up for Kong Konnect
      • Documentation
    • Featured
      Open Banking SolutionsMobile Application API DevelopmentBuild a Developer PlatformAPI SecurityAPI GovernanceKafka Event StreamingAI GovernanceAPI Productization
      Industry
      Financial ServicesHealthcareHigher EducationInsuranceManufacturingRetailSoftware & TechnologyTransportation
      Use Case
      API Gateway for IstioBuild on KubernetesDecentralized Load BalancingMonolith to MicroservicesObservabilityPower OpenAI ApplicationsService Mesh ConnectivityZero Trust SecuritySee all Solutions
      Demo

      Learn how to innovate faster while maintaining the highest security standards and customer trust

      Register Now
  • Customers
    • Documentation
      Kong KonnectKong GatewayKong MeshKong AI GatewayKong InsomniaPlugin Hub
      Explore
      BlogLearning CentereBooksReportsDemosCase StudiesVideos
      Events
      API SummitWebinarsUser CallsWorkshopsMeetupsSee All Events
      For Developers
      Get StartedCommunityCertificationTraining
    • Company
      About UsWhy Kong?CareersPress RoomInvestorsContact Us
      Partner
      Kong Partner Program
      Security
      Trust and Compliance
      Support
      Enterprise Support PortalProfessional ServicesDocumentation
      Press Release

      Kong Expands with New Headquarters in Downtown San Francisco

      Read More
  • Pricing
  • Login
  • Get a Demo
  • Start for Free
Blog
  • Engineering
  • Enterprise
  • Learning Center
  • Kong News
  • Product Releases
    • API Gateway
    • Service Mesh
    • Insomnia
    • Kubernetes
    • API Security
    • AI Gateway
  • Home
  • Blog
  • News
  • Kong and Okta Deliver Best-in-Class Identity for API Management
News
November 18, 2021
3 min read

Kong and Okta Deliver Best-in-Class Identity for API Management

Eric Gandhi

As organizations look to accelerate their digital transformation initiatives, a couple of key trends are prevalent. First, there is a movement from monolithic to smaller cloud native microservices. Second, there is more pressure to innovate, resulting in an explosion of APIs and connections to secure. To help organizations address these trends, Kong is joining forces with Okta to deliver the best-in-class identity for API management.

"We are pleased to have Kong join the Okta technology partner ecosystem,” said John Pritchard, VP of product management at Okta. "Kong is a leader in API management. Kong's integration with Okta helps our joint customers securely manage their APIs and microservices."

Kong's technology partnership with Okta helps organizations securely design, publish, and consume APIs and microservices.

"Kong and Okta are best-in-class solutions to support customers' API management and identity needs, enabling organizations to make it easier to secure identity at every step of the development lifecycle," said Ken Kim, vice president of business development at Kong.

Kong's API gateway was designed and built for modern application development platforms, optimized for microservices and distributed architectures. The main capabilities provided by Kong are:

  • Universal deployment to hybrid or multi-cloud infrastructure with sub-millisecond processing latency
  • Extensive library of plugins to implement request processing policies for north/south or edge API traffic, including commonly used plugins such as rate limiting, authentication and authorization, proxy caching, log processing, Kafka and GraphQL servers integration.
  • API developer portal to onboard developers and APIs, generate API documentation from OpenAPI, create custom web pages, manage API versions and secure API access

Okta API Access Management provides comprehensive identity provider (IdP) capabilities to secure enterprise-wide applications, including:

  • Single sign-on: Cloud and hybrid-based authentication processes
  • Universal directory: One directory abstraction for all users, groups and devices stored in multiple repositories
  • Multi-factor authentication (MFA): flexible authentication policies to support numerous credential types

The Kong API gateway is available in two form-factors, Kong Enterprise, which is self-managed, and a new cloud offering called Kong Konnect Cloud. Kong and Okta have created integrations for both editions, which leverage the same plugins and provide all the same benefits

Kong Gateway Integration With Okta API Access Management

The Kong API gateway and Okta identity provider relationship is based on OpenID Connect (OIDC) standards. Both products fully support OIDC and provide seamless integration to implement all flows and grants defined in the standard to give flexibility to the authentication and authorization processes.

In this sense, Kong and Okta offload request processing from the upstream services: Kong handles routing, transformation, observability and other policies while delegating authentication, authorization and role-mapping to Okta. The services sitting behind Kong and Okta, including legacy SOAP services, modern protocols such as REST, GraphQL and gRPC, as well as cutting-edge microservices running in Kubernetes, are free to focus on business logic alone, leading to a dramatically improved development velocity, an improved security posture and faster time to value.

Okta Support in Kong Konnect Cloud

During Kong Summit 2021, Kong announced the availability of Okta support in Kong Konnect Cloud for Kong administrative SSO and authentication and authorization for API consumers. Kong announced a one-click button integration with Okta with complete role-mapping.

For more Information, check both Kong and Okta web sites as well as the blog video series describing four OIDC-based processes, including:

  • User authentication with authorization code grant
  • Application authentication with client credentials grant
  • Token issuing and strong validation processes with introspection flow
  • OIDC-based access control policies

Claudio Acquaviva also contributed to this article.

Topics:API Management
|
API Authentication
|
API Authorization
Powering the API world

Increase developer productivity, security, and performance at scale with the unified platform for API management, service mesh, and ingress controller.

Sign up for Kong newsletter

Platform
Kong KonnectKong GatewayKong AI GatewayKong InsomniaDeveloper PortalGateway ManagerCloud GatewayGet a Demo
Explore More
Open Banking API SolutionsAPI Governance SolutionsIstio API Gateway IntegrationKubernetes API ManagementAPI Gateway: Build vs BuyKong vs PostmanKong vs MuleSoftKong vs Apigee
Documentation
Kong Konnect DocsKong Gateway DocsKong Mesh DocsKong AI GatewayKong Insomnia DocsKong Plugin Hub
Open Source
Kong GatewayKumaInsomniaKong Community
Company
About KongCustomersCareersPressEventsContactPricing
  • Terms•
  • Privacy•
  • Trust and Compliance
  • © Kong Inc. 2025