Okta announces Sign in with Okta, an API that lets users sign in with their Okta account on other services
Add Sign In with Okta to Your Apps Today
Context & Ripple Effects
By 2018, Okta had already been anointed by the giants: Google named it the preferred identity provider for Google Apps enterprise customers in 2016, and on the very same day as this launch it deepened a Workplace by Facebook integration under Project Onramp. Sign in with Okta is the logical next step — turning the credential Okta already manages for enterprise employees into something those users can carry onto third-party services.
The move reframes Okta from back-office single sign-on into a front-door login option, a position consumer platforms were also racing to claim — TikTok would later ship its own Login Kit for developer sign-ins.
First-order effects
- Developers gain a one-API way to accept Okta credentials at signup, so any service can now authenticate against the workforce identities Okta already holds for its enterprise customers.
- Okta's moat shifts from being the SSO vendor inside the firewall to being a login button on the open web, directly monetizing the identity graph built through deals like the Google Apps partnership.
Second-order effects
- Consumer login providers — Facebook, Google, and later TikTok with its Login Kit — face competition for third-party app sign-in placement from a vendor whose credentials are backed by employers rather than ad-funded profiles.
- Rival enterprise SSO vendors must decide whether to match the external-login play or cede the 'sign in with your work account' category to Okta.
Third-order effects
- If workforce identity becomes a portable web-wide credential, the identity provider becomes the control layer for both human and, eventually, machine access — a trajectory Okta itself later extended with Okta Platform Services and biometric sign-in APIs, and which it now ties to agentic AI demand for identity tooling.
The trend: Identity providers are expanding from internal enterprise single sign-on into federated login for the open web, making the workplace credential a portable key across third-party services.