Connect with us

AI

Optimizing AI Agent Token Costs through Okta’s MCP Scoping

Published

on

Okta targets AI agent token costs with MCP scoping

Reducing AI Agent Token Costs with Identity-Scoped Model Context Protocol (MCP) Tool Lists

Okta, a leading identity management company, has introduced a new approach to minimize token costs for AI agents through the use of identity-scoped Model Context Protocol (MCP) tool lists.

When an AI agent makes a model call, it typically receives a list of schemas, names, descriptions, and parameters for all tools available on an MCP server. Okta refers to the overhead generated by this process as the “tool tax”, as tokens are consumed even for tools that the agent may never actually use.

According to Okta, this cost is incurred before an agent even attempts to call a tool, and once tokens are consumed, they cannot be recovered if the request is later rejected. To address this issue, Okta has proposed a solution that filters the list of tools based on permissions assigned to the agent’s identity and the associated user.

Internal studies conducted by Okta have shown that implementing this filtering mechanism can reduce the number of visible tools by more than 90%. While exact token and dollar figures were not provided, Okta claims that the costs associated with tool schemas also decreased proportionally.

MCP Tool Schemas and Prompt Overhead

MCP servers serve as a bridge for connecting AI agents to various tools and data sources, such as Google Workspace and Slack. However, the sheer volume of tools exposed by an MCP server can lead to significant prompt overhead for AI agents.

Each time a model call is made, the agent receives a representation of every available tool, including its schema, name, description, and parameters. This overhead becomes more pronounced when dealing with MCP servers that expose a large number of tools, leading to increased costs for each active user.

See also  Breaking Barriers: How Anthropic's Multi-Session Claude SDK Revolutionized AI Agent Technology

Furthermore, the issue extends to access control, as agents may attempt to use tools outside their authorized scope. By filtering the tool list before it reaches the agent, Okta aims to mitigate this problem and reduce unnecessary schema costs.

Implementing Tool Filters for Enhanced Security

Okta’s approach to filtering tools is part of its broader strategy for securing enterprise agents. By allowing administrators to configure the tools that each identity can access, Okta ensures that agents only see a subset of tools that are relevant to their role.

By limiting the tool set presented to the agent, Okta reduces the risk of unauthorized tool usage and enforces least-privilege access at the tool level. This not only enhances security but also optimizes the token and dollar costs associated with model calls.

While Okta has not provided specific customer deployment examples, its methodology is based on internal modeling using product data and industry documentation, emphasizing the potential benefits of identity-based scoping for AI agents.

Comparing Identity Entitlements and Gateway Controls

Okta contrasts identity-based scoping with traditional gateway controls, highlighting the benefits of using identity governance tools for cost control and precision. While gateways can cap spending and enforce routing rules, identity entitlements offer a more granular approach by defining the tools available to each specific agent or user.

Paul Webber, a cybersecurity analyst, commended Okta’s approach for leveraging entitlement data to govern security effectively. By filtering tools at the identity layer, Okta ensures that only authorized tools are accessible to agents, reducing the likelihood of costly security breaches.

See also  "Gemini's Revolutionary AI Agent: The Next Generation of Technology"

Enhancing Security with Scoped Tool Visibility

Okta emphasizes the role of scoped tool visibility in reducing security risks associated with MCP access. By restricting the tools visible to each identity, Okta minimizes the potential impact of a compromised agent and limits the actions that can be taken in such scenarios.

Organizations can leverage Okta’s methodology to map MCP server tools to OAuth scopes, allowing them to compare the full tool catalogue with the scoped catalogue visible to different user segments. This approach not only enhances security but also streamlines the AI agent’s decision-making process.

Okta’s innovative solution for reducing AI agent token costs through identity-scoped tool lists demonstrates the company’s commitment to enhancing security and optimizing efficiency in enterprise environments. By implementing tailored access controls and filtering mechanisms, organizations can mitigate risks and drive cost savings while empowering AI agents to perform their tasks effectively.

If you’re interested in learning more about AI and big data technologies, consider attending the upcoming AI & Big Data Expo event hosted by Okta in Amsterdam on October 19-20, 2026. For more information and to explore other industry events, visit the TechForge Media website.

Trending