AI
Optimizing AI Agent Token Costs through Okta’s MCP Scoping
Reducing AI Agent Token Costs with Identity-Scoped Model Context Protocol (MCP) Tool Lists
Okta, a leading identity management company, has introduced a new approach to minimize token costs for AI agents through the use of identity-scoped Model Context Protocol (MCP) tool lists.
When an AI agent makes a model call, it typically receives a list of schemas, names, descriptions, and parameters for all tools available on an MCP server. Okta refers to the overhead generated by this process as the “tool tax”, as tokens are consumed even for tools that the agent may never actually use.
According to Okta, this cost is incurred before an agent even attempts to call a tool, and once tokens are consumed, they cannot be recovered if the request is later rejected. To address this issue, Okta has proposed a solution that filters the list of tools based on permissions assigned to the agent’s identity and the associated user.
Internal studies conducted by Okta have shown that implementing this filtering mechanism can reduce the number of visible tools by more than 90%. While exact token and dollar figures were not provided, Okta claims that the costs associated with tool schemas also decreased proportionally.
MCP Tool Schemas and Prompt Overhead
MCP servers serve as a bridge for connecting AI agents to various tools and data sources, such as Google Workspace and Slack. However, the sheer volume of tools exposed by an MCP server can lead to significant prompt overhead for AI agents.
Each time a model call is made, the agent receives a representation of every available tool, including its schema, name, description, and parameters. This overhead becomes more pronounced when dealing with MCP servers that expose a large number of tools, leading to increased costs for each active user.
Furthermore, the issue extends to access control, as agents may attempt to use tools outside their authorized scope. By filtering the tool list before it reaches the agent, Okta aims to mitigate this problem and reduce unnecessary schema costs.
Implementing Tool Filters for Enhanced Security
Okta’s approach to filtering tools is part of its broader strategy for securing enterprise agents. By allowing administrators to configure the tools that each identity can access, Okta ensures that agents only see a subset of tools that are relevant to their role.
By limiting the tool set presented to the agent, Okta reduces the risk of unauthorized tool usage and enforces least-privilege access at the tool level. This not only enhances security but also optimizes the token and dollar costs associated with model calls.
While Okta has not provided specific customer deployment examples, its methodology is based on internal modeling using product data and industry documentation, emphasizing the potential benefits of identity-based scoping for AI agents.
Comparing Identity Entitlements and Gateway Controls
Okta contrasts identity-based scoping with traditional gateway controls, highlighting the benefits of using identity governance tools for cost control and precision. While gateways can cap spending and enforce routing rules, identity entitlements offer a more granular approach by defining the tools available to each specific agent or user.
Paul Webber, a cybersecurity analyst, commended Okta’s approach for leveraging entitlement data to govern security effectively. By filtering tools at the identity layer, Okta ensures that only authorized tools are accessible to agents, reducing the likelihood of costly security breaches.
Enhancing Security with Scoped Tool Visibility
Okta emphasizes the role of scoped tool visibility in reducing security risks associated with MCP access. By restricting the tools visible to each identity, Okta minimizes the potential impact of a compromised agent and limits the actions that can be taken in such scenarios.
Organizations can leverage Okta’s methodology to map MCP server tools to OAuth scopes, allowing them to compare the full tool catalogue with the scoped catalogue visible to different user segments. This approach not only enhances security but also streamlines the AI agent’s decision-making process.
Okta’s innovative solution for reducing AI agent token costs through identity-scoped tool lists demonstrates the company’s commitment to enhancing security and optimizing efficiency in enterprise environments. By implementing tailored access controls and filtering mechanisms, organizations can mitigate risks and drive cost savings while empowering AI agents to perform their tasks effectively.
If you’re interested in learning more about AI and big data technologies, consider attending the upcoming AI & Big Data Expo event hosted by Okta in Amsterdam on October 19-20, 2026. For more information and to explore other industry events, visit the TechForge Media website.
-
Facebook10 months agoEU Takes Action Against Instagram and Facebook for Violating Illegal Content Rules
-
Facebook10 months agoWarning: Facebook Creators Face Monetization Loss for Stealing and Reposting Videos
-
Facebook8 months agoFacebook’s New Look: A Blend of Instagram’s Style
-
Facebook10 months agoFacebook Compliance: ICE-tracking Page Removed After US Government Intervention
-
Facebook8 months agoFacebook and Instagram to Reduce Personalized Ads for European Users
-
Facebook10 months agoInstaDub: Meta’s AI Translation Tool for Instagram Videos
-
Facebook8 months agoReclaim Your Account: Facebook and Instagram Launch New Hub for Account Recovery
-
Apple10 months agoMeta discontinues Messenger apps for Windows and macOS

