Skip to main content
Enterprise Managed Authorization lets your organization connect members to Unblocked in Claude through Okta, without requiring each member to complete a separate Unblocked browser sign-in. For more background, see the official MCP documentation on Enterprise-Managed Authorization.

Prerequisites

Before you start, confirm that:
  1. You are configuring Claude (Anthropic). This setup is only for the Unblocked connector in Claude.
  2. Your organization uses Okta as its SSO provider for both Claude and Unblocked. Other identity providers are not supported for this setup.
  3. Okta SSO for Unblocked is configured.
  4. User and group provisioning (SCIM) is enabled, and the members who need access are provisioned in Unblocked.
  5. You have organization-admin access in Claude and the Super Admin role in Okta.
To check your Unblocked configuration, open Single Sign-On settings. Under SAML Configuration, look for Configured for Okta. Under SCIM User Provisioning, check the Last Synced timestamp to confirm provisioning has synced. Unblocked settings showing SAML configured for Okta and a last synced timestamp under SCIM User Provisioning

Configure managed authorization

1

Open your organization settings in Claude

Sign in to your organization’s Claude account through Okta SSO. Open your account menu and select Organization settings.Claude account menu with Organization settings selected
2

Find the Unblocked connector

Select Connectors under Libraries & Access. If Unblocked is already listed, open it. Otherwise, select Add, then All available to open the connector directory.Claude organization Connectors page with Add and All available selectedSearch for Unblocked. Add the connector if needed, then open its details.Unblocked in the Claude connector directory search results
3

Start managed authorization setup

Open the Configuration tab. Under Managed authorization, select Set up.Unblocked connector Configuration tab with the Managed authorization Set up button
4

Follow Anthropic's Okta setup guide

In the Connect step, confirm that Okta is the connected identity provider, then select Open WorkOS setup.Managed authorization Connect step with the Open WorkOS setup linkFollow all steps in the Anthropic setup guide that opens. It provides the instructions and values for configuring Cross-App Access (XAA), the AI agent, and its resource connection in Okta.Use the existing Okta application that provides SSO to your Unblocked organization when configuring the connector application. The application name may differ from the example shown below. For the agent’s user access, use your organization’s Claude SSO application as directed by the guide.Anthropic WorkOS guide for configuring the connector application and completing the Okta setup
Claude may also display a step to enable managed authorization in Unblocked’s admin settings. No separate Unblocked managed authorization toggle is required. Complete the SSO and provisioning prerequisites above, then continue with the setup guide.
5

Test the connection

After completing the Anthropic guide, return to Claude and select Run test. Confirm that all checks pass, then select Continue.Successful checks for authorization server discovery, identity request, token exchange, and connector access
6

Choose who gets managed authorization

Select the Claude roles whose members should connect through Okta automatically. Members outside the selected roles keep browser sign-in. Select Continue.Claude role selection for members who will use managed authorization
7

Choose the MCP scope

Keep the mcp scope selected, then select Save & turn on.The mcp scope selected with the Save and turn on button
8

Confirm managed authorization is enabled

On the connector’s Configuration tab, confirm that Managed authorization is on and that Applied roles and Scopes match your selections.Unblocked connector with managed authorization enabled, applied roles, and mcp scope