Okta acquires Permiso for $200M to secure non-human identities in the cloud
The purchase of the AI-powered security startup strengthens Okta's ability to detect threats in machine identities, AI agents, and workloads in cloud environments.
July 31, 2026 · 4 min read
TL;DR: Okta has acquired Permiso, an AI-powered security startup, for about $200M. The deal aims to protect non-human identities (AI agents, bots, API keys) in the cloud, a rapidly growing market.
What happened?
Okta, the leading identity and access management (IAM) platform, has announced the acquisition of Permiso, a startup specializing in security for non-human identities (NHIs). According to sources close to TechCrunch, the deal is valued at around $200 million, although neither Okta nor Permiso has officially confirmed the figure. Permiso, founded in 2022 by former AWS and Google Cloud security engineers, uses artificial intelligence and machine learning to detect anomalous behavior in service accounts, API keys, OAuth tokens, certificates, and other types of non-human identities operating in cloud environments such as AWS, Azure, and GCP. Permiso's technology analyzes access patterns, traffic volumes, and unusual schedules to identify threats like stolen credentials, privilege abuse, or lateral movement. This acquisition comes after Okta suffered a security breach in October 2023, when attackers accessed its support system through a compromised service account, underscoring the strategic relevance of protecting non-human identities.
Why is it important?
Non-human identities—such as those of AI agents, bots, microservices, serverless functions, and applications—have multiplied exponentially in recent years. According to a 2024 CyberArk report, non-human identities outnumber human ones by a ratio of 45 to 1 in large organizations, and this gap is expected to widen with the massive adoption of generative AI. However, traditional security tools, such as intrusion detection systems (IDS) or SIEMs, are not designed to monitor the activity of these identities, which often have elevated permissions and access to critical data. This creates a huge and poorly monitored attack surface. The acquisition of Permiso allows Okta to address this gap by integrating real-time threat detection for NHIs into its identity platform. According to TechCrunch, the integration will enable Okta customers to apply Zero Trust policies to all identities, including non-human ones, with contextual alerts and automated response. This is especially critical at a time when attacks targeting NHIs are on the rise: CrowdStrike's 2024 threat report notes that incidents related to machine credentials grew 67% year-over-year.
Market implications
This deal positions Okta as a key player in the emerging non-human identity security market, which according to Gartner projections will reach $5.2 billion by 2028, with a compound annual growth rate of 24%. Competitors like Microsoft, with its Entra ID solution (formerly Azure AD), and CrowdStrike, which has integrated NHI capabilities into its Falcon platform, are also investing heavily in this segment. Okta's acquisition of Permiso is reminiscent of Okta's purchase of Auth0 in 2021 for $6.5 billion, which consolidated its leadership in identity-as-a-service (IDaaS). However, unlike that deal, this one focuses on a specific but high-growth niche. For Okta customers, the integration of Permiso promises unified visibility of all identities, human and non-human, with dashboards showing the risk of each entity and the ability to revoke access automatically. This could reduce the average time to detect NHI-related incidents from days to minutes, according to industry sources. However, the technical integration will not be trivial: Permiso currently supports public clouds but not hybrid or on-premise environments, limiting its initial scope. Additionally, the $200 million price tag seems high for a startup with estimated revenues of less than $10 million, suggesting Okta is betting on future potential rather than current revenue.
What should readers know?
Security teams should start cataloging and monitoring all non-human identities in their cloud environments. Tools like Permiso's can help, but the acquisition by Okta is a sign that the industry is moving toward a 'Zero Trust' model that includes machines. The functionality is expected to be available in the coming months as part of Okta Identity Threat Protection, though specific timelines have not been announced. Security leaders should also consider that protecting NHIs is not just technological: it requires changes in provisioning processes, credential rotation, and continuous monitoring. For companies already using Okta, the integration will likely be seamless, but customers of other IAM providers will need to seek alternative solutions, such as CyberArk Conjur or HashiCorp Vault, which also offer NHI capabilities. In summary, Okta's purchase of Permiso marks a milestone in the maturation of the non-human identity security market and underscores the urgency of addressing this growing attack vector. As Okta CEO Todd McKinnon said in a recent interview: 'Identity is the new perimeter, and that includes machines.'