🚀 AuthSec early access is open — sign up in 30 secondsGet access →
AuthSecAuthSec
AGENT CIAM

Your AI agents log users in. Make sure that login is real.

AuthSec extends the identity rails your customers already trust - OIDC login, MFA, consent - to every AI agent acting on their behalf. No parallel identity system, no bare API key standing in for a person.

DELEGATION TRACE - LIVEuser → agent → app
EVERY ACTION TRACES BACK TO A CONSENTING HUMANHUMAN USEROIDC+ MFAAI AGENTconfidential clientREGISTEREDCONSENT GRANTuser · agent · scopesREVOCABLE ANYTIMEID-JAGtokenexchangeSCOPEDMCP SERVERapproved · roleINTERNAL APIpending approvalAPPLICATIONS
01 - THE PROBLEM

A shared API key is not an identity.

NO USER BEHIND IT

Most “agent auth” today is a long-lived API key pasted into an agent's config file. No user is tied to it, no consent was ever captured, and revoking it breaks every workflow that shares it - not just the one you meant to stop.

NO EVIDENTIARY TRAIL

When an agent takes an action for a real customer, that action deserves the same trail a human login gets: who authorized it, exactly what it was allowed to do, and a way to revoke it without collateral damage.

NO INVENTORY

Security and IAM teams typically have no inventory of which agents are calling which internal APIs on whose behalf - until an incident forces them to reconstruct it after the fact.

02 - HOW IT WORKS

OIDC login, then token exchange, then a scoped token per application.

01

Register the agent

A single call mints a confidential OAuth client scoped to your workspace. You get back a client ID, a client secret (shown once), and your issuer URL - the three values you paste into the agent's own config.

02

The agent drives a real login

It doesn't invent its own auth - it signs the user in through the exact same OIDC flow, MFA, and WebAuthn/device rails your product already uses for humans.

03

The user consents once

What the agent may do is captured as a consent grant - this user, this agent, this application, these capabilities. Visible in a self-service view and revocable at any time, by the user or an admin.

04

Token exchange produces an ID-JAG

The agent exchanges the login result for a cross-app delegation assertion, then redeems it at each downstream Application for a scoped, short-lived token - never the user's original credential.

05

First contact is a pending connection

The first time an agent calls a given Application it shows up as a pending connection. An admin approves it with a specific role before the agent can do anything else there.

06

Every action traces back to a person

Because the token descends from a real login and a real consent grant, any agent action reads as: user X consented → agent Y acted → role Z allowed it.

03 - CAPABILITIES

Registration, consent, delegation, approval, and a kill switch.

Agent registration & inventory

Register an agent once; it appears in your inventory the moment it makes its first real connection, not before.

Consent grants, admin and self-service

Users see exactly what they've authorized, per application, and can revoke it themselves; admins can do the same workspace-wide.

Cross-app delegation via ID-JAG

Agents act through a real delegation token descended from a user login, not a shared static key.

Connection approval workflow

Every new agent → Application pairing starts pending and is approved with a specific role; connections are individually revocable.

Trust Delegation guardrails

Set a ceiling - maximum role, maximum permissions, maximum token lifetime - on what can ever be delegated under a given client, before any delegation happens.

Discovered Agents

Passively finds agents and workloads already running in your infrastructure that nobody registered; claim an owner or quarantine them from a governance queue.

Built-in debugging

A dry-run simulator answers “would this token even mint, and why not.” A cross-app checker explains why an agent can't reach an Application, with a shareable failure bundle.

Voice agents

IN PROGRESS

A CIBA-based push-approval pattern for phone and voice-driven agents, sharing the same MFA device infrastructure as human end users.

04 - WHO IT'S FOR
Product & app engineers

Wiring an AI agent into a customer-facing product without building a second identity system just for agents.

Security & IAM admins

Who need an inventory of every agent, what it can reach, and a per-agent kill switch.

Trust & safety / compliance

Who need proof that every agent action traces to a real user's consent, with revocation history intact.

WHY IT'S DIFFERENT

Not “issue the agent an API key and hope.” Not a bespoke agent-identity system bolted on beside your real user base.

The agent rides the exact same OIDC and consent rails your customers already use - so there's no second identity system to secure, audit, or explain to a compliance reviewer.

05 - TERMINOLOGY

What these words mean here.

Agent
A confidential OAuth client that logs a real user in and acts on their behalf - distinct from a Service Account, which has no user.
ID-JAG
The cross-app delegation token an agent redeems at each Application after a user's OIDC login and token exchange.
Consent grant
The record of what a user allowed a given client - including an agent - to do. Revocable anytime.
Connection
A specific agent ↔ Application pairing; pending until an admin approves it with a role.
Trust Delegation policy
The ceiling - maximum role, permissions, and token lifetime - on what can ever be delegated to an agent or workload under a given client.
Discovered Agent
An agent or workload found running in your infrastructure that nobody explicitly registered.
06 - FAQ
Is this a separate login system just for agents?
No - agents use the same OIDC login, MFA, and consent flow your product already runs for human users.
Can a user see which agents have access to their data?+
What stops an agent from doing more than the user allowed?+
What if we find an agent running that we never registered?+
Talk to us

Get in Touch

Have questions about AuthSec? Want to see how it fits your AI infrastructure? We're happy to help.

  • Request a live demo
  • Discuss your use case
  • Get technical guidance

Send us a message

We typically respond within one business day.

Give every agent a real identity.

Get started, or talk to us about migrating an existing agent fleet.