
What is AI agent identity?
An AI agent that borrows a person's token or a shared API key cannot be limited, audited or stopped on its own. Here is what an identity for an agent consists of.
Guides and engineering notes on identity, access and AI agents, from the people building AuthFI.

An AI agent that borrows a person's token or a shared API key cannot be limited, audited or stopped on its own. Here is what an identity for an agent consists of.



Identity, boundaries and approvals for software that acts on its own.

An agent will try whatever its input tells it to. A boundary limits what it can reach, for how long, and where the limit is enforced so the agent cannot argue with it.

Where authentication sits in an agent's tool call, how OAuth-based authorisation works for MCP, and why a token must never be passed through to the API behind a tool.

Some actions should not be an agent's decision alone. How to pick them, and how to design approval requests that people actually read before they answer.
How the fabric is built and run.

This blog is a Next.js app on Cloudflare Workers with a Strapi CMS. Pages are pre-rendered, cached at the edge and regenerated only when a webhook says content changed.

Identity data is personal data. What counts as identity data, how regional planes and a global control plane divide the work, and what may reasonably cross a border.

An audit record should answer who did what, on whose behalf, from where and with what outcome. How to design the fields, make it tamper-evident and keep it searchable.
Sign-in, single sign-on, passkeys and recovery for the people you serve.

SAML 2.0 and OpenID Connect both deliver single sign-on, in different shapes. How each one works, when to pick which, and what it takes to run both side by side.

Recovery is the weakest door into most accounts. Design rules for a recovery email that helps a locked-out person without handing an attacker a second way in.

Employees and customers both sign in, but the users, scale, lifecycle and sign-in methods differ. Here is how the two compare and when one platform fits both.
Guides to roles, access and choosing the right tools.

Role-based access control decays unless it is maintained. How permissions, roles and bindings fit together, and how to find roles nobody holds or that grant nothing.

A shared kubeconfig tells the cluster nothing about who is calling. How OIDC, RBAC subjects and short-lived credentials tie Kubernetes access to a person or workload.

A vendor-neutral checklist for choosing an identity provider: protocols, sign-in methods, lifecycle, audit, data residency, key custody, AI agents and your exit plan.
Keys, certificates and the controls that keep access honest.

SSH keys copied to servers outlive the people who made them. Certificates signed by a CA expire in minutes, name who may log in and leave a record. How they work.

Step-up authentication asks for a stronger or fresher factor only before sensitive actions. Which actions to cover, how fresh a session must be, and how to avoid MFA fatigue.
Protecting applications and services without changing their code.

Zero-code authentication puts sign-in and access checks in front of a service instead of inside it. How sidecars, proxies and kernel interception compare, and when to use an SDK.

How services prove who they are to each other with mTLS, workload identity and short-lived certificates, and why a shared static API key is the wrong tool for the job.