
What is AI agent identity?
An AI agent that borrows a person's token or a shared API key cannot be limited, audited or stopped on its own. Here is what an identity for an agent consists of.
20 articles, newest first.

An AI agent that borrows a person's token or a shared API key cannot be limited, audited or stopped on its own. Here is what an identity for an agent consists of.

An agent will try whatever its input tells it to. A boundary limits what it can reach, for how long, and where the limit is enforced so the agent cannot argue with it.

Where authentication sits in an agent's tool call, how OAuth-based authorisation works for MCP, and why a token must never be passed through to the API behind a tool.

Some actions should not be an agent's decision alone. How to pick them, and how to design approval requests that people actually read before they answer.

How to put single sign-on in front of an old internal app without changing it, and why the identity headers it receives must be stripped and re-stamped at the boundary.

Zero-code authentication puts sign-in and access checks in front of a service instead of inside it. How sidecars, proxies and kernel interception compare, and when to use an SDK.

How services prove who they are to each other with mTLS, workload identity and short-lived certificates, and why a shared static API key is the wrong tool for the job.

How passkeys work under WebAuthn, the difference between synced and device-bound passkeys, and a rollout plan that covers fallback and recovery from day one.

SAML 2.0 and OpenID Connect both deliver single sign-on, in different shapes. How each one works, when to pick which, and what it takes to run both side by side.