
What is AI agent identity?
An AI agent that borrows a person's token or a shared API key cannot be limited, audited or stopped on its own. Here is what an identity for an agent consists of.
7 posts

An AI agent that borrows a person's token or a shared API key cannot be limited, audited or stopped on its own. Here is what an identity for an agent consists of.

An agent will try whatever its input tells it to. A boundary limits what it can reach, for how long, and where the limit is enforced so the agent cannot argue with it.

Zero-code authentication puts sign-in and access checks in front of a service instead of inside it. How sidecars, proxies and kernel interception compare, and when to use an SDK.

How services prove who they are to each other with mTLS, workload identity and short-lived certificates, and why a shared static API key is the wrong tool for the job.

SSH keys copied to servers outlive the people who made them. Certificates signed by a CA expire in minutes, name who may log in and leave a record. How they work.

Step-up authentication asks for a stronger or fresher factor only before sensitive actions. Which actions to cover, how fresh a session must be, and how to avoid MFA fatigue.

A shared kubeconfig tells the cluster nothing about who is calling. How OIDC, RBAC subjects and short-lived credentials tie Kubernetes access to a person or workload.