AgentSec is Authdog's security layer for AI agents: authenticate agents the way you authenticate people, and govern what they can call the way you govern workloads. One owner, one identity, one revoke switch per agent. Product page: /product/agentsec.
Most teams today hand agents the same static API keys humans use. Those keys can't tell you who is calling, can't be scoped to specific tools, live forever, and share one blast radius across every agent. AgentSec replaces that with two connected halves:
| Half | Problem it solves | Where it lives |
|---|---|---|
| Agent authentication | An agent signs into your app with its own identity, through the standard browser-based OIDC code flow — no shared credentials, revocable in one click | Agent Sign-In |
| Agent access control | An agent calls your APIs and MCP servers with a registered identity: verified subject, allowed tools, kill switch, and per-agent activity | Agents module |
Authenticate agents into your app
Agent Sign-In gives an agent what a person gets from your login page: an identity it owns, a browser-based sign-in loop your app already knows how to consume, and an owner who can cut it off.
- Your app configures two values — its
httpsorigin as theclient_idand a same-site redirect URI. No registration, no client secret. - The agent proves possession of a P-256 key: kept in its browser for interactive use, or a key file its own runtime signs with for headless operation.
- The agent gets an OIDC identity: synthetic address,
sub,email,name,actor_type: agent— standard claims your existing token validation already handles. - Approvals are remembered (180 days, sliding) so repeat sign-ins are zero-interaction, and honest revocation stops new sign-ins immediately while existing tokens die within minutes.
Govern what agents call
The Agents module registers every non-human caller in your environment's trust store and gates what it can reach:
- Register and verify the caller — a provisioned OIDC client, an existing client ID, a SPIFFE ID, or a URI.
- Scope allowed tools with globs and allowed scopes;
mcp_rug_pulldetection fires when a pinned MCP manifest drifts from the live tool list. - Revoke is an issuer-side kill switch: new tokens fail immediately.
- Audit every tool invocation, denial, and trust violation per agent in the Activity tab — not one undifferentiated "API key" in your logs.
For agents that act on a user's behalf, delegation uses RFC 8693 token
exchange with an explicit act chain — never account impersonation.
Shared guarantees
Both halves run on the same rules:
| Guarantee | What it means |
|---|---|
| Owner-bound | Every agent identity has an accountable human owner in your directory; recreating an identity mints a new sub |
| Per-environment | An agent registered in dev is not registered in prod; scoping never leaks across environments |
| Revocable | One click stops new sign-ins and new tokens; existing tokens live at most their documented minutes |
| Auditable | Authentication and tool activity land in the same environment audit trail |
| No shared credentials | Each agent holds its own key; a leaked key compromises one agent, not the fleet |
Where to start
| If you… | Read |
|---|---|
| Build an app that agents should sign in to | Agent Sign-In |
| Run APIs or MCP servers that agents call | Agents module |
| Are choosing between M2M, agents, service accounts, and PATs | Machine identity |
| Want a first gated agent running end to end | Agents quickstart |
The Agents module is sales-gated — request access if the console page is locked.