AgentSec is Authdog's security layer for AI agents: authenticate agents
the way you authenticate people, and govern what they can call the way you
govern workloads. One owner, one identity, one revoke switch per agent.
Product page: [/product/agentsec](/product/agentsec).

Most teams today hand agents the same static API keys humans use. Those
keys can't tell you who is calling, can't be scoped to specific tools,
live forever, and share one blast radius across every agent. AgentSec
replaces that with two connected halves:

| Half | Problem it solves | Where it lives |
|------|-------------------|----------------|
| **Agent authentication** | An agent signs **into your app** with its own identity, through the standard browser-based OIDC code flow — no shared credentials, revocable in one click | [Agent Sign-In](/docs/agent-sign-in) |
| **Agent access control** | An agent **calls your APIs and MCP servers** with a registered identity: verified subject, allowed tools, kill switch, and per-agent activity | [Agents module](/docs/console/agents) |

## Authenticate agents into your app

[Agent Sign-In](/docs/agent-sign-in) gives an agent what a person gets from
your login page: an identity it owns, a browser-based sign-in loop your app
already knows how to consume, and an owner who can cut it off.

- Your app configures two values — its `https` origin as the `client_id`
  and a same-site redirect URI. No registration, no client secret.
- The agent proves possession of a P-256 key: kept in its browser for
  interactive use, or a key file its own runtime signs with for headless
  operation.
- The agent gets an OIDC identity: synthetic address, `sub`, `email`,
  `name`, `actor_type: agent` — standard claims your existing token
  validation already handles.
- Approvals are remembered (180 days, sliding) so repeat sign-ins are
  zero-interaction, and honest revocation stops new sign-ins immediately
  while existing tokens die within minutes.

## Govern what agents call

The [Agents module](/docs/console/agents) registers every non-human caller
in your environment's trust store and gates what it can reach:

- **Register and verify** the caller — a provisioned OIDC client, an
  existing client ID, a SPIFFE ID, or a URI.
- **Scope allowed tools** with globs and allowed scopes; `mcp_rug_pull`
  detection fires when a pinned MCP manifest drifts from the live tool
  list.
- **Revoke** is an issuer-side kill switch: new tokens fail immediately.
- **Audit** every tool invocation, denial, and trust violation per agent
  in the Activity tab — not one undifferentiated "API key" in your logs.

For agents that act on a user's behalf, delegation uses RFC 8693 token
exchange with an explicit `act` chain — never account impersonation.

## Shared guarantees

Both halves run on the same rules:

| Guarantee | What it means |
|-----------|---------------|
| Owner-bound | Every agent identity has an accountable human owner in your directory; recreating an identity mints a new `sub` |
| Per-environment | An agent registered in `dev` is not registered in `prod`; scoping never leaks across environments |
| Revocable | One click stops new sign-ins and new tokens; existing tokens live at most their documented minutes |
| Auditable | Authentication and tool activity land in the same environment audit trail |
| No shared credentials | Each agent holds its own key; a leaked key compromises one agent, not the fleet |

## Where to start

| If you… | Read |
|---------|------|
| Build an app that agents should sign in to | [Agent Sign-In](/docs/agent-sign-in) |
| Run APIs or MCP servers that agents call | [Agents module](/docs/console/agents) |
| Are choosing between M2M, agents, service accounts, and PATs | [Machine identity](/docs/machine-identity) |
| Want a first gated agent running end to end | [Agents quickstart](/docs/quickstarts/agents) |

The Agents module is sales-gated — [request access](/docs/console/support)
if the console page is locked.