Your agents keep their own model, planning, and memory. When they act — call a tool, move money, send mail — AgentAuth verifies who is asking, judges the action against the intent you approved, rehearses the write before it commits, and puts every step on the record. Revocable instantly.
→ request: pay invoice #4821
✓ identity signed request verified — key-bound, no shared secret
✓ intent consistent with approved mission "reconcile May invoices"
▸ rehearsal simulated: $1,840 → ACME Corp · matches request
✓ verdict PROCEED · scope: payments.send · expires in 90s
# audit sha256:9f2c…e1a7 appended · undo reference stored
✓ executed — on the record ▌
Most agent security stops at authentication — “here is a valid token.” It never inspects, simulates, or governs the action itself. A fully authorized agent can still be prompt-injected, misled by a poisoned tool response, or simply wrong.
holds static API key
Every agent carries a cryptographic identity bound to its own key, with signed requests on every call. A stolen token is useless without the key — and there are no shared secrets to leak.
no credentials held
✓signature validbound to agent key
✓proof of possessionno shared secret
✓replay windowfresh nonce
Each action is checked against the mission you approved and the full history of the task. An action that doesn't fit the stated intent is escalated or refused — even when the credentials are valid.
“reconcile May invoices”
content-addressed · sha256:22ab…90fe
Before a write commits, AgentAuth runs it in a safe simulation and reports exactly what it would do. If the predicted effect exceeds the request, the action pauses for human approval.
simulated: transfer $1,840 → ACME Corp
✓predicted effect matches request1 payment
✓no data leaves tenant
Approved actions run with a fresh, narrowly scoped, short-lived token. Every step lands in an append-only, cryptographically chained log — searchable, exportable to your SIEM, undoable where possible.
scope: payments.send · ttl 90s
minted for this action · nothing durable to steal
✓executed — on the recordsha256:9f2c…e1a7
✓undo reference stored
no credentials held
✓signature validbound to agent key
✓proof of possessionno shared secret
✓replay windowfresh nonce
Deterministic policy — identity, scopes, expiry, revocation — decides what may happen, with no machine learning anywhere. AI judgment can escalate, narrow, or refuse an action, but it can never expand authority beyond what policy already granted. A wrong or manipulated model degrades to more caution, never less.
AAuth-compatible and MCP-native: conformant agents work out of the box, and existing integrations connect through a compatible endpoint without adopting anything new.
Agents hold no credentials at all. Authority exists only as a fresh, task-scoped token minted per individual action — there is nothing durable to steal from the client.
bound to this action · useless anywhere else
credentials stored on the agent: 0
AI agents for banking operations — and hyper-customized ERP.
AgentAuth is now onboarding early-access teams. Tell us what your agents need to do, and we'll show you what they can do safely.
Get early access