Introducing AgentAuth by Flow

The control plane for what AI agents do

Your agents keep their own model, planning, and memory. When they act — call a tool, move money, send mail — AgentAuth verifies who is asking, judges the action against the intent you approved, rehearses the write before it commits, and puts every step on the record. Revocable instantly.

Action ledger — liveagent: finance-bot

→ request: pay invoice #4821

✓ identity signed request verified — key-bound, no shared secret

✓ intent consistent with approved mission "reconcile May invoices"

▸ rehearsal simulated: $1,840 → ACME Corp · matches request

✓ verdict PROCEED · scope: payments.send · expires in 90s

# audit sha256:9f2c…e1a7 appended · undo reference stored

✓ executed — on the record ▌

Built on open standardsAAuthOAuth 2.1MCPSigned requestsSIEM export
The problem

Anatomy of an insecure agent

Most agent security stops at authentication — “here is a valid token.” It never inspects, simulates, or governs the action itself. A fully authorized agent can still be prompt-injected, misled by a poisoned tool response, or simply wrong.

1No identity

Agents + Users

holds static API key

intent
2PII exposed3No policy gate

Agent process

Workers
Memory
Foundational model
data access + actions
4Unvetted access

Tools + Services

  • MCP servers
  • APIs
  • Data stores
5No trail
  1. 1No identity. Any process holding the key is “the agent.”
  2. 2PII exposed. Tools see whatever the agent decides to send.
  3. 3No policy gate. Every authorized call goes through, asked-for or not.
  4. 4Unvetted access. Injected instructions in tool output become real actions.
  5. 5No trail. The audit log is whatever the agent chose to write.
How it works

Every action, four gates

01

Verify

Every agent carries a cryptographic identity bound to its own key, with signed requests on every call. A stolen token is useless without the key — and there are no shared secrets to leak.

Agent · finance-bot

no credentials held

signed request · sig ed25519:8a41…
AgentAuth · identity check

✓signature validbound to agent key

✓proof of possessionno shared secret

✓replay windowfresh nonce

01 · key-bound identity
02

Judge

Each action is checked against the mission you approved and the full history of the task. An action that doesn't fit the stated intent is escalated or refused — even when the credentials are valid.

Approved mission · immutable

“reconcile May invoices”

content-addressed · sha256:22ab…90fe

Actions judged against it
pay invoice #4821proceed
export all contactsdeny · outside mission
02 · intent judged
03

Rehearse

Before a write commits, AgentAuth runs it in a safe simulation and reports exactly what it would do. If the predicted effect exceeds the request, the action pauses for human approval.

Sandbox rehearsal

simulated: transfer $1,840 → ACME Corp

✓predicted effect matches request1 payment

✓no data leaves tenant

If the effect exceeds the request
would modify 1,200 recordspause · ask a human
03 · rehearsed before commit
04

Execute on the record

Approved actions run with a fresh, narrowly scoped, short-lived token. Every step lands in an append-only, cryptographically chained log — searchable, exportable to your SIEM, undoable where possible.

Per-action token

scope: payments.send · ttl 90s

minted for this action · nothing durable to steal

Append-only audit ledger

✓executed — on the recordsha256:9f2c…e1a7

✓undo reference stored

04 · on the recordrevoke — kill switch
The load-bearing guarantee

AI can only make it safer — never less safe

Deterministic policy — identity, scopes, expiry, revocation — decides what may happen, with no machine learning anywhere. AI judgment can escalate, narrow, or refuse an action, but it can never expand authority beyond what policy already granted. A wrong or manipulated model degrades to more caution, never less.

Platform

Built for agents acting in the real world

AAuth-compatible and MCP-native: conformant agents work out of the box, and existing integrations connect through a compatible endpoint without adopting anything new.

Zero standing privilege

Agents hold no credentials at all. Authority exists only as a fresh, task-scoped token minted per individual action — there is nothing durable to steal from the client.

  • Scope and lifetime matched to one request — stolen authority expires in minutes
  • Legacy API keys get a managed migration path
  • One kill switch revokes every outstanding token, instantly
Token lifecycle
request: pay invoice #4821judged · rehearsed
mint: scope payments.sendactive · ttl 90s

bound to this action · useless anywhere else

t+90stoken expired

credentials stored on the agent: 0

Also from Flow

AI agents for banking operations — and hyper-customized ERP.

Explore Solutions →

Put your agents on the record

AgentAuth is now onboarding early-access teams. Tell us what your agents need to do, and we'll show you what they can do safely.

Get early access