Agent identity
OAuth, NHI, authentication, and authorization
Agentic identity / NHI 126
- Astrix Securityastrix.security
- Aembitaembit.io
- Keycardkeycard.sh
- Descopedescope.com
- AgentCordongetcordoned.sh
- AI Agent Authentication and Authorizationdatatracker.ietf.org
- Detecting Malicious Entra OAuth Apps with LLM-Based Permission Riskarxiv.org
- CIMD - OAuth Client ID Metadata Documentsclient.dev
- SEP-991: Enable URL-based Client Registration using OAuth Client IDgithub.com
- RFC: Simplify OAuth with Domain-as-Client-ID Principle - Alternativgithub.com
- Authorize every prompt. Authenticate every agent.pomerium.com
- How to Secure Agents using OAuth — Jared Hanson (Keycard, Passporyoutu.be
- Keycard is identity infrastructure for the agent-native worldkeycard.ai
- Will AI Agents Force Us to Finally Do Auth Right?blog.christianposta.com
- AI agent identity: it's just OAuthmayakaczorowski.com
- $82,000 in 48 Hours from stolen Gemini API Key. My monthly Usagereddit.com
- CLI Installer – AuthKit – WorkOS Docsworkos.com
- CLI proxy that reduces LLM token consumption bgithub.com
- US Secretary of War Pete Hegseth: Today, we are unleashing https://t.co/7ZlxYquxk3 Thisx.com
- modelcontextprotocol/docs/specification/draft/basic/authorization.mgithub.com
- Extensions to authorizationgithub.com
- Back in July, Neeraj Gupta introduced DeepPass2, a smarter secret scanner thatx.com
- Securing your agents with authentication and authorizationblog.langchain.com
- MCP server for the Delinea Secretgithub.com
- How Pixel and Android are bringing a new level of trust tosecurity.googleblog.com
- I've seen a lot of complaints about how MCP isn't ready formodelcontextprotocol.io
- ngalongc/AuthzAIgithub.com
- Introducing Agentic Wallets, our first ever wallet infrastructure built specifically for autonomousx.com
- Paid + GitLaw: Introducing Legal Contracts Built for AI Agents - Papaid.ai
- Introducing SpiceBox and spicedb-devauthzed.com
- A Comprehensive Formal Security Analysis of OAuth 2.0arxiv.org
- Abusing Delegated Permissions via Easy Authdazesecurity.io
- Abusing Intune Permissions for Lateral Movement and Privilege Escalation in Entra ID Native Environmentscloud.google.com
- AC2 Protocol - cryptographic control and verifiable actions for AI agentsac2protocol.org
- Agent Auth by Vigil - DID identity and authentication for AI agentsusevigil.dev
- Agent Auth Protocol - open standard for AI agent authentication and capability-based authorizationagent-auth-protocol.com
- Agent identity: a new access model for autonomous, team-wide AIclaude.com
- agent-directory - first-class AI agent identities in Active Directorygithub.com
- Agents can now create Cloudflare accounts, buy domains, and deployblog.cloudflare.com
- AgentsID - Identity for AI Agentsagentsid.dev
- AI Agents act for a person - Not just as themselveslinkedin.com
- Announcing Keycard for Coding Agentskeycard.ai
- Announcing Keycard for Multi-Agent Apps: Auth for Agentic Systemskeycard.ai
- Announcing Microsoft Entra Agent ID: Secure and manage your AI agentstechcommunity.microsoft.com
- Announcing native AI agent support in HashiCorp Vaulthashicorp.com
- Apono - Just-in-Time Cloud Permission Management and Agentic Privileged Accessapono.io
- AppTotal - OAuth app posture and permission analysisapptotal.io
- Attacking Entra Metaverse, Part 1 - SpecterOpsposts.specterops.io
- auth.md - open protocol for AI agent registration and user-scoped credentialsworkos.com
- Azure's Hidden Operators: A Threat Model for Platform-Level Managed Identitiesvectra.ai
- BloodHound Enterprise Expands Beyond Microsoft: Mapping Identity Attack Paths Across Okta, GitHub, and Macspecterops.io
- Border0 is joining Tailscale - modern privileged access managementtailscale.com
- Borrowing Windows Hello keys for authentication and persistencedirkjanm.io
- CAPSlock - Offline Entra Conditional Access policy analysis toolgithub.com
- Claude API Workload Identity Federation - short-lived identity tokens instead of static API keysplatform.claude.com
- Creating immutable users through a bug in Entra ID restricted administrative unitssecuritylabs.datadoghq.com
- CrowdStrike to Acquire SGNL to Secure Every Identity in the AI Eracrowdstrike.com
- CVE-2025-47949 Reveals Flaw in samlify That Opens Door to SAML Single Sign-On Bypassendorlabs.com
- CVE-2026-1529 - Keycloak unauthorized organization registration via improper invitation token validationcvefeed.io
- Emilien Socchi on AzRoleWatcher detecting 12 new Azure application permissionsx.com
- Enterprise-Managed Authorization: Zero-touch OAuth for MCPblog.modelcontextprotocol.io
- Entra ID Attack Pathsjbaes.be
- Entra Identity Governance Portal - self-hosted Entra ID app and identity risk governancegithub.com
- Entra Token Broker - secretless federated auth for Entra-joined devicesgithub.com
- EntraOps Classification Explorer - privileged role and permission tiering for Entra ID and Azurecloud-architekt.net
- FerrisKey - open-source cloud-native IAM written in Rustgithub.com
- FIDO Cross Device Phishingdenniskniep.github.io
- GitHub Copilot SDK - Azure managed identity setupgithub.com
- Giving OpenClaw Its Own Identity, And a Sandbox to Run Inblog.somecreativity.com
- GraphSpy - the Swiss Army Knife for attacking M365 and Entrainsights.spotit.be
- HashiCorp Boundary LDAP authenticationhashicorp.com
- How Okta Passwords Can Be Compromised: Uncovering a Risk to User Datamitiga.io
- Human Principal - privacy-preserving proof that a human is behind an agent, by Auth0Labhumanprincipal.ai
- Identity as a New Security Perimeter - ISACAisaca.org
- Identity Management for Agentic AI - OpenID Foundation whitepaperopenid.net
- Identity Management for Agentic AI: The New Frontier of Authorization, Authentication, and Securityarxiv.org
- Identity Providers for RedTeamersblog.xpnsec.com
- Just-in-time approval workflow with Boundary and Azurehashicorp.com
- Macaroons: Cookies with Contextual Caveats for Decentralized Authorization in the Cloudstorage.googleapis.com
- Martez Reed on workload identity for Proxmox via an AWS-style metadata serverx.com
- Nathan McNulty on using evilginx-captured ESTSAUTH cookies to auto-register a passkeyx.com
- NHInsight - find risky non-human identities and access paths across cloudsgithub.com
- Oasis Security Research Uncovers Microsoft Azure MFA Bypassoasis.security
- obo-wash - persistent Azure AD credentials via on-behalf-of flowgithub.com
- Obtaining Microsoft Entra Refresh Tokensinfosecnoodle.com
- Oh-Auth: Abusing OAuth to take over millions of accountssalt.security
- OhAuth - community OAuth index for auditing over-privileged appsohauth.ai
- Okta AD/LDAP Delegated Authentication - Username Above 52 Characters Advisorytrust.okta.com
- Okta brings first-class identity to AI agents with Agent SSOokta.com
- Okta buys AI security startup Permiso - source says for about $200Mtechcrunch.com
- Okta for Red Teamers - TrustedSec post-exploitation techniques against Oktatrustedsec.com
- Okta with Axiom Security: Delivering robust privileged access for modern infrastructure in the AI eraokta.com
- One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokensdirkjanm.io
- OneLogin, Many Secrets: Clutch Uncovers Critical API Vulnerability Exposing Client Credentialsclutch.security
- Open-sourcing OpenPubkey SSH - OPKSSH - integrating single sign-on with SSHblog.cloudflare.com
- OpenClaw bug: gateway overwrites fresh OAuth token with stale cached state on startupgithub.com
- OrcaID - an account in your agent's nameorcaid.ai
- Orion Belt - Self-hosted SSH/RDP access gateway with PAM workflowsgithub.com
- Otterize - Intent-Based Access Control for Kubernetes Workload IAMdocs.otterize.com
- Permissions in the Age of AI-Driven Companiesdust.ghost.io
- Persistence via App Registration in Entra IDcyberdom.blog
- Phishing for Codes: Russian Threat Actors Target Microsoft 365 OAuth Workflowsvolexity.com
- Phishing for Primary Refresh Tokens and Windows Hello keysdirkjanm.io
- Potential Risk of Privilege Escalation in Azure AD Applicationsmsrc.microsoft.com
- Public Disclosure: Backdooring Managed Identities via Azure API Managementdazesecurity.io
- Securing the Agentic Workforce: Cisco Announces Intent to Acquire Astrix Securityblogs.cisco.com
- Silent provisioning of FIDO key to use for headless requests against hidden APIslieben.nu
- Snowflake to Acquire Natoma to Bring Governed Agentic Access to the Enterprisesnowflake.com
- SSO Gadgets: Escalate Self-XSS to Account Takeover via OAuth2 and OIDCsecurity.lauritz-holtmann.de
- Supporting more identity providers on Ubuntu with the new Authd OIDC brokerubuntu.com
- The Authorization Code grant in excruciating detail - Part 2 of 2stackoverflow.blog
- The complete guide to protecting your APIs with OAuth2 - part 1stackoverflow.blog
- The Hallucination Defense - why logs make 'the AI did it' the perfect excuseniyikiza.com
- The Human Root of Trust - framework for cryptographic accountability in agent systemshumanrootoftrust.org
- The Ultimate Guide To Non-Human Identities - NHI Mgmt Groupnhimg.org
- Tony Dang announces Agent Vault - open source credential proxy and vault for agentsx.com
- Traveling with OAuth - Account Takeover on Booking.comsalt.security
- Understanding the Complete Identity Management Ecosystem: IAM, CIAM, PAM Explainedguptadeepak.com
- unix-oidc - OIDC authentication for Unix/Linuxgithub.com
- Vorim AI - trust layer for AI agents with cryptographic identity and audit trailsvorim.ai
- Warden - secure gateway connecting AI agents to enterprise systemsgithub.com
- Why is OAuth still hard in 2026 - lessons from implementing OAuth for 50 popular APIsnango.dev
- World - World ID proof of human network for the AI eraworld.org
- Yubico and Delinea Close the Agentic AI Accountability Gapyubico.com
- Yubico will introduce secure and privacy capable passkey enabled digital signatures in upcoming 5.8 firmwareyubico.com
- Zeko Labs - Agent Mission-Bound Auth: cryptographically verified autonomous agent workflowsx.com