Runtime auth for agents

Give each agent its own identity, authority to act, and access to resources under your policy.

“We wanted our engineers deploying agents and tools into production without needing to be security or identity experts. Keycard’s platform made that possible. We had agents running against production systems in days.”

Dennis Yang, Principal Product Manager, Generative AI at Chime

The Challenge

The better your agents get, the more access they need.

Agents accumulate privilege, and most teams have no way to narrow it back down.

  • Put a human in front of every action?

    Manual approvals don’t scale.

  • Let an agent inherit a human or workload identity?

    There’s no way to tell who took what action.

  • Provision for everything it might need?

    That’s also everything it could do.

How Keycard works

Keycard verifies each request, evaluates it against policy, and makes authorization decisions for your agents and whatever they need to access.

  1. Capture the full context

    Keycard verifies the agent making the request and where it’s running.

    When it acts for a user, the request also carries that user’s identity. The full picture is used to make authorization decisions at runtime.

  2. Make resources available

    Connect a resource once and make it available to whoever needs it.

    Resources can be data stores, MCP servers, APIs, or agents. Configure the resource’s credential provider and Keycard will handle all authorization requests against it.

    Configure Resources
    • Knowledge MCP
    • GitHub API
    • PagerDuty MCP
    • Sentry MCP
    • Neon MCP
    • Linear MCP
    • Slack API

    Custom resource Knowledge MCP

    Identifier
    https://kb.internal/mcp
    Credential provider
    Keycard
    Credential type
    Scoped access token
    Connect custom resource (Keycard docs, opens in a new tab)
  3. Grant access dynamically

    At runtime, each request is evaluated against policy.

    If approved, Keycard’s secure token server issues a short-lived authorization token scoped to the task at hand.

    If denied, no credentials are created but the decision is logged for visibility.

  4. See real-time activity

    Inspect sessions by application, user, or resource and export audit logs to your SIEM.

    Each authorization event includes full attribution, including denials. Revoke a credential instantly and subsequent events are denied wherever it applies.

    Research agent

    • On behalf of
      Alex Lee
      Resource
      GitHub API
      Credential issued
      Delegated OAuth token
      Scope
      repo
    • On behalf of
      Alex Lee
      Resource
      Slack API
      Credential issued
      Delegated OAuth token
      Scope
      channels:read
    • On behalf of
      Alex Lee
      Resource
      Knowledge MCP
      Credential issued
      Scoped access token
      Scope
      knowledge:read
    • On behalf of
      Alex Lee
      Outcome
      Denied
      Reason

      Policy denied the credential request.

      Alex Lee doesn’t have PII access, so neither does this agent. Rule: agents-inherit-user-scope

agents-inherit-user-scope.cedar
Rule effect
Permit Forbid
principal
any
action
any
resource
is Resource pii-db
unless
context.subject in Group pii-access

Policy as Code

Write the rules.
Apply them at runtime.

Define access in Cedar and manage changes using Terraform. Validate and test new policies, then activate the version you want Keycard to use for credential requests.

Policy enforcement points

Integrate Keycard where it’s needed

Use the request path you already have. Choose where authorization should happen to protect the resources your agents use.

  1. 01 / Application

    In your application

    Add authentication, authorization, and delegated API access to any agent or MCP server with a few lines of code.

    Keycard handles everything—no token plumbing, no auth middleware, no security footguns.

  2. 02 / Gateway

    Through a gateway

    A gateway brokers authentication and authorization across agents, clients, and resources.

    Each request gets secure, policy-checked access from Keycard with no code changes.

  3. 03 / Infrastructure

    In your infrastructure

    A sidecar proxy intercepts the agent’s outbound traffic and swaps placeholder secrets for real, user-scoped tokens from Keycard.

    The agent stays unchanged and never holds a real credential.

Enterprise Ready

Built on open standards.
Helping write the new ones.

Keycard speaks the protocols your stack already uses, ships drop-in SDKs for the services you build, and federates the identity providers you run today. Policy is written in Cedar and applied through Terraform, the same way you manage the rest of your infrastructure.

SOC 2 Type II Visit Trust center
Identity
Federate users and workloads with your existing identity providers.
Build
Add auth to agents and MCP servers with drop-in SDKs
Policy
Write policy as code and manage changes programmatically.
Audit export
Export events to any SIEM that reads OCSF, or send them to S3.

Agent Baseline

White Paper

A shared framework for deploying enterprise AI agents, developed in partnership with Docker and Snyk. Six outcomes and the capabilities, implementation requirements, and evidence associated with each one. Bring it to your next security review to evaluate your agentic security posture.

Developed with Snyk, Docker and Keycard

Read Agent Baseline (opens in a new tab)

On the record

Insecure Agents

What practitioners are running into.

Conversations about building and securing AI agents from our podcast, Insecure Agents.

Explore episodes of Insecure Agents (opens in a new tab)

More about Keycard

Frequently asked questions

What is Keycard and what does it do?

Keycard is runtime authorization infrastructure for AI agents. It gives applications their own identity, evaluates credential requests against policy, and issues credentials when access is allowed. Register applications and resources once, then reuse them as you build.

Who is Keycard for?

Developers building agents and internal tools, alongside platform, security, and AI operations teams bringing them into production. Use Keycard with your agents, MCP servers, APIs, and other services.

When should a company use Keycard?

When agents need to act on production systems at scale. If you’re managing dozens of MCP servers, using multiple human and workload identity providers, or considering refactoring existing applications one-by-one, that’s a sign you need Keycard.

How does Keycard work with my existing stack?

Keycard federates the identity provider you already run, whether that’s Okta, Entra, Google, or Auth0, and adds policy and token issuance on top rather than replacing it. SDKs for Python, TypeScript, Ruby, and Go cover services your developers build. Policy is defined in Cedar and ships as code through Terraform. Supported audit events export to your Amazon S3 bucket for ingestion by compatible SIEM tools. If you already run an AI gateway, talk to us about how it can act as the enforcement point for authorization decisions.

What is runtime authorization for AI agents?

Runtime authorization for AI agents means the access decision is made when the agent acts, not when access was set up or when the agent was deployed. Each request carries context on which agent is asking, where it’s running, who it’s acting for, and what it wants to reach. Policy is evaluated against the full composite identity, and if approved, a credential is issued for the approved access.

The alternatives are to let the agent inherit a human identity or a shared service account with standing permissions; to pre-authorize the agent with its own fixed set of permissions, sized in advance to cover everything it might need; or to gate progressive privilege by human-in-the-loop approvals. Each gives something up. Inherited access is sized to someone else’s job and attributed to them rather than to the agent. A pre-authorized grant is written before anyone knows what the agent will do, so it covers everything it might do. Approvals fit a small set of sensitive operations, but they don’t scale to every request.

How is Keycard’s approach to agent access different from other solutions?

Most solutions inspect traffic after a credential already exists. Keycard evaluates each request against policy and issues credentials only if access is approved. If the request is denied, Keycard issues no new credential. Keycard records policy decisions and credential requests in audit logs. Keycard mints the tokens, but your traffic doesn’t have to go through it. With the SDK in your app or a proxy in your infrastructure, your agent talks to the resource directly. Calls pass through Keycard only if you route them through its gateway, which is optional.

Give every agent a Keycard

Book a demo