Keep credentials out of prompts
Design connections so provider secrets do not need to enter agent code or model context.
Product
Customer IdentityPublic beta · Hosted customer authenticationMCP AuthorizationDeveloper preview · Scoped AI-client accessAgent AccessDesign partner · External provider accessWorkforce IdentityDesign partner · Employee lifecycle and SSODevelopers
OverviewHosted Auth, OAuth/OIDC, and MCPDocumentationGuides & integrationAPI referenceEndpoints & schemasTrust
DPDP readinessChecklist & readiness reviewSecurityHow we protect your dataPrivacyHow we handle your dataWe are exploring governed connections from agents to external providers: who authorized the connection, what the agent may do, how long access lasts, and how a person revokes it. This is separate from protecting your own MCP server.
Design connections so provider secrets do not need to enter agent code or model context.
Represent the person, agent, resource, scope, and approval behind an action.
Prefer narrow, short-lived access over durable credentials copied between systems.
Agent Access is in design, not a generally available feature. Today’s implemented agent-facing foundation is MCP Authorization for customer-owned resources; external-provider credentials, autonomous agent principals, and broader delegation remain roadmap work.
In design