← Back to Playbooks
Identity

Agent Credential Architectures (Unstealable ≠ Scoped)

Map the four public designs — then close the shared gap with audience-bound tokens

Operator recipe for production agent credentials. Treat egress-proxy / placeholder designs (Google Managed Agents, NVIDIA OpenShell) as containment against sandbox exfiltration — not as authorization. Map the four public architectures from the WorkOS comparison (21 Sep 2026): egress proxy + placeholders; Rubrik per-call token minting at an MCP gateway; Microsoft Entra GSA MCP firewall protocol inspection; Opal Zero decide-then-delegate into an existing gateway. For each, record the failure it removes and the gap it leaves. Hard rule, restated from Google’s own agents docs in that comparison: only store credentials whose full scope you are willing to grant. Unstealable is not the same as scoped. Close the shared gap with an authorization server that issues audience-bound, short-lived tokens (MCP authorization spec 2026-07-28; clients send the RFC 8707 resource parameter) that the resource server can verify itself. Distinct from /playbooks/agent-identity-kya/ (network KYA / Connections) and /playbooks/harness-permission-outside-agent/ (host grants connectors/egress). Operator recipe only — not a restatement of Research Field Notes #79. Primary: https://workos.com/blog/agent-credential-architectures. Optional implementation detail: https://workos.com/docs/authkit/mcp (CIMD, resource indicators, protected-resource metadata). Related catalog: /resources/tools/workos-authkit/.

0
Registrations
$1,000
Prize Pool
Feb 23, 2026
Starts
0%
Complete

Core Workflows (6)

Each workflow represents a critical business function. Click any workflow to see detailed automation architecture.

01

Inventory which layer you actually run

Led by: Credential Operator

WorkOS: five vendors shipped four architectures; they intervene at different layers and protect against different failures. The useful exercise is not picking a “best” one — it is working out which failure each one actually removes, because most leave a specific gap, and it is the same gap in almost every case. List the credential path your agent uses today (sandbox env, egress proxy, MCP gateway, network firewall, decide-then-delegate). Do not collapse this recipe into /playbooks/agent-identity-kya/ (who the agent is on a network) or /playbooks/harness-permission-outside-agent/ (host grants connectors/egress).

Sub-Agents
Inventory
Skills Required
WorkOS agent-credential comparisonArchitecture inventory
Human TouchpointWrite down the layer you run before adopting another vendor’s design as a substitute
02

Map egress proxy + placeholders (Google, NVIDIA)

Led by: Credential Operator

Failure removed (WorkOS table): credential theft from the sandbox, credentials in logs or model context. Failure left: over-broad credential scope, confused deputy. Google Managed Agents: store a write-only secret, reference it by ID on a network allowlist; an egress proxy injects the header on the wire. If an SDK reads process.env, the variable holds a placeholder; the proxy swaps the real value only for that credential’s trusted_domains. NVIDIA OpenShell: credentials are providers attached per sandbox at creation (no host-env inheritance; cannot attach to a running sandbox). Binding is to an endpoint (host, port, path); mismatch returns 403 credential_endpoint_mismatch. Seccomp blocks raw socket syscalls; a network namespace forces egress through a local CONNECT proxy. A proxy you can route around is a suggestion. This is containment, not authorization.

Sub-Agents
Egress ProxySandbox
Skills Required
Google Managed Agents placeholdersNVIDIA OpenShell providers
Human TouchpointConfirm the runtime never sees the live secret — and that you still treat scope as a separate problem
03

Map per-call token minting (Rubrik)

Led by: Credential Operator

Failure removed (WorkOS table): standing privilege, credential reuse across actions. Failure left: requires a gateway in the path for every call. Rubrik Agent Identity (Black Hat, 4 Aug): the agent holds a credential worth almost nothing. Every tool call clears three checkpoints at an MCP gateway — SAGE behavioural analysis of intent/parameters/impact, an infrastructure policy check, then an identity step that authenticates the session and mints a token scoped to that single call. On-Behalf-Of federation scopes access to servers and tools by user and group; the agent cannot exceed the permissions of the user behind it. Rubrik MCP (15 Sep, co-engineered with Anthropic) is in private preview, with general availability targeted for October — do not treat that target as live GA.

Sub-Agents
MCP Gateway
Skills Required
Rubrik Agent IdentityPer-call token minting
Human TouchpointIf you adopt this shape, budget a gateway on every call; do not claim Rubrik MCP GA before October ships
04

Map protocol inspection (Microsoft GSA MCP firewall)

Led by: Network Operator

Failure removed (WorkOS table): unapproved servers and tools, protocol downgrade. Failure left: nothing about what the token means; stdio uncovered. Microsoft’s Global Secure Access MCP firewall (public preview) does not handle credentials. It inspects MCP JSON-RPC 2.0 over streamable HTTP and Server-Sent Events and allow/blocks servers, primitives, methods, unencrypted HTTP, and outdated protocol versions via Conditional Access. Hard limits in the docs, restated by WorkOS: TLS inspection must be on (MCP rides inside HTTPS); only remote HTTP transports are covered — stdio does not traverse Global Secure Access. Distinct from a host-authority grant in /playbooks/harness-permission-outside-agent/.

Sub-Agents
Credential Operator
Skills Required
Entra GSA MCP firewallTLS inspection
Human TouchpointTurn on TLS inspection if you rely on this control; do not treat stdio / local MCP as covered
05

Map decide-then-delegate (Opal Zero)

Led by: Policy Operator

Failure removed (WorkOS table): permanent grants, unowned agents, unreviewed access. Failure left: depends on a gateway that can enforce what it writes. Opal Zero (launched 17 Sep, general availability at the end of the month per WorkOS): an agent files a request through Opal’s MCP server; Paladin evaluates it against written policy and organisational context (who owns the agent, what it was built for, whether the request reaches past what the owner holds). Gateway Sync then writes a scoped, time-bound decision into the MCP gateway the enterprise already runs — Databricks Unity Gateway and AWS AgentCore Gateway supported at launch. No second control plane. Connectors include Okta Cross App Access and Claude’s Enterprise-Managed Authorization for MCP connectors.

Sub-Agents
Existing MCP Gateway
Skills Required
Opal ZeroGateway Sync
Human TouchpointConfirm the gateway you already run can enforce the decision Opal writes; do not invent a second enforcement plane
06

Close the shared gap: audience-bound short-lived tokens

Led by: Authorization Operator

Hard rule (Google’s agents docs, restated by WorkOS): “The agent may use any credential it has access to, so only provide credentials whose full scope you are willing to grant.” Unstealable ≠ scoped. From inside the perimeter, a placeholder is exactly as powerful as the secret it stands for. A confused-deputy injection that persuades the agent to make a different request to an allowlisted domain still gets authenticated. NVIDIA endpoint binding is a scoping control, not a secrecy one. The durable answer WorkOS names: a short-lived token bound to a specific audience — the only artifact the resource server can check for itself. Under MCP 2026-07-28, an MCP server is an OAuth resource server: it validates every token and confirms the token was issued for itself as audience. Clients must send the resource parameter from RFC 8707 on authorization and token requests. Servers must not accept tokens issued for anything else, and must not forward a token they received upstream. AuthKit’s MCP docs cover CIMD registration, resource indicators, protected-resource metadata, and issuer validation so the server’s job is validating the token and deciding what its bearer may do. Gateway, proxy, and firewall are legitimate layers; none substitute for that authorization server.

Sub-Agents
MCP Resource Server
Skills Required
MCP 2026-07-28RFC 8707 resource indicatorsAuthKit MCP
Human TouchpointDo not ship a “hidden PAT” as scoped access; require audience-bound short-lived tokens the resource server verifies