Agent Credential Architectures (Unstealable ≠ Scoped)
Map the four public designs — then close the shared gap with audience-bound tokens
Operator recipe for production agent credentials. Treat egress-proxy / placeholder designs (Google Managed Agents, NVIDIA OpenShell) as containment against sandbox exfiltration — not as authorization. Map the four public architectures from the WorkOS comparison (21 Sep 2026): egress proxy + placeholders; Rubrik per-call token minting at an MCP gateway; Microsoft Entra GSA MCP firewall protocol inspection; Opal Zero decide-then-delegate into an existing gateway. For each, record the failure it removes and the gap it leaves. Hard rule, restated from Google’s own agents docs in that comparison: only store credentials whose full scope you are willing to grant. Unstealable is not the same as scoped. Close the shared gap with an authorization server that issues audience-bound, short-lived tokens (MCP authorization spec 2026-07-28; clients send the RFC 8707 resource parameter) that the resource server can verify itself. Distinct from /playbooks/agent-identity-kya/ (network KYA / Connections) and /playbooks/harness-permission-outside-agent/ (host grants connectors/egress). Operator recipe only — not a restatement of Research Field Notes #79. Primary: https://workos.com/blog/agent-credential-architectures. Optional implementation detail: https://workos.com/docs/authkit/mcp (CIMD, resource indicators, protected-resource metadata). Related catalog: /resources/tools/workos-authkit/.
Core Workflows (6)
Each workflow represents a critical business function. Click any workflow to see detailed automation architecture.
Inventory which layer you actually run
Led by: Credential OperatorWorkOS: five vendors shipped four architectures; they intervene at different layers and protect against different failures. The useful exercise is not picking a “best” one — it is working out which failure each one actually removes, because most leave a specific gap, and it is the same gap in almost every case. List the credential path your agent uses today (sandbox env, egress proxy, MCP gateway, network firewall, decide-then-delegate). Do not collapse this recipe into /playbooks/agent-identity-kya/ (who the agent is on a network) or /playbooks/harness-permission-outside-agent/ (host grants connectors/egress).
Map egress proxy + placeholders (Google, NVIDIA)
Led by: Credential OperatorFailure removed (WorkOS table): credential theft from the sandbox, credentials in logs or model context. Failure left: over-broad credential scope, confused deputy. Google Managed Agents: store a write-only secret, reference it by ID on a network allowlist; an egress proxy injects the header on the wire. If an SDK reads process.env, the variable holds a placeholder; the proxy swaps the real value only for that credential’s trusted_domains. NVIDIA OpenShell: credentials are providers attached per sandbox at creation (no host-env inheritance; cannot attach to a running sandbox). Binding is to an endpoint (host, port, path); mismatch returns 403 credential_endpoint_mismatch. Seccomp blocks raw socket syscalls; a network namespace forces egress through a local CONNECT proxy. A proxy you can route around is a suggestion. This is containment, not authorization.
Map per-call token minting (Rubrik)
Led by: Credential OperatorFailure removed (WorkOS table): standing privilege, credential reuse across actions. Failure left: requires a gateway in the path for every call. Rubrik Agent Identity (Black Hat, 4 Aug): the agent holds a credential worth almost nothing. Every tool call clears three checkpoints at an MCP gateway — SAGE behavioural analysis of intent/parameters/impact, an infrastructure policy check, then an identity step that authenticates the session and mints a token scoped to that single call. On-Behalf-Of federation scopes access to servers and tools by user and group; the agent cannot exceed the permissions of the user behind it. Rubrik MCP (15 Sep, co-engineered with Anthropic) is in private preview, with general availability targeted for October — do not treat that target as live GA.
Map protocol inspection (Microsoft GSA MCP firewall)
Led by: Network OperatorFailure removed (WorkOS table): unapproved servers and tools, protocol downgrade. Failure left: nothing about what the token means; stdio uncovered. Microsoft’s Global Secure Access MCP firewall (public preview) does not handle credentials. It inspects MCP JSON-RPC 2.0 over streamable HTTP and Server-Sent Events and allow/blocks servers, primitives, methods, unencrypted HTTP, and outdated protocol versions via Conditional Access. Hard limits in the docs, restated by WorkOS: TLS inspection must be on (MCP rides inside HTTPS); only remote HTTP transports are covered — stdio does not traverse Global Secure Access. Distinct from a host-authority grant in /playbooks/harness-permission-outside-agent/.
Map decide-then-delegate (Opal Zero)
Led by: Policy OperatorFailure removed (WorkOS table): permanent grants, unowned agents, unreviewed access. Failure left: depends on a gateway that can enforce what it writes. Opal Zero (launched 17 Sep, general availability at the end of the month per WorkOS): an agent files a request through Opal’s MCP server; Paladin evaluates it against written policy and organisational context (who owns the agent, what it was built for, whether the request reaches past what the owner holds). Gateway Sync then writes a scoped, time-bound decision into the MCP gateway the enterprise already runs — Databricks Unity Gateway and AWS AgentCore Gateway supported at launch. No second control plane. Connectors include Okta Cross App Access and Claude’s Enterprise-Managed Authorization for MCP connectors.
Close the shared gap: audience-bound short-lived tokens
Led by: Authorization OperatorHard rule (Google’s agents docs, restated by WorkOS): “The agent may use any credential it has access to, so only provide credentials whose full scope you are willing to grant.” Unstealable ≠ scoped. From inside the perimeter, a placeholder is exactly as powerful as the secret it stands for. A confused-deputy injection that persuades the agent to make a different request to an allowlisted domain still gets authenticated. NVIDIA endpoint binding is a scoping control, not a secrecy one. The durable answer WorkOS names: a short-lived token bound to a specific audience — the only artifact the resource server can check for itself. Under MCP 2026-07-28, an MCP server is an OAuth resource server: it validates every token and confirms the token was issued for itself as audience. Clients must send the resource parameter from RFC 8707 on authorization and token requests. Servers must not accept tokens issued for anything else, and must not forward a token they received upstream. AuthKit’s MCP docs cover CIMD registration, resource indicators, protected-resource metadata, and issuer validation so the server’s job is validating the token and deciding what its bearer may do. Gateway, proxy, and firewall are legitimate layers; none substitute for that authorization server.