agentgateway Token Exchange for AI Agents
An AI agent that calls tools for a user needs that user’s authority, and the usual shortcuts are a pasted personal access token or a shared service …
Read more →building the agentic future in public
I run LLMs, robots, and gateways into production walls so you don't have to. Deep dives on the agentic mesh, agent runtimes, AI gateways, and the Kubernetes substrate that keeps autonomous systems honest — every post ships with a repo you can clone and receipts you can check.
An AI agent that calls tools for a user needs that user’s authority, and the usual shortcuts are a pasted personal access token or a shared service …
Read more →MCP’s Enterprise-Managed Authorization lets the corporate IdP decide which employees can use which MCP servers, by making the client trade an IdP-signed …
Read more →An egress allowlist decides whether an agent can reach a destination. It has no opinion about how often. On October 7, 2026, the Wikimedia Foundation disclosed …
Read more →A production agent platform needs one gateway path where SPIFFE identity binds the caller and four controls ride the same hop: secretless provider keys, per-key …
Read more →agentgateway v1.6.0 went GA on October 2. Two features are worth a hands-on look before anything else: a built-in LLM pricing catalog that gives you cost …
Read more →They answer different questions. SPIFFE proves which process is calling, without a provisioned secret. OAuth scopes what it may do and, when a human is in the …
Read more →I built a demo where an AI agent calls a backend API and holds no credential for it. No API key in its environment, no key file on disk, no token. agentgateway …
Read more →Three replicas of an MCP server, fronted by agentgateway , with no session affinity configured anywhere. A four-call shopping cart session (create cart, add two …
Read more →I spent the last month building small, runnable labs for the ways AI agents break the infrastructure they run on: credentials, egress, audit logs, MCP tool …
Read more →Choose by the controls in the request path, not by model-catalog size. Write down what you must enforce on agent→model and agent→tool traffic: workload …
Read more →