An AI agent that calls a model, a tool, or another agent has to prove who it is. Almost every production failure I have written up this month traces back to that one question being answered badly, or being answered for the wrong party.
This series works the problem from the bottom up: what the protocol specs actually define, what the platform can issue underneath them, and where the gap between the two has to be filled by a gateway.
The short version
The agent should hold nothing. Every credential an agent stores is a credential that leaks when the agent is compromised, and agents are compromised through their tool surface, not their login page. The pattern that holds up is: the agent presents an identity the platform already gave it, and something on the call path exchanges that identity for a short-lived, audience-bound token.
The spec layer is behind the platform layer. MCP’s roadmap names agent identity as a priority workstream, but the only stable piece authenticates the employee behind the agent, not the agent. If you are shipping this quarter, the workload identity you need exists — just one layer down, in SPIFFE, in Kubernetes projected tokens, and in gateway-mediated token exchange.
Audience binding is the control people skip. A token that names no audience is replayable against every backend sharing an issuer. RFC 8707 fixes that, and the implementations that support it tend to ship with it switched off.
How to read these
Start with the MCP agent identity gap if you want to know what the protocol does and does not promise you. Start with secretless agents if you want a working demo first and the spec argument later. Start with SPIFFE workload identity for AI agents if you want attested identity with no secret on disk.
The posts below are listed newest first. They are independent; none assumes you read the others, but they were written against one running argument, and the audience-binding and token-service posts are the most directly operational of the set.
Every post in this series
- Per-Request Minted JWTs for Agent Backends with agentgateway
— agentgateway v1.5 signs a fresh 15-second JWT on every request, so an AI agent reaches its backend holding no key. Claims, expiry, and a failed replay, tested. - Do AI Agents Need SPIFFE or OAuth?
— SPIFFE proves which agent process is calling; OAuth scopes what it may do and for whom. When each is enough, and when production agents need both. - Building Workload Identity Federation for AI Agents on Kubernetes
— How an AI agent pod trades a Kubernetes service account token for a resource-scoped credential, with no shared secret and no long-lived key in the pod. - agentgateway CEL Gotchas: Fail-Open + 403 Fix
— agentgateway matchExpressions are OR'ed, so two rules fail open; llm.requestModel is empty at the traffic phase, so every call 403s. The working policy. - The agentgateway Token Service Now Runs Without a Cluster
— agentgateway enterprise 2026.9.0 ships its token service as a standalone binary on a public bucket, so a gateway-mediated agent identity setup fits on a laptop. - kagent Audience-Bound Tokens (RFC 8707)
— kagent v0.10.0 GA can bind an agent's exchanged token to one backend using RFC 8707 resource indicators. Two environment variables, both empty by default. - MCP Agent Identity: What Shipped, What to Use
— MCP has one shipped identity spec, and it authenticates the employee, not the agent. DPoP and Workload Identity Federation are still open. What to use now. - SPIFFE for AI Agents: End-to-End Identity Demo
— An agentgateway v1.5.0 demo where the agent, the gateway, and the model upstream all authenticate with SPIFFE SVIDs and no certificate file exists anywhere. - Your AI Agent Should Not Hold the LLM API Key
— How an AI agent calls an LLM with no API key in its env, disk, or process: short-lived identity at agentgateway, provider key attached at the gateway.