Identity
Issue one durable subject to the Agent, independent of its host.
Identity and delegated access for AI agents
Give every Agent a durable identity and controller-approved access to the exact APIs, scopes, and lifetime it needs.
Agent Passport / Authority Flow
Why Realmroot
Realmroot models an Agent as its own security principal while keeping a human or organization in control of every authority decision.
The Agent keeps one issuer and subject while host keys rotate, move, or are revoked. A machine credential never becomes the public identity.
Stable identity ≠ host credentialEstablishing identity does not imply business access. A new resource, account, or wider scope always requires a new controller decision.
Identity first. Authority on request.After approval, the Agent calls native or external APIs directly with a short-lived, audience-bound, DPoP-bound token.
Agent → API, directlyExplicit authority
Every grant binds one Agent to one resource, exact scopes, and a clear lifetime. Audit records reconstruct who approved what without recording credentials or raw tokens.
Read the Agent authority model →tickets:readdrafts:writeLimited · 30 minOne realm, every actor
People, applications, APIs, and Agents share one issuer and policy boundary. Your product stops stitching together a login system, an Agent key vault, and an authorization proxy.
Hosted sign-in, MFA, passkeys, sessions
OIDC clients and product integrations
Durable identity and delegated authority
Native or external protected resources
Journal
Authentication is only the front door. A product also needs one explicit boundary for users, applications, policy, APIs, and delegated agents.
Durable agent identity, host credentials, and delegated API authority solve different problems. Treating them as one secret creates accidental power.
Why Realmroot makes the deployment—not an organization row or application record—the identity isolation boundary.
One realm. Every actor. Explicit authority.
Run one realm as the trust root for people, applications, APIs, and Agents.