← heapsort-ai

authorization

10 items

DOCDEV.to AI·4/22/2026

AI Agent Authentication & Authorization: How to Secure Tool Calls, OAuth Scopes, and Permissions in Production

This content addresses a new security challenge for autonomous AI agents, where authorization failures and prompt injection can lead to unintended actions, such as accessing sensitive APIs. It introduces a guide for a complete security architecture for production AI agents, covering identity management, OAuth, and permissions.

27
ARTICLEDEV.to AI·4/24/2026

Letters of Marque for AI Agents: The 600-Year Authorization Architecture You're Reinventing

The content introduces a three-token architecture for AI agent authorization, extending OAuth 2.0 and OpenID Connect with User ID, Agent-ID, and Delegation tokens. It insightfully compares this modern approach to the 600-year-old governance system of "Letters of Marque" for privateers, highlighting parallels in identity, scope, accountability, and review.

27