Security
Reduce attack surface from your own agents (and from others) with verified domains, scoped OAuth, and agent-first policies.
Our security approach
Self-registration
Your agents and scripts sign up just like users would, or require agent sign-ups to require a secret or invite code.
CLIs and APIs for easier automation
Agents, devices and users can be created and managed at scale.
Self-verifying
Your services verify against highly cached jwks.json on your own domain.
Reduces Risk
Agent-first
Opt-in policies and templates designed to restrict bad agent or script behavior.
Limited exposure
Trap agents and scripts in limited scopes and services, with no access to your entire system or data.
Inbound email hardening
Inbound messages to identity-related addresses are filtered aggressively, stripped of attachments and trackers, and routed to shared inboxes.
Auditable actions and logs
Watch and understand what your agents are doing and what they've done.
Security through clarity
Prevent your own agents from being a source of risk, and reduce the attack surface for others.