[{"data":1,"prerenderedAt":914},["ShallowReactive",2],{"blog-ai-agent-identity-least-privilege-en":3},{"slug":4,"published":5,"minutes":6,"category":7,"tags":8,"keywords":13,"about":24,"sources":34,"cover":77,"og":78,"expertise":79,"locales":80,"lang":81,"title":84,"description":85,"coverAlt":86,"metaTitle":87,"takeaways":88,"faq":94,"toc":113,"blocks":141,"others":609},"ai-agent-identity-least-privilege","2026-10-02",12,"security",[9,10,11,12],"AI agent identity","Least privilege","OAuth token exchange","Non-human identity",[14,15,16,17,18,19,20,21,22,23],"AI agent identity management","non-human identity AI agents","AI agent least privilege","OAuth token exchange for AI agents","on-behalf-of flow AI agent","Microsoft Entra Agent ID","Okta Agent SSO Cross App Access","AI agent credentials and secrets","offboarding AI agents","delegated vs autonomous agent access",[25,28,31],{"name":26,"url":27},"Identity management","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FIdentity_management",{"name":29,"url":30},"Principle of least privilege","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FPrinciple_of_least_privilege",{"name":32,"url":33},"OAuth","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FOAuth",[35,38,41,44,47,50,53,56,59,62,65,68,71,74],{"title":36,"url":37},"Microsoft Learn: What is Microsoft Entra Agent ID?","https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fentra\u002Fagent-id\u002Fwhat-is-microsoft-entra-agent-id",{"title":39,"url":40},"Microsoft Learn: What are agent identities?","https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fentra\u002Fagent-id\u002Fwhat-are-agent-identities",{"title":42,"url":43},"Microsoft Learn: Best practices for Microsoft Entra Agent ID","https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fentra\u002Fagent-id\u002Fbest-practices-agent-id",{"title":45,"url":46},"Microsoft Learn: Microsoft Entra Agent ID logs","https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fentra\u002Fagent-id\u002Fsign-in-audit-logs-agents",{"title":48,"url":49},"Microsoft Learn: How agent identity deletion works","https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fentra\u002Fagent-id\u002Fconcept-agent-identity-deletion",{"title":51,"url":52},"Microsoft Learn: What's new in Microsoft Entra Agent ID","https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fentra\u002Fagent-id\u002Fwhats-new-agent-id",{"title":54,"url":55},"Microsoft Learn: Microsoft Agent 365 overview","https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fmicrosoft-agent-365\u002Foverview",{"title":57,"url":58},"Okta: Okta brings first-class identity to AI agents with Agent SSO (24 August 2026)","https:\u002F\u002Fwww.okta.com\u002Fnewsroom\u002Fpress-releases\u002Fokta-brings-first-class-identity-to-ai-agents-with-agent-sso\u002F",{"title":60,"url":61},"Okta: Auth0 gives developers the identity layer to securely ship agentic apps (May 2026)","https:\u002F\u002Fwww.okta.com\u002Fnewsroom\u002Farticles\u002Fauth0-may-2026-product-innovations\u002F",{"title":63,"url":64},"IETF: RFC 8693, OAuth 2.0 Token Exchange","https:\u002F\u002Fwww.rfc-editor.org\u002Frfc\u002Frfc8693",{"title":66,"url":67},"Model Context Protocol blog: Enterprise-Managed Authorization, zero-touch OAuth for MCP (18 June 2026)","https:\u002F\u002Fblog.modelcontextprotocol.io\u002Fposts\u002Fenterprise-managed-auth\u002F",{"title":69,"url":70},"Model Context Protocol: Security best practices","https:\u002F\u002Fmodelcontextprotocol.io\u002Fspecification\u002Fdraft\u002Fbasic\u002Fsecurity_best_practices",{"title":72,"url":73},"WorkOS: AI agents and the multi-hop delegation problem","https:\u002F\u002Fworkos.com\u002Fblog\u002Foauth-multi-hop-delegation-ai-agents",{"title":75,"url":76},"TechCrunch: OpenAI launches Dots, its bubbly agentic avatar","https:\u002F\u002Ftechcrunch.com\u002F2026\u002F09\u002F29\u002Fopenai-launches-dots-its-bubbly-agentic-avatar\u002F","\u002Fimages\u002Fblog\u002Fai-agent-identity-least-privilege\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fai-agent-identity-least-privilege\u002Fog.jpg","ai-engineer",[81,82,83],"en","de","hu","AI agents are identities: least privilege for non-human users","Give every AI agent its own identity, delegated tokens and an off switch. Token exchange, secrets, audit and offboarding, plus what Entra, Okta and Auth0 ship.","Diagram: a user, an agent with its own identity and an identity provider that issues a short-lived, narrowly scoped token for an API.","AI agent identity and least privilege · Balázs Csorba",[89,90,91,92,93],"An agent that acts is a user of your systems. Give it its own identity, a named human sponsor and a lifecycle, not a copy of someone else's login or a shared API key.","Choose per task between delegated access (the agent acts for a person, limited by that person's rights) and autonomous access (the agent acts with its own, minimal rights). Never blend the two in one token.","OAuth token exchange (RFC 8693) is the standard building block: swap the user's token plus the agent's identity for a short-lived token with a narrow audience and scope that records both sub and act.","In 2026 the tooling exists: Microsoft Entra Agent ID and Agent 365 (GA 1 May), Okta Agent SSO (GA 24 August) with Cross App Access in MCP, and Auth0 for AI Agents. The protocols are standard; the governance is still your job.","Offboarding is the weakest link: disable first, delete later, reassign sponsors when people leave, and review agents on a schedule so no orphan keeps its access.",[95,98,101,104,107,110],{"q":96,"a":97},"What is a non-human identity for an AI agent?","It is an account of its own that a software agent uses to authenticate to systems, instead of borrowing a person's login or a shared key. Microsoft Entra Agent ID, for example, describes agent identities as identity accounts that give AI agents unique identification and authentication, distinct from workforce, customer and workload identities.",{"q":99,"a":100},"Should an AI agent use the user's credentials or its own?","Use delegated access when the agent does something for a specific person and should never exceed that person's rights, and use the agent's own identity when it runs autonomously on a schedule or event. Either way the agent should be identifiable in logs and its token should carry only the scopes the task needs. Sharing the user's password or a long-lived personal token is the pattern to avoid.",{"q":102,"a":103},"What is OAuth token exchange and why does it matter for agents?","RFC 8693 defines a grant in which a client presents a token it already holds and receives a different one with another audience or narrower scope. With an actor token it expresses delegation: the new token says that the agent acts on behalf of the user, via the act claim. That gives downstream APIs and audit logs both identities.",{"q":105,"a":106},"How do I store secrets for AI agents?","Avoid storing them: prefer managed identities or workload identity federation, issue short-lived tokens, and keep credentials in a vault or sidecar rather than in prompts, environment dumps or logs. Microsoft's best practices recommend federated credentials or certificates in production and client secrets only for development.",{"q":108,"a":109},"How do I offboard or shut down an AI agent safely?","Disable the identity first, because that blocks authentication immediately and keeps evidence, then delete it after review. In Entra, disabling a blueprint blocks all agents created from it, and deleted agent identities are restorable for 30 days. Also revoke third-party tokens the agent holds, remove its secrets and reassign or retire its sponsor.",{"q":111,"a":112},"Do Entra Agent ID, Okta and Auth0 solve agent identity?","They solve the plumbing: identities, token issuance, policies, logs and lifecycle workflows. They do not decide how much access an agent should have, who is accountable for it or what happens when it reads a malicious document. Those decisions remain with you, which is why the control checklist matters more than the vendor choice.",[114,117,120,123,126,129,132,135,138],{"id":115,"title":116},"why-identity","Why an agent needs its own identity",{"id":118,"title":119},"delegated-or-own","Delegated or own credentials: pick per task",{"id":121,"title":122},"token-flow","The delegated token flow",{"id":124,"title":125},"secrets","Secrets: the best credential is the one you do not store",{"id":127,"title":128},"vendors","What the vendors ship in October 2026",{"id":130,"title":131},"audit-offboarding","Audit and offboarding",{"id":133,"title":134},"checklist","Control checklist",{"id":136,"title":137},"what-to-do","What I would do first",{"id":139,"title":140},"sources","Sources",[142,150,153,156,159,168,169,180,227,238,241,242,253,262,269,281,284,287,288,291,324,327,328,331,393,401,402,405,408,422,424,427,438,439,442,540,543,544,547,560,563,564],{"type":143,"content":144},"paragraph",[145,146],"For two years most teams treated an AI agent as a feature of an application. It called tools with whatever credential was convenient: the developer's personal access token, a shared service account, an API key in an environment variable. That worked in a demo. It does not survive the first audit question, which is always the same: ",{"tag":147,"children":148},"em",[149],"who did this, and who allowed it?",{"type":143,"content":151},[152],"An agent that reads mail, files tickets or changes records is a user of your systems, just a very fast and very literal one. This article treats agents as identities and walks through the decisions that follow: delegated versus own credentials, OAuth token exchange, short-lived scoped tokens, secrets, audit and offboarding. I also checked what the vendors actually ship as of October 2026, because several announcements turned into generally available products over the summer.",{"type":154,"level":155,"id":115,"text":116},"heading",2,{"type":143,"content":157},[158],"Application identities were designed for services that people build, name and keep for years. Human identities come with passwords, MFA and a manager. An agent is neither. Microsoft's documentation describes agents that may exist for minutes, or be created and destroyed thousands of times per day, and names the problems an agent identity should solve: telling agent actions apart from those of employees, customers and workloads, giving right-sized access, keeping agents out of the most critical roles, and scaling to large, short-lived fleets.",{"type":143,"content":160},[161,162,167],"The practical argument is simpler. Without a separate identity you cannot answer three questions: what can this agent reach, what did it do, and how do I stop it without breaking a colleague's account? A shared token fails all three. If the agent also reads untrusted content, which most useful agents do, its permissions define the blast radius of a successful prompt injection (see ",{"tag":163,"to":164,"children":165},"link","\u002Fblog\u002Fprompt-injection-lethal-trifecta-patterns",[166],"the lethal trifecta patterns","). An identity is where you attach that limit.",{"type":154,"level":155,"id":118,"text":119},{"type":143,"content":170},[171,172,175,176,179],"There are really three ways an agent can authenticate, and only two of them are good. Entra Agent ID names the good ones explicitly: ",{"tag":147,"children":173},[174],"autonomous access",", using rights given directly to the agent identity, and ",{"tag":147,"children":177},[178],"delegated access",", where the agent acts on behalf of a human using rights given to the user, who controls what is delegated.",{"type":181,"head":182,"rows":191},"table",[183,185,187,189],[184],"Pattern",[186],"Who the API sees",[188],"Strength",[190],"Failure mode",[192,205,216],[193,199,201,203],[194,198],{"tag":195,"children":196},"strong",[197],"Borrowed login or shared key"," (anti-pattern)",[200],"The person or a shared account, never the agent",[202],"Fast to build",[204],"No attribution, no per-agent revocation, rights far beyond the task",[206,210,212,214],[207],{"tag":195,"children":208},[209],"Delegated (on behalf of a user)",[211],"The user, with the agent recorded as the actor",[213],"Agent can never exceed the user; consent and user policies apply",[215],"Needs a user in the loop; long-running jobs outlive the user session",[217,221,223,225],[218],{"tag":195,"children":219},[220],"Autonomous (own identity)",[222],"The agent itself",[224],"Fits schedules and events; rights are explicit and reviewable",[226],"Over-broad app permissions are easy to grant and hard to notice",{"type":143,"content":228},[229,230,233,234,237],"My rule: if the work is ",{"tag":147,"children":231},[232],"for"," someone, such as \"summarise my inbox\" or \"prepare my quote\", use delegated access, so the agent inherits that person's limits and your existing access policies keep working. If the work is ",{"tag":147,"children":235},[236],"by"," the agent as a role, such as nightly reconciliation or a support triage queue, give it its own identity with the smallest app-level permissions you can defend. Microsoft's best-practice guidance says the same: client credentials only with the required app permissions for autonomous agents, on-behalf-of for interactive ones, and no app permissions where delegated ones would do.",{"type":143,"content":239},[240],"One consequence is easy to miss. A delegated token is bounded by the user, and a user is often an administrator. Delegation does not help if the person behind it is over-privileged, so the agent's own scope must also be capped, and the effective rights are the intersection of the two.",{"type":154,"level":155,"id":121,"text":122},{"type":143,"content":243},[244,245,248,249,252],"The standard mechanism is OAuth 2.0 Token Exchange, RFC 8693. A client sends a ",{"tag":147,"children":246},[247],"subject token"," (who the request is for) and optionally an ",{"tag":147,"children":250},[251],"actor token"," (who is acting), together with the audience and scope it wants. Without an actor token you get impersonation, where the agent simply becomes the user and nobody can tell them apart. With one you get delegation, where the agent keeps its own identity and the new token records that it acts for the user.",{"type":254,"attrs":255,"inner":259,"caption":260},"diagram",{"viewBox":256,"role":257,"aria-labelledby":258},"0 0 720 446","img","d1-aid-t d1-aid-d","\u003Ctitle id=\"d1-aid-t\">Delegated access with token exchange\u003C\u002Ftitle>\u003Cdesc id=\"d1-aid-d\">Sequence between user, agent, identity provider and API. The user signs in and consents. The identity provider gives the agent a user token. The agent exchanges the user token plus its own identity for a short-lived token for the API with narrow scope, where sub is the user and act is the agent. The agent calls the API, which checks audience and scope and logs both identities.\u003C\u002Fdesc>\u003Ctext x=\"20\" y=\"24\" class=\"d-title\">Delegated access with token exchange\u003C\u002Ftext>\u003Ctext x=\"700\" y=\"24\" text-anchor=\"end\" class=\"d-label\">RFC 8693\u003C\u002Ftext>\u003Crect x=\"20\" y=\"44\" width=\"140\" height=\"46\" rx=\"10\" class=\"d-sky\" \u002F>\u003Ctext x=\"90\" y=\"63\" text-anchor=\"middle\" class=\"d-text\">User\u003C\u002Ftext>\u003Ctext x=\"90\" y=\"84\" text-anchor=\"middle\" class=\"d-small\">delegator\u003C\u002Ftext>\u003Crect x=\"200\" y=\"44\" width=\"140\" height=\"46\" rx=\"10\" class=\"d-accent\" \u002F>\u003Ctext x=\"270\" y=\"63\" text-anchor=\"middle\" class=\"d-text\">Agent\u003C\u002Ftext>\u003Ctext x=\"270\" y=\"84\" text-anchor=\"middle\" class=\"d-small\">own identity\u003C\u002Ftext>\u003Crect x=\"380\" y=\"44\" width=\"140\" height=\"46\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"450\" y=\"63\" text-anchor=\"middle\" class=\"d-text\">IdP\u003C\u002Ftext>\u003Ctext x=\"450\" y=\"84\" text-anchor=\"middle\" class=\"d-small\">identity provider\u003C\u002Ftext>\u003Crect x=\"560\" y=\"44\" width=\"140\" height=\"46\" rx=\"10\" class=\"d-mint\" \u002F>\u003Ctext x=\"630\" y=\"63\" text-anchor=\"middle\" class=\"d-text\">API\u003C\u002Ftext>\u003Ctext x=\"630\" y=\"84\" text-anchor=\"middle\" class=\"d-small\">resource\u003C\u002Ftext>\u003Cpath d=\"M90 90 V400\" class=\"d-line d-dash\" \u002F>\u003Cpath d=\"M270 90 V400\" class=\"d-line d-dash\" \u002F>\u003Cpath d=\"M450 90 V400\" class=\"d-line d-dash\" \u002F>\u003Cpath d=\"M630 90 V400\" class=\"d-line d-dash\" \u002F>\u003Cpath d=\"M90 138 H442\" class=\"d-line\" \u002F>\u003Cpath d=\"M450 138 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Ctext x=\"270\" y=\"130\" text-anchor=\"middle\" class=\"d-text\">1 Sign in and consent\u003C\u002Ftext>\u003Cpath d=\"M450 192 H278\" class=\"d-line\" \u002F>\u003Cpath d=\"M270 192 l9 -5 v10 z\" class=\"d-head\" \u002F>\u003Ctext x=\"360\" y=\"169\" text-anchor=\"middle\" class=\"d-text\">2 user token\u003C\u002Ftext>\u003Ctext x=\"360\" y=\"184\" text-anchor=\"middle\" class=\"d-small\">aud: agent\u003C\u002Ftext>\u003Cpath d=\"M270 246 H442\" class=\"d-line-accent\" \u002F>\u003Cpath d=\"M450 246 l-9 -5 v10 z\" class=\"d-head-accent\" \u002F>\u003Ctext x=\"360\" y=\"223\" text-anchor=\"middle\" class=\"d-text\">3 Token Exchange\u003C\u002Ftext>\u003Ctext x=\"360\" y=\"238\" text-anchor=\"middle\" class=\"d-small\">aud=API, narrow scope\u003C\u002Ftext>\u003Cpath d=\"M450 300 H278\" class=\"d-line-accent\" \u002F>\u003Cpath d=\"M270 300 l9 -5 v10 z\" class=\"d-head-accent\" \u002F>\u003Ctext x=\"360\" y=\"277\" text-anchor=\"middle\" class=\"d-text\">4 short-lived token\u003C\u002Ftext>\u003Ctext x=\"360\" y=\"292\" text-anchor=\"middle\" class=\"d-small\">sub=user, act=agent\u003C\u002Ftext>\u003Cpath d=\"M270 354 H622\" class=\"d-line\" \u002F>\u003Cpath d=\"M630 354 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Ctext x=\"450\" y=\"346\" text-anchor=\"middle\" class=\"d-text\">5 API call with the token\u003C\u002Ftext>\u003Crect x=\"520\" y=\"378\" width=\"190\" height=\"52\" rx=\"10\" class=\"d-gold\" \u002F>\u003Ctext x=\"615\" y=\"399\" text-anchor=\"middle\" class=\"d-small\">6 checks aud and scope\u003C\u002Ftext>\u003Ctext x=\"615\" y=\"417\" text-anchor=\"middle\" class=\"d-small\">logs user + agent\u003C\u002Ftext>",[261],"The API never sees the user's original token or the agent's long-lived credential, only a token minted for it.",{"type":143,"content":263},[264,265,268],"In steps 3 and 4 the identity provider is the policy point. It can refuse the exchange if the agent is blocked, the user has not consented or the requested scope is wider than allowed, and it can set a short lifetime. Because the new token has the API as its audience, a leaked copy is useless anywhere else. The ",{"tag":147,"children":266},[267],"act"," claim then travels to the resource server and into its logs, which is what makes \"the user did it\" and \"the agent did it for the user\" distinguishable later.",{"type":270,"variant":271,"title":272,"body":273},"callout","warn","Never pass the incoming token through",[274],[275,276,280],"If your agent calls an MCP server or an internal tool server, that server must only accept tokens issued for it and must not forward them downstream. The MCP security guidance calls token passthrough an anti-pattern and states that servers MUST NOT accept tokens that were not explicitly issued for them, because it breaks audience boundaries, bypasses rate limits and monitoring, and corrupts the audit trail. Exchange, do not forward. See also my ",{"tag":163,"to":277,"children":278},"\u002Fblog\u002Fmcp-server-security-checklist",[279],"MCP server security checklist",".",{"type":143,"content":282},[283],"Know the limits of the standard. RFC 8693 lets act claims nest to describe a chain of actors, but a consumer should only trust the top-level claims, and earlier actors are informational. Nothing in it forces permissions to shrink at each hop. WorkOS describes this as the multi-hop delegation problem and points to drafts on attenuating tokens and verifiable actor chains. Until those mature, keep chains short, narrow scope at every exchange, and add a policy check at tool invocation rather than relying on token validity alone.",{"type":143,"content":285},[286],"The enterprise variant of the same idea is Cross App Access. The user signs in to the company identity provider, which issues an Identity Assertion JWT Authorization Grant (ID-JAG); the client then exchanges it at the target service's authorization server for an access token. Admins enable a server once and users inherit it within the groups and roles they already have, with no per-server consent screens. The MCP project adopted it as the Enterprise-Managed Authorization extension on 18 June 2026.",{"type":154,"level":155,"id":124,"text":125},{"type":143,"content":289},[290],"An agent has two kinds of secrets: the credential it uses to prove who it is, and the third-party tokens it holds to act in other systems. Both are attractive targets because agents run code, read untrusted input and write logs. I would apply these rules.",{"type":292,"ordered":293,"items":294},"list",false,[295,300,305,310,315],[296,299],{"tag":195,"children":297},[298],"No static keys for production agents."," Entra's guidance is to prefer federated identity credentials (managed identities) or certificates over client secrets, to use secrets only for development, and to rotate certificates at least annually. Okta's Agent SSO likewise issues short-lived, identity-governed tokens instead of static API keys.",[301,304],{"tag":195,"children":302},[303],"Keep credentials out of the model's reach."," The agent process asks a sidecar, vault or broker for a token; the model never sees the secret in its prompt, tool arguments or tool results. Entra offers an Auth SDK sidecar for exactly this pattern, including for agents on AWS Bedrock or n8n.",[306,309],{"tag":195,"children":307},[308],"One credential per blueprint and environment."," Do not share a credential between unrelated agents, and separate dev, test and prod so a compromise stays local.",[311,314],{"tag":195,"children":312},[313],"Hold third-party tokens in a token vault",", per customer or tenant, and release them to the agent only through a scoped, audited call. Auth0 announced a Token Vault with Organizations support for multi-tenant SaaS.",[316,319,320,280],{"tag":195,"children":317},[318],"Scrub logs and traces."," Tokens leak through debug logs, error messages and observability pipelines; redact authorization headers before they leave the process. For the runtime side, see the ",{"tag":163,"to":321,"children":322},"\u002Fblog\u002Fsandboxing-coding-agents-ci-checklist",[323],"sandboxing checklist",{"type":143,"content":325},[326],"Short lifetimes matter more than clever storage. A token that expires quickly turns a leak from an incident into a footnote, and the scope-minimisation advice in the MCP guidance applies directly: start with low-risk read scopes and step up only when a privileged operation is attempted, instead of publishing every scope up front.",{"type":154,"level":155,"id":127,"text":128},{"type":143,"content":329},[330],"Verified against vendor documentation and announcements, this is the current picture. It is a fast-moving area, so check dates and licences before you plan around any row.",{"type":181,"head":332,"rows":339},[333,335,337],[334],"Offering",[336],"What it gives you",[338],"Status and caveats",[340,348,357,366,375,384],[341,344,346],[342],{"tag":195,"children":343},[19],[345],"Agent identity blueprints (templates) and agent identities, optional paired agent user accounts, owners and sponsors, OAuth with autonomous and on-behalf-of flows, sign-in and audit logs; works with non-Microsoft agents via a sidecar or workload identity federation",[347],"Generally available, available to all Entra customers. Extending Entra security features (such as Conditional Access) to agents requires Agent 365",[349,353,355],[350],{"tag":195,"children":351},[352],"Microsoft Agent 365",[354],"Central agent registry and map, lifecycle and access governance with Entra and Purview, Defender protections",[356],"GA on 1 May 2026 for the Commercial segment, licensed per user; included in Microsoft 365 E7, add-on for E5 and others",[358,362,364],[359],{"tag":195,"children":360},[361],"Okta Agent SSO and Okta for AI Agents",[363],"Agents that support Cross App Access are registered in Universal Directory and get short-lived tokens; the separate product adds discovery, lifecycle, certification reviews, approval workflows and deactivation, also for agents without Cross App Access",[365],"Agent SSO GA on 24 August 2026, included in core SSO at no extra cost; Okta for AI Agents is a separate subscription",[367,371,373],[368],{"tag":195,"children":369},[370],"Auth0 for AI Agents",[372],"Auth for MCP, On-Behalf-Of Token Exchange, Token Vault, fine-grained authorization",[374],"Auth for MCP and OBO token exchange were announced as GA in May 2026. An \"Agent as Principal\" feature was announced as a developer preview for June; I could not verify its current state",[376,380,382],[377],{"tag":195,"children":378},[379],"MCP Enterprise-Managed Authorization",[381],"IdP-controlled authorization for MCP servers using ID-JAG; clients such as Claude and VS Code, servers such as Asana, Atlassian, Figma, Linear and Supabase",[383],"Official MCP extension since June 2026; needs support on both the client and the server side",[385,389,391],[386],{"tag":195,"children":387},[388],"OpenAI specialist dots",[390],"Dots that can be provisioned with specific identities, credentials and tools through existing systems; OpenAI says it is working with Microsoft on Agent 365 controls",[392],"Announced on 29 September 2026 as enterprise pilots; details beyond the announcement were not public when I checked",{"type":143,"content":394},[395,396,400],"Two observations. First, the protocols converged faster than I expected: Entra, Okta and the MCP project all describe the same shape, which is a directory identity for the agent, token issuance at the identity provider and short-lived scoped tokens at the resource. Second, the commercial boundary is real. Microsoft separates the identity platform from the governance features, and Okta separates single sign-on from lifecycle governance. Budget for the governance layer, because identity without review and lifecycle is just a different place to forget agents. I covered why ",{"tag":163,"to":397,"children":398},"\u002Fblog\u002Fopenai-dots-always-on-agents-impact",[399],"OpenAI's dots"," turn agent governance into an identity question in a separate article.",{"type":154,"level":155,"id":130,"text":131},{"type":154,"level":403,"text":404},3,"Make every action attributable",{"type":143,"content":406},[407],"Logging is only useful if the log can tell agents from people and name the human behind a delegated action. Entra tags audit events with an agent type (blueprint, agent identity or agent user account) and the blueprint ID, and adds an agent sign-in event type. Because agents can sign in with delegated or app-only permissions, their sign-ins appear across all four sign-in log types, so filter on the agent type rather than on one log.",{"type":292,"ordered":293,"items":409},[410,412,414,420],[411],"Log both subject and actor for every delegated call, and the agent identity alone for autonomous ones.",[413],"Alert on credential changes, new permission grants and sign-ins from unfamiliar locations, and on changes outside your deployment pipeline.",[415,416,280],"Correlate the agent identity with the run ID in your traces, so you can replay what one identity did across a whole ",{"tag":163,"to":417,"children":418},"\u002Fblog\u002Fagent-loop-explained",[419],"agent loop",[421],"Keep retention long enough for your compliance regime; agent logs are high volume, so export them to an archive.",{"type":154,"level":403,"text":423},"Offboard agents like employees",{"type":143,"content":425},[426],"Agents are created easily and forgotten just as easily. Entra's model shows what a good lifecycle looks like. Every blueprint and agent identity needs a sponsor, the person or group accountable for its purpose, plus a technical owner. Lifecycle workflows can notify co-sponsors and transfer sponsorship automatically when a sponsor changes role or leaves, to prevent orphaned agents. Microsoft recommends that sponsors attest every 6 to 12 months that an agent is still needed, and that you review quarterly for missing sponsors and agents with no recent activity.",{"type":143,"content":428},[429,430,433,434,437],"For shutting an agent down, separate ",{"tag":147,"children":431},[432],"disable"," from ",{"tag":147,"children":435},[436],"delete",". Disabling a blueprint stops all its agent identities from authenticating at once, which makes it a kill switch, and leaves the evidence in place. Deleting soft-deletes the object and, asynchronously, its child identities; the cleanup can lag by hours or days, and objects can be restored for 30 days. Do not rely on deletion for an emergency; disable first. Then do the part no directory does for you: revoke tokens the agent holds in third-party systems, remove its secrets and its entries in vaults, and close its connections to external services.",{"type":154,"level":155,"id":133,"text":134},{"type":143,"content":440},[441],"Use this table in design reviews. Each control has a concrete test; if you cannot show evidence for a row, treat it as open.",{"type":181,"head":443,"rows":450},[444,446,448],[445],"Control",[447],"What good looks like",[449],"Evidence",[451,460,469,478,487,495,504,513,522,531],[452,456,458],[453],{"tag":195,"children":454},[455],"Unique identity",[457],"One identity per agent, no shared accounts, no personal tokens",[459],"Directory list of agents with owners",[461,465,467],[462],{"tag":195,"children":463},[464],"Sponsor and owner",[466],"A named accountable person or group, reassigned when they leave",[468],"Sponsor field, lifecycle workflow run",[470,474,476],[471],{"tag":195,"children":472},[473],"Access mode chosen",[475],"Delegated for work done for a person, autonomous for roles; never both in one token",[477],"Design note per agent",[479,483,485],[480],{"tag":195,"children":481},[482],"Token exchange",[484],"Audience-restricted tokens with actor recorded; no token passthrough",[486],"Token claims in a test trace",[488,491,493],[489],{"tag":195,"children":490},[10],[492],"Narrowest scopes, step-up for risky operations, effective rights capped by agent and user",[494],"Permission review, denied-scope test",[496,500,502],[497],{"tag":195,"children":498},[499],"Short lifetimes",[501],"Minutes-scale access tokens, no static production keys",[503],"Token configuration, key inventory",[505,509,511],[506],{"tag":195,"children":507},[508],"Secret handling",[510],"Managed or federated credentials, vault or sidecar, nothing in prompts or logs",[512],"Secret scan of prompts, traces and logs",[514,518,520],[515],{"tag":195,"children":516},[517],"Policy at the gate",[519],"Agent-specific conditional access, risk-based block, tool-level checks",[521],"Policy export, blocked-sign-in test",[523,527,529],[524],{"tag":195,"children":525},[526],"Audit trail",[528],"Agent type, blueprint, subject and actor in logs; alerts configured",[530],"Sample investigation walk-through",[532,536,538],[533],{"tag":195,"children":534},[535],"Review and offboarding",[537],"Sponsor attestation, orphan review, tested disable procedure and token revocation",[539],"Last review date, drill result",{"type":143,"content":541},[542],"Two rows deserve a drill rather than a document: the denied-scope test and the disable procedure. Ask an agent to do something outside its scope and confirm that it fails and that the failure is logged. Then pretend it is compromised and time how long it takes to cut off every credential it holds.",{"type":154,"level":155,"id":136,"text":137},{"type":143,"content":545},[546],"You do not need a platform purchase to start. In order:",{"type":292,"ordered":548,"items":549},true,[550,552,554,556,558],[551],"Inventory every agent and automation that calls your systems today, and mark which use a personal token or shared key.",[553],"Give each agent a unique identity and a sponsor, starting with the ones that touch customer data or money.",[555],"Decide delegated or autonomous per agent, and cut scopes to what the task needs; test that an out-of-scope call fails.",[557],"Move to token exchange and short-lived tokens at your identity provider; remove static keys from production and from prompts.",[559],"Write the disable-and-revoke runbook, rehearse it once, and schedule the quarterly orphan review.",{"type":143,"content":561},[562],"Agent identity is not glamorous, but it is the control that makes everything else enforceable: sandboxing limits what code can do, and identity limits what the agent may reach and whom you can hold accountable.",{"type":154,"level":155,"id":139,"text":140},{"type":292,"ordered":548,"items":565},[566,570,573,576,579,582,585,588,591,594,597,600,603,606],[567],{"tag":568,"href":37,"children":569},"a",[36],[571],{"tag":568,"href":40,"children":572},[39],[574],{"tag":568,"href":43,"children":575},[42],[577],{"tag":568,"href":46,"children":578},[45],[580],{"tag":568,"href":49,"children":581},[48],[583],{"tag":568,"href":52,"children":584},[51],[586],{"tag":568,"href":55,"children":587},[54],[589],{"tag":568,"href":58,"children":590},[57],[592],{"tag":568,"href":61,"children":593},[60],[595],{"tag":568,"href":64,"children":596},[63],[598],{"tag":568,"href":67,"children":599},[66],[601],{"tag":568,"href":70,"children":602},[69],[604],{"tag":568,"href":73,"children":605},[72],[607],{"tag":568,"href":76,"children":608},[75],[610,706,792,858],{"slug":611,"published":5,"minutes":6,"category":7,"tags":612,"keywords":618,"about":629,"sources":639,"cover":700,"og":701,"expertise":79,"locales":702,"lang":81,"title":703,"description":704,"coverAlt":705},"pii-redaction-llm-pipelines",[613,614,615,616,617],"PII redaction","GDPR","Microsoft Presidio","LLM security","Pseudonymisation",[619,620,621,622,623,624,625,626,627,628],"PII redaction LLM","how to remove PII before sending to LLM","Microsoft Presidio tutorial","PII detection German Hungarian","pseudonymisation vs anonymisation GDPR","reversible tokenization LLM prompts","redact PII in logs and traces","LLM data masking","PII guardrail LiteLLM","test PII detection recall",[630,633,636],{"name":631,"url":632},"Personal data","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FPersonal_data",{"name":634,"url":635},"General Data Protection Regulation","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FGeneral_Data_Protection_Regulation",{"name":637,"url":638},"Data anonymization","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FData_anonymization",[640,643,646,649,652,655,658,661,664,667,670,673,676,679,682,685,688,691,694,697],{"title":641,"url":642},"Microsoft Presidio: documentation (limitations, methods)","https:\u002F\u002Fpresidio.dataprivacystack.org\u002F",{"title":644,"url":645},"Presidio: supported entities and country-specific recognizers","https:\u002F\u002Fpresidio.dataprivacystack.org\u002Fsupported_entities\u002F",{"title":647,"url":648},"Presidio: supporting additional languages","https:\u002F\u002Fpresidio.dataprivacystack.org\u002Fanalyzer\u002Flanguages\u002F",{"title":650,"url":651},"Presidio: anonymizer operators","https:\u002F\u002Fpresidio.dataprivacystack.org\u002Fanonymizer\u002F",{"title":653,"url":654},"Google Cloud: infoTypes reference","https:\u002F\u002Fdocs.cloud.google.com\u002Fsensitive-data-protection\u002Fdocs\u002Finfotypes-reference",{"title":656,"url":657},"Google Cloud: pseudonymization in Sensitive Data Protection","https:\u002F\u002Fdocs.cloud.google.com\u002Fsensitive-data-protection\u002Fdocs\u002Fpseudonymization",{"title":659,"url":660},"Microsoft Learn: Azure Language PII detection language support","https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fai-services\u002Flanguage-service\u002Fpersonally-identifiable-information\u002Flanguage-support",{"title":662,"url":663},"AWS: Detecting PII entities with Amazon Comprehend","https:\u002F\u002Fdocs.aws.amazon.com\u002Fcomprehend\u002Flatest\u002Fdg\u002Fhow-pii.html",{"title":665,"url":666},"spaCy: models and languages","https:\u002F\u002Fspacy.io\u002Fusage\u002Fmodels",{"title":668,"url":669},"Hugging Face: novakat\u002Fnerkor-hubert (Hungarian NER)","https:\u002F\u002Fhuggingface.co\u002Fnovakat\u002Fnerkor-hubert",{"title":671,"url":672},"arXiv: An Evaluation Study of Hybrid Methods for Multilingual PII Detection","https:\u002F\u002Farxiv.org\u002Fabs\u002F2510.07551",{"title":674,"url":675},"LiteLLM: Presidio PII masking guardrail","https:\u002F\u002Fdocs.litellm.ai\u002Fdocs\u002Fproxy\u002Fguardrails\u002Fpii_masking_v2",{"title":677,"url":678},"Langfuse: masking","https:\u002F\u002Flangfuse.com\u002Fdocs\u002Fobservability\u002Ffeatures\u002Fmasking",{"title":680,"url":681},"GDPR Article 4: definitions (pseudonymisation, 4(5))","https:\u002F\u002Fgdpr-info.eu\u002Fart-4-gdpr\u002F",{"title":683,"url":684},"EDPB: Guidelines 01\u002F2025 on Pseudonymisation","https:\u002F\u002Fwww.edpb.europa.eu\u002Four-work-tools\u002Fdocuments\u002Fpublic-consultations\u002F2025\u002Fguidelines-012025-pseudonymisation_en",{"title":686,"url":687},"IAPP: EDPB publishes draft guidelines on pseudonymization","https:\u002F\u002Fiapp.org\u002Fnews\u002Fa\u002F-what-s-in-a-name-edpb-publishes-draft-guidelines-on-pseudonymization",{"title":689,"url":690},"Taylor Wessing: Analysis of the CJEU judgment in C-413\u002F23 P (EDPS v SRB)","https:\u002F\u002Fwww.taylorwessing.com\u002Fen\u002Finsights-and-events\u002Finsights\u002F2025\u002F09\u002Fanalysis-of-the-cjeu-judgment",{"title":692,"url":693},"Jones Day: CJEU clarifies scope of personal data in EDPS v SRB","https:\u002F\u002Fwww.jonesday.com\u002Fen\u002Finsights\u002F2025\u002F09\u002Fcjeu-clarifies-scope-of-personal-data-in-edps-v-srb-decision",{"title":695,"url":696},"IAPP: leaked Council Digital Omnibus compromise drops the revised personal data definition","https:\u002F\u002Fiapp.org\u002Fnews\u002Fa\u002Feu-member-states-leaked-digital-omnibus-compromise-proposal-eliminates-revised-gdpr-definition-of-personal-data",{"title":698,"url":699},"Law Health Tech: Pseudonymisation under the GDPR and the Digital Omnibus (May 2026)","https:\u002F\u002Flawhealthtech.com\u002F2026\u002F05\u002F04\u002Fpseudonymisation-under-the-gdpr-where-we-are-what-may-change-under-the-digital-omnibus-and-what-regulators-think\u002F","\u002Fimages\u002Fblog\u002Fpii-redaction-llm-pipelines\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fpii-redaction-llm-pipelines\u002Fog.jpg",[81,82,83],"PII redaction in LLM pipelines: where to redact, how, and what GDPR says","Where to redact PII in an LLM pipeline, reversible tokens vs masking, Presidio and cloud DLP, German and Hungarian gaps, GDPR on pseudonymised data, and tests.","Diagram: user input passes a redaction gate before the LLM, a token vault restores real values after the output check, and logs and traces only ever see redacted text.",{"slug":707,"published":5,"minutes":6,"category":7,"tags":708,"keywords":713,"about":724,"sources":734,"cover":786,"og":787,"expertise":79,"locales":788,"lang":81,"title":789,"description":790,"coverAlt":791},"eu-ai-act-gpai-high-risk-2026",[709,710,711,712],"EU AI Act","GPAI","High-risk AI","AI compliance",[714,715,716,717,718,719,720,721,722,723],"EU AI Act high-risk deadline","AI Act digital omnibus","AI Act GPAI obligations","AI Act provider vs deployer","EU AI Act 2 December 2027","GPAI code of practice","AI literacy Article 4","AI Act compliance checklist","AI Act OpenAI API provider deployer","AI Act mid-size company",[725,728,731],{"name":726,"url":727},"Artificial Intelligence Act","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FArtificial_Intelligence_Act",{"name":729,"url":730},"General-purpose artificial intelligence","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FFoundation_model",{"name":732,"url":733},"European Commission","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FEuropean_Commission",[735,738,741,744,747,750,753,756,759,762,765,768,771,774,777,780,783],{"title":736,"url":737},"Regulation (EU) 2024\u002F1689 (AI Act), EUR-Lex","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2024\u002F1689\u002Foj",{"title":739,"url":740},"Regulation (EU) 2026\u002F1744 (Digital Omnibus on AI), EUR-Lex","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2026\u002F1744\u002Foj",{"title":742,"url":743},"AI Act Explorer: Digital Omnibus on AI, full amending text","https:\u002F\u002Fartificialintelligenceact.eu\u002Fai-act-explorer\u002Fdigital-omnibus\u002F",{"title":745,"url":746},"European Commission: AI Act regulatory framework and timeline","https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fregulatory-framework-ai",{"title":748,"url":749},"European Commission: Guidelines for providers of general-purpose AI models","https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fguidelines-gpai-providers",{"title":751,"url":752},"European Commission: Q&A on the guidelines for GPAI providers","https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Ffaqs\u002Fguidelines-obligations-general-purpose-ai-providers",{"title":754,"url":755},"European Commission: The General-Purpose AI Code of Practice","https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fcontents-code-gpai",{"title":757,"url":758},"European Commission: AI literacy Questions and Answers","https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Ffaqs\u002Fai-literacy-questions-answers",{"title":760,"url":761},"AI Act Article 25: Responsibilities along the AI value chain","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F25\u002F",{"title":763,"url":764},"AI Act Article 26: Obligations of deployers of high-risk AI systems","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F26\u002F",{"title":766,"url":767},"AI Act Article 27: Fundamental rights impact assessment","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F27\u002F",{"title":769,"url":770},"AI Act Article 53: Obligations for providers of general-purpose AI models","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F53\u002F",{"title":772,"url":773},"AI Act Article 99: Penalties","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F99\u002F",{"title":775,"url":776},"AI Act Article 101: Fines for providers of general-purpose AI models","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F101\u002F",{"title":778,"url":779},"Gibson Dunn: EU AI Act Omnibus Agreement, postponed high-risk deadlines (27 May 2026)","https:\u002F\u002Fwww.gibsondunn.com\u002Feu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes\u002F",{"title":781,"url":782},"Orrick: EU AI Act Update, Digital Omnibus finalizes 8 compliance changes (29 July 2026)","https:\u002F\u002Fwww.orrick.com\u002Fen\u002FInsights\u002F2026\u002F07\u002FEU-AI-Act-Update-Digital-Omnibus-Finalizes-8-Compliance-Changes",{"title":784,"url":785},"K&L Gates: EU Digital Omnibus on AI enters into force (31 July 2026)","https:\u002F\u002Fwww.klgates.com\u002FEU-Digital-Omnibus-on-AI-Enters-Into-Force-7-31-2026","\u002Fimages\u002Fblog\u002Feu-ai-act-gpai-high-risk-2026\u002Fcover.webp","\u002Fimages\u002Fblog\u002Feu-ai-act-gpai-high-risk-2026\u002Fog.jpg",[81,82,83],"EU AI Act beyond Article 50: GPAI, high-risk dates and what to do now","The AI Act after the Digital Omnibus: GPAI duties, high-risk dates (2 Dec 2027 and 2 Aug 2028), provider vs deployer on OpenAI and Anthropic APIs, AI literacy.","Diagram: the AI Act timeline from February 2025 to August 2028, fanning out into GPAI duties, high-risk systems, provider and deployer roles and AI literacy.",{"slug":793,"published":794,"minutes":795,"category":7,"tags":796,"keywords":802,"about":812,"sources":821,"cover":852,"og":853,"expertise":79,"locales":854,"lang":81,"title":855,"description":856,"coverAlt":857},"prompt-injection-lethal-trifecta-patterns","2026-09-27",9,[797,798,799,800,801],"Prompt injection","AI agent security","Lethal trifecta","Design patterns","Red teaming",[803,804,798,805,806,807,808,809,810,811],"prompt injection","lethal trifecta","indirect prompt injection","dual LLM pattern","prompt injection design patterns","how to prevent prompt injection in AI agents","agents rule of two","prompt injection egress allowlist","OWASP agentic top 10 goal hijack",[813,815,818],{"name":797,"url":814},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FPrompt_injection",{"name":816,"url":817},"Large language model","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FLarge_language_model",{"name":819,"url":820},"OWASP","https:\u002F\u002Fowasp.org\u002F",[822,825,828,831,834,837,840,843,846,849],{"title":823,"url":824},"Simon Willison: The lethal trifecta for AI agents","https:\u002F\u002Fsimonwillison.net\u002F2025\u002FJun\u002F16\u002Fthe-lethal-trifecta\u002F",{"title":826,"url":827},"Design Patterns for Securing LLM Agents against Prompt Injections","https:\u002F\u002Farxiv.org\u002Fabs\u002F2506.08837",{"title":829,"url":830},"Simon Willison: Design patterns for securing LLM agents (summary)","https:\u002F\u002Fsimonwillison.net\u002F2025\u002FJun\u002F13\u002Fprompt-injection-design-patterns\u002F",{"title":832,"url":833},"Simon Willison: The Dual LLM pattern","https:\u002F\u002Fsimonwillison.net\u002F2023\u002FApr\u002F25\u002Fdual-llm-pattern\u002F",{"title":835,"url":836},"Defeating Prompt Injections by Design (CaMeL)","https:\u002F\u002Farxiv.org\u002Fabs\u002F2503.18813",{"title":838,"url":839},"The Attacker Moves Second","https:\u002F\u002Farxiv.org\u002Fabs\u002F2510.09023",{"title":841,"url":842},"Meta: Agents Rule of Two","https:\u002F\u002Fai.meta.com\u002Fblog\u002Fpractical-ai-agent-security\u002F",{"title":844,"url":845},"Anthropic: How we contain Claude","https:\u002F\u002Fwww.anthropic.com\u002Fengineering\u002Fhow-we-contain-claude",{"title":847,"url":848},"Claude Code documentation: Sandboxing","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fsandboxing",{"title":850,"url":851},"promptfoo: OWASP Top 10 for Agentic Applications","https:\u002F\u002Fwww.promptfoo.dev\u002Fdocs\u002Fred-team\u002Fowasp-agentic-ai\u002F","\u002Fimages\u002Fblog\u002Fprompt-injection-lethal-trifecta-patterns\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fprompt-injection-lethal-trifecta-patterns\u002Fog.jpg",[81,82,83],"Prompt injection defense: the lethal trifecta and six design patterns","Why prompt injection can't be filtered away: the lethal trifecta, six design patterns that contain it, egress rules and a red-team checklist for AI agents.","Shield diagram with rings for egress control, data scope and pattern choice around a core labelled trifecta, broken",{"slug":859,"published":794,"minutes":860,"category":7,"tags":861,"keywords":867,"about":876,"sources":887,"cover":908,"og":909,"expertise":79,"locales":910,"lang":81,"title":911,"description":912,"coverAlt":913},"mcp-server-security-checklist",10,[862,863,864,865,866],"MCP security","Tool poisoning","MCP OAuth","Supply chain","Audit logs",[862,868,869,870,864,871,872,873,874,875],"MCP server security","MCP tool poisoning","MCP rug pull","MCP vulnerabilities","how to secure an MCP server","MCP authorization RFC 9207","NSA MCP guidance","MCP audit logging",[877,880,882,885],{"name":878,"url":879},"Model Context Protocol","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FModel_Context_Protocol",{"name":881,"url":33},"OAuth 2.0",{"name":883,"url":884},"OpenTelemetry","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FOpenTelemetry",{"name":819,"url":886},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FOWASP",[888,891,894,897,900,903,906],{"title":889,"url":890},"Invariant Labs: MCP Security Notification – Tool Poisoning Attacks (1 April 2025)","https:\u002F\u002Finvariantlabs.ai\u002Fblog\u002Fmcp-security-notification-tool-poisoning-attacks",{"title":892,"url":893},"OWASP: Top 10 for Agentic Applications for 2026 (9 December 2025)","https:\u002F\u002Fgenai.owasp.org\u002Fresource\u002Fowasp-top-10-for-agentic-applications-for-2026\u002F",{"title":895,"url":896},"MCP specification 2026-07-28: changelog (SEP-2468, SEP-2352, SEP-414)","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fmodelcontextprotocol\u002Fblob\u002Fmain\u002Fdocs\u002Fspecification\u002F2026-07-28\u002Fchangelog.mdx",{"title":898,"url":899},"RFC 9207: OAuth 2.0 Authorization Server Issuer Identification","https:\u002F\u002Fwww.rfc-editor.org\u002Frfc\u002Frfc9207",{"title":901,"url":902},"NSA: Model Context Protocol (MCP) – Security Design Considerations for AI-Driven Automation (May 2026)","https:\u002F\u002Fmedia.defense.gov\u002F2026\u002FJun\u002F02\u002F2003943289\u002F-1\u002F-1\u002F0\u002FCSI_MCP_SECURITY.PDF",{"title":904,"url":905},"Reed Smith: NSA publishes security guidance on designing AI systems with MCP (4 June 2026)","https:\u002F\u002Fwww.reedsmith.com\u002Four-insights\u002Fblogs\u002Fviewpoints\u002F102mvg9\u002Fnsa-publishes-security-guidance-on-designing-ai-systems-with-model-context-protoc\u002F",{"title":907,"url":845},"Anthropic: How we contain Claude across products (25 May 2026)","\u002Fimages\u002Fblog\u002Fmcp-server-security-checklist\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fmcp-server-security-checklist\u002Fog.jpg",[81,82,83],"MCP security checklist: tool poisoning, rug pulls and OAuth","MCP security checklist: the threat model, tool poisoning, rug pulls, RFC 9207 issuer checks, per-issuer credentials, scoped tokens and audit logs.","Concentric rings from outside in: NSA guidance, OWASP agentic risks, issuer-bound credentials, pinned tool definitions and a scoped core token.",1791009037064]