Keycard puts users, developers and companies in control of AI agents with real-time, adaptive permissions and complete transparency.

Keycard is going to @aiDotEngineer NYC October 12-14! Here's where to find us: Come see us at our booth (number 15) anytime. Swing by to enter our raffle, see a multi-agent demo using A2A, and chat with our team about agent identity and runtime authorization. Monday Oct 12, 3:30pm-4:30pm: @KimMaida, our Head of DevRel, leads a workshop on secure, durable agents with @temporalio. Tuesday Oct 13, 11:30am-12:20pm: Intent Based Auth panel, featuring @ianlivingstone, CEO of Keycard, Michael Davis, Global Chief Security Architect at @jpmorgan, and @DickHardt, founder of AAuth. @vtahowe moderates. Tuesday Oct 13, 2:30pm-2:50pm: Kamil Potrec Product Lead, runs an expo session on agent auth across gateways and SDKs. Tuesday Oct 13, 5:30-8:30pm: Keycard is hosting Agent Baseline Demo Night with @braintrust, Dick Hardt, and others to explore a reference architecture for building, deploying, and operating production agents. RSVP: luma.com/keycard-rg1c We're excited to meet you and hear how you're handling auth for agents.
1
2
7
1,628
Really enjoyed talking with @MollySOShea about why we’re entering the systems engineering phase of agents. The raw intelligence is here, but making agents the default in software means figuring out how to make them cheap, reliable, and safe without nuking their ability to reason and solve problems dynamically. That is why we’re building auth for agents at @KeycardAI.
Ian Livingstone (@ianlivingstone) CEO of @KeycardAI says the biggest thing standing between today’s AI agents & true autonomy actually isn't intelligence.. “We have apparently AGI, but the real thing that stops us from having autonomous agents that actually work, like a self-driving car, is identity & access.” “Our systems weren't built for agents that are non-deterministic actors.”
4
28
1,823
Our CEO @ianlivingstone gave some pretty hot takes at @browserbase's Navigate Conference Ian says AGI might be here but identity and access is what's preventing agents from being truly autonomous
Ian Livingstone (@ianlivingstone) CEO of @KeycardAI says the biggest thing standing between today’s AI agents & true autonomy actually isn't intelligence.. “We have apparently AGI, but the real thing that stops us from having autonomous agents that actually work, like a self-driving car, is identity & access.” “Our systems weren't built for agents that are non-deterministic actors.”
1
9
824
We had a great time learning about the infra behind reliable agents with @MongoDB and @temporalio! We showed how Keycard replaces static secrets with per-agent identities and task-scoped, short-lived credentials, so an agent can only do the thing it was asked to do.
1
7
624
Join us tomorrow night in SF with @temporalio and @MongoDB to learn how to build a durable agent with memory and auth! You’ll learn how to build agent workflows that stay current, recover cleanly, and scale beyond a fragile demo. RSVP: luma.com/hu0e1aks
5
636
I've always found Satya a salient thinker, and once again he nails it here. As AI gets more capable, we need to keep pushing to democratize access, increase choice, and build the controls that let us adopt it safely at any scale. We started @KeycardAI because we believe in a future where trusted, autonomous agents are everywhere, and everyone can access them and build them themselves. The problem is that agents break the security models we've relied on for decades because they were built for humans, not millions of non-deterministic machines acting on our behalf. Democratizing that future requires authn/z built for this new world: delegated, task-scoped and revocable access, identity carried through every tool call, a tamper-resistant record of who did what and on whose behalf, and intent-based authorization that can reason about what an agent is trying to do and apply deterministic boundaries dynamically at machine scale. That's the infrastructure we're building at @KeycardAI.
Any pursuit of superintelligence has to be grounded in the core principle that if the AI we build is not helping humanity and under human control, it's not worth pursuing. We also need to accelerate and spread the benefits of AI, such that they are diffused broadly across countries, communities, and companies. This requires a frontier ecosystem in which both closed and open-source models can thrive. And for firms, it’s imperative that they retain full control over their unique and tacit knowledge. Every organization should be able to build its own continuous learning loop/hill climbing machine, without becoming dependent on any one model provider, and have the ability to embed its own knowledge into models and weights they control. So, in this context, we welcome the research, focus, and deliberate pacing needed to get alignment right as the design goal. We also welcome ideas like "embedded evaluators" and the broader efforts to develop the mechanisms to make this more than just talk. The key is that this cannot be controlled by a handful of entities, but must have broad representation across the ecosystem, countries, and fields, including academia. This is the approach we are taking: broad access and choice at every layer of the AI stack; enterprise control of learning loops and models; and the “Code of Conduct” that underlies our own first party MAI models that we’ll publish tomorrow for public consultation.
3
13
1,413
Keycard retweeted
I'm stoked for next week's Builder After Hours: Durable Agents with @MongoDB , @temporalio, and @KeycardAI (9/15, SF). Instead of the usual lineup of separate talks, @MelGoesTech is bringing a fresh take: co-presenting one shared architecture, then diving into each component. RSVP here: luma.com/hu0e1aks
3
7
542
It's been a great day at @browserbase's Navigate conference chatting agent identity, agentic commerce, and how to ship agents into production.
18
836
Auth for agents is the biggest remaining gap between cool toy and production grade autonomy. The permission problem is perpetuated by an age of human driven computing where static roles and broad scopes were sufficient - it doesn’t work for agents - permissions have to be task scope and contextual to the progression of the task. We’re solving this @KeycardAI
i used instinct pretty aggressively on day one. it felt magical. and then it turned scary. giving it access to my email was already scary. then it started establishing sessions across apps and websites i use, on its own. watching an ai get that much access to act as me made me appreciate granular permissions on APIs a lot more. think about it. would you give even a clone of yourself unrestricted access to tools that could cost you money & happiness? i'd feel more comfortable with a dedicated app where sessions stay on device. but even then, i'd want it to ask before logging into anything on my behalf. and honestly, whatsapp/imessage doesn't feel like the right interface for this. i want to see where it's working, what it's doing in real time, and be able to step in before it does something i wouldn't have. that's why i prefer codex for example. the form factor is built around you trying to code, lives in projects and connects to your IDE easily. i'm not completely in the dark about what it's doing. ai agents don't have to live inside the apps or interfaces we already use. familiar interfaces help with adoption. they don't solve trust or control. if something can act as me, i need more than a chat bubble telling me it's done.
7
6
35
8,391
During the Hugging Face incident agents tampered with their transcripts to cover up their actions. Therefore, the audit log must live outside of the agent's control. In Keycard, every action in a delegation chain is captured as real-time telemetry.
1
9
2,213
Teams with Keycard won't need to waste time deciphering or patching together what happened using manipulated agent transcripts. They'll have data they can trust and access to it quickly in Keycard.
1
77
The ability to immediately revoke an agent's access at machine speed is something we believe all teams must have. And it's available in Keycard today docs.keycard.ai/api/resource…
Agents Are Like Teenagers: Governing at Machine Speed with Mastercard's Alissa Abdullah, PhD ("Dr. Jay") and Arjun Ramakrishnan "I think we're moving from guardrails to this new buzzword called a kill switch. Everybody wants to build a kill switch. But defining the technical requirements of how do you implement a kill switch is really tricky." @dralissajay, Deputy Chief Security Officer at Mastercard, and Arjun Ramakrishnan, Senior Principal Cybersecurity Architect at @Mastercard, sat down with us live from @BlackHatEvents. Dr. Jay tells us governing agents is like governing teenagers: you set boundaries, monitor for drift, and revoke their car keys or access if the boundary is exceeded. We get into: > Why real time governance means auditing every agent action > Why teams must have the ability to instantly revoke agent access > Why just in time access means something completely different when agents run at machine speed >Why an agent may need more access than the human it works for > Why not one but many kill switches are needed TIMESTAMPS (01:40) Security for AI, from AI, and with AI: the three layers behind trust at scale (03:00) The autonomous SOC, and why the regulators aren't there yet (03:40) Defenders have to be right every time. Adversaries have to be right once. (05:00) The Hugging Face sandbox escape, read from the adversary's side (07:00) Everybody wants a kill switch. How do you secure your own kill switch from attackers? (08:20) Human in the loop, on the loop, out of the loop, and the shift from prevention to resilience (11:20) Agents are teenagers: the car keys, the Tesla app, and the governor (13:50) Governance is still a meeting, and that does not work in an AI era (15:00) Using AI to govern AI (16:00) You cannot provision access to an agent the way you provision it to a person (16:40) Every tool call, every action needs to be authorized (18:40) Good intent, wrong action: agents have a mission, not a moral compass (20:30) The classified systems model: an agent with more access than its owner (21:40) One intercepted agent out of tens of thousands you already trust (23:20) An agent breaching from inside out and then outside in (28:40) Vulnerability free releases, and why defenders need the raw log data
1
4
994
With Keycard, the key difference is secrets aren’t available by default anymore. They’re earned on every run. The question moved from “is this secret configured in the repo?” to “does this workflow, with its verified identity, have a policy that permits this resource right now?”
1
4
1,133
These are the type of patterns we have to get right in order to enable secure software factories. For guidance on how to build production ready agents, see agentbaseline.org/
24