Keycard puts users, developers and companies in control of AI agents with real-time, adaptive permissions and complete transparency.

Keycard is going to @aiDotEngineer NYC October 12-14! Here's where to find us: Come see us at our booth (number 15) anytime. Swing by to enter our raffle, see a multi-agent demo using A2A, and chat with our team about agent identity and runtime authorization. Monday Oct 12, 3:30pm-4:30pm: @KimMaida, our Head of DevRel, leads a workshop on secure, durable agents with @temporalio. Tuesday Oct 13, 11:30am-12:20pm: Intent Based Auth panel, featuring @ianlivingstone, CEO of Keycard, Michael Davis, Global Chief Security Architect at @jpmorgan, and @DickHardt, founder of AAuth. @vtahowe moderates. Tuesday Oct 13, 2:30pm-2:50pm: Kamil Potrec Product Lead, runs an expo session on agent auth across gateways and SDKs. Tuesday Oct 13, 5:30-8:30pm: Keycard is hosting Agent Baseline Demo Night with @braintrust, Dick Hardt, and others to explore a reference architecture for building, deploying, and operating production agents. RSVP: luma.com/keycard-rg1c We're excited to meet you and hear how you're handling auth for agents.
1
2
7
1,695
We had a great time learning about the infra behind reliable agents with @MongoDB and @temporalio! We showed how Keycard replaces static secrets with per-agent identities and task-scoped, short-lived credentials, so an agent can only do the thing it was asked to do.
1
7
624
It's been a great day at @browserbase's Navigate conference chatting agent identity, agentic commerce, and how to ship agents into production.
18
836
During the Hugging Face incident agents tampered with their transcripts to cover up their actions. Therefore, the audit log must live outside of the agent's control. In Keycard, every action in a delegation chain is captured as real-time telemetry.
1
9
2,213
The ability to immediately revoke an agent's access at machine speed is something we believe all teams must have. And it's available in Keycard today docs.keycard.ai/api/resource…
Agents Are Like Teenagers: Governing at Machine Speed with Mastercard's Alissa Abdullah, PhD ("Dr. Jay") and Arjun Ramakrishnan "I think we're moving from guardrails to this new buzzword called a kill switch. Everybody wants to build a kill switch. But defining the technical requirements of how do you implement a kill switch is really tricky." @dralissajay, Deputy Chief Security Officer at Mastercard, and Arjun Ramakrishnan, Senior Principal Cybersecurity Architect at @Mastercard, sat down with us live from @BlackHatEvents. Dr. Jay tells us governing agents is like governing teenagers: you set boundaries, monitor for drift, and revoke their car keys or access if the boundary is exceeded. We get into: > Why real time governance means auditing every agent action > Why teams must have the ability to instantly revoke agent access > Why just in time access means something completely different when agents run at machine speed >Why an agent may need more access than the human it works for > Why not one but many kill switches are needed TIMESTAMPS (01:40) Security for AI, from AI, and with AI: the three layers behind trust at scale (03:00) The autonomous SOC, and why the regulators aren't there yet (03:40) Defenders have to be right every time. Adversaries have to be right once. (05:00) The Hugging Face sandbox escape, read from the adversary's side (07:00) Everybody wants a kill switch. How do you secure your own kill switch from attackers? (08:20) Human in the loop, on the loop, out of the loop, and the shift from prevention to resilience (11:20) Agents are teenagers: the car keys, the Tesla app, and the governor (13:50) Governance is still a meeting, and that does not work in an AI era (15:00) Using AI to govern AI (16:00) You cannot provision access to an agent the way you provision it to a person (16:40) Every tool call, every action needs to be authorized (18:40) Good intent, wrong action: agents have a mission, not a moral compass (20:30) The classified systems model: an agent with more access than its owner (21:40) One intercepted agent out of tens of thousands you already trust (23:20) An agent breaching from inside out and then outside in (28:40) Vulnerability free releases, and why defenders need the raw log data
1
4
994
With Keycard, the key difference is secrets aren’t available by default anymore. They’re earned on every run. The question moved from “is this secret configured in the repo?” to “does this workflow, with its verified identity, have a policy that permits this resource right now?”
1
4
1,133
All of the technology needed to create a software factory is here today but the security model is missing. Agent Baseline, a reference architecture for production agents, helps you answer three key questions in order to create that security model. agentbaseline.org/
A Reference Architecture for Securing Software Factories, with Aaron Stanley and Ahmad Nassri "We're now at the point where this has to change, and the idea that an agent has a human's identity is not going to work anymore." Aaron Stanley, former CISO at dbt Labs, and @AhmadNassri, CTO of @SocketSecurity, sat down with us at Black Hat to draft the first version of a security reference architecture for software factories. Today, model vision has improved, context windows have gotten larger, and tool ecosystems are richer. The technology to make software factories real is here but the security model is missing. In this episode we envision that model together. We get into: > The pernicious problem: agents that look compliant while working against the rules you set > Why the enforcement boundary has to sit outside the agent loop, not inside it > Why a factory needs purposeful authentication and authorization of its own > Why one poisoned dependency is an incident in every work tree at machine speed > What actually belongs in the architecture: sandboxing, identity, supply chain, verification, your ways of working i.e. don't outsource the thinking! TIMESTAMPS (00:00) The inflection point for software factories, and the missing security model (01:20) A self-propagating worm moving through the npm registry during Black Hat week (02:50) The pernicious problem: compliant on paper, working against the rules in practice (03:30) The Andon cord, and whether the agent will pull it itself (05:00) One mono agent or a mixture of experts, and multiple cords for multiple stations (08:10) The components of a secure coding agent stack (09:20) The factory cannot have a human's identity (10:20) Contextual access: read in one scenario, never write in another (13:00) Git has no cryptographic dual identity, so who gets paged at 3 AM? (14:00) Context, tools, MCP servers, and skills are all supply chain (16:00) A firewall that omits vulnerable packages so the agent never learns they exist (18:10) You cannot trust the agents to police themselves (19:40) Escape hatches, paths of least resistance, and approval fatigue (21:50) The CTO's job becomes spec and build the factory, not the code (24:30) The housekeeper should not get a hot dog vending machine (28:40) npm install vs npm ci, and agents trained on a decade of blog posts (34:30) First steps: authenticated design and verified ways of working
1
6
823
AAuth Night is coming back to SF October 15th! During AAuth Night @aiDotEngineer our CTO @jaredhanson showed how intent-based authorization (AAuth missions) can be used as a way to reduce consent fatigue and defer credential issuance until after an agent has discovered tools. Jared made it clear that AAuth makes agents more secure while providing an even better end user experience. We can't wait to see what he demos next on Oct 15th! RSVP to join us and be part of the future of agent auth: luma.com/insecure-rmm0
1
1
4
1,012
The agent runs without a .env but still has access to every MCP, API, and tool it needs. Every tool call receives a highly ephemeral token scoped to the task at hand. Every credential grant is audited and if needed, grants can be revoked to instantly cut off the agent's access.
1
2
82
Watch the full talk
63
During @aiDotEngineer World's Fair our Head of DevRel @KimMaida walked through 3 common agent access problems and their solutions > Agents dropping a db with an overprivileged credential > Human consent fatigue > Credential use without attribution All easily fixed with Keycard
1
8
822
Recent agent escapes make it clear that we must be able to respond at machine speed. Our CEO @ianlivingstone explains that security teams today must be able to react immediately.
6
1
9
1,812
Read Agent Baseline, a new vendor-neutral reference architecture for building and deploying secure agents. It's open for public comment until September 30 agentbaseline.org/
1
1
87
We had a great time @BlackHatEvents meeting all of you! The theme is clear between all the meetings, panels, and podcasts: We can't trust agents with static creds and the ability to immediately revoke an agent's access or kill its ability to perform an action is fundamental.
1
2
9
732
Agent Baseline is live. A vendor-neutral reference architecture for enterprise AI agents, written by @Docker @KeycardAI and @snyksec. It defines six security outcomes and 35 capabilities every team needs to confidently adopt, deploy, and govern agents. 🧵
1
2
14
2,046
A good cost conscious loop has to track state to know what it's already tried. That state typically exists in a shared memory store. @ianlivingstone explains "our access control systems weren't designed for this world where machines are acting and reasoning on our behalf"
1
2
3
853
Our CEO @ianlivingstone defended loops during a debate on the main stage of @aiDotEngineer World's Fair His key points > software is inherently verifiable > loops are at the core of software > at some point a human has to be attributable for an agent's actions
🆕 The Great Loops Debate! piped.video/c35YoMdnI78 Team No Delta - @ianlivingstone - @GeoffreyHuntley Team Delta - @dexhorthy - @grichadev led by the inimitable @vtahowe! Our first ever Oxford Style Debate: There is, or is not, a delta between the hype behind loops and what actually works in practice.
1
3
9
1,279
This week we published a blog post on how we use Keycard to secure our own CI/CD To set the stage, in March 2025, one compromised GitHub Action leaked secrets from 23,000+ repos. A year later, the Megalodon campaign hit 5,500 repos in six hours. Same root cause both times 🧵
1
1
6
839
Our CTO @jaredhanson showed a demo of intent-based authorization (AAuth missions) as a way to reduce consent fatigue and defer credential issuance until after an agent has discovered tools.
2
92
During the panel our CEO @ianlivingstone shared building great identity and auth infrastructure means making makes use of, and helping define, the best practices available today, while building for what's coming tomorrow. piped.video/XqaJZ7MQQfw?si=-t1K…
1
1
154
Two CISOs from @box and @NomaSecurity on the security panel at @AICouncilConf described the same problem: teams today can't see half of what's running in their own environments. You can't govern an agent you can't identify. Identity comes first.
1
11
1,194
Our Head of DevRel @KimMaida gave a talk titled "It's 10pm. Do You Know Where Your Agents Are?" @aiDotEngineer Long story short, you probably don't know where they are. Stop by our booth to learn how to control agent access and secure coding agents, MCPs, and 3rd party APIs.
2
7
716
We're keeping busy @aiDotEngineer! Stop by our booth after @KimMaida's talk coming up here shortly at 2:50pm on the Security Track.
4
637
We're excited to share @snyksec is joining AAuth Night Snyk's job is securing what developers build, and agents are developers now, so having them in the room helps us build a big tent around AAuth and agent security best practices. RSVP to this and our other AIE side events👇
1
6
934
Today Keycard announced support for ID-JAG, the open standard behind Cross-App Access by @okta. It joins OAuth, A2A, and MCP as standards Keycard speaks, so you get one identity and access layer for the agents you build and the agents you buy. Your identity provider issues the grant, Keycard governs what the agent does with it. Agents borrow access to get their work done: a human's login, a shared service account, a static key copied between services. None of that can be scoped to one agent, governed, or revoked. That's what Keycard is for: centralizing how you adopt and build agents to automate your software development lifecycle and your business. Keycard is for developers building an agent or automating a workflow in your SDLC, for security governing every agent the organization builds or buys, and for every organization that wants to move fast with the right hard boundaries in place. Agents need short-lived, identity-bound tokens, not borrowed credentials. Secretless, scoped, governed. Read the announcement 👇
1
7
1,178
We're proud to have our own @KimMaida on stage giving a talk at @aiDotEngineer: "It's 10pm. Do You Know Where Your Agents Are?" Kim is also running a workshop on the 1st 12-3pm. You'll build a MCP server in TypeScript and lock it down with Keycard. Sign up link below.
3
1
14
1,720
OAuth was built for one person connecting to a resource. Not for an agent making 10,000 calls on your behalf. Even its creator @DickHardt thinks agents need something new. We're sponsoring AAuth Night on July 1st via @insecureagents to work through it together.
2
3
11
433
For 30 years, security assumed you could trust the actor and you'd have time to fix what broke. Agents break both assumptions. 🧵
1
9
557
@Redpoint named us to the 2026 InfraRed 100, the list of the most promising private infra companies. #AIAgents are the new infra layer. 🧵
4
4
16
1,376
Great night at the @insecureagents event at @AICouncilConf. Our co-founder @ianlivingstone was on the panel with @sentry, @browserbase, and @Cloudflare talking about why identity is the bottleneck for agents, followed by a packed happy hour. Thanks to Insecure Agents for putting this together and thanks to everyone that came out.
1
3
10
859
When one agent calls another to query Snowflake, it passes down the same broad credentials. Nothing is scoped to the task. Nothing expires with the session. You can't tell which agent did what, on whose behalf, or why. Today we're launching Keycard for Multi-Agent Apps 🧵
2
6
26
8,195
@a16z is hosting a Security & AI Demo Day on May 21 in SF. Fireside chat with @PattiDegnan and Joel de la Garza, then five portfolio companies demo live: @KeycardLabs, @SocketSecurity, @cotoolai, @CygnvsInc, and @DoppelHQ. Stick around for the cocktail reception after. It's always a good time to connect with folks building in this space.
1
13
330
Our CEO @ianlivingstone is presenting about Keycard at the @foundersysk Startup Showcase on May 20 in SF, co-hosted with @Rippling and @digitalocean. 60 minutes of fast startup presentations, plus networking with founders before and after.
2
2
9
708
Your agent needs API access, so you paste a static key into a .env file. The key has write permissions because sometimes you need that. The agent reads the data, finds an error, and helpfully writes a fix you didn't ask for 🧵
1
4
375
Every team building internal AI is reinventing the credential broker. We're comparing notes on stage 5/14 with @sentry, @browserbase, and @Cloudflare at AI Council.
1
11
1,441
Keycard has been named to the @CBinsights 2026 AI 100. We've been building the identity and access layer for AI agents: the infrastructure that identifies agents, enforces task-scoped access at runtime, and gives organizations a complete audit trail of every action 🧵
1
2
11
1,179
The @vercel breach didn't happen because OAuth failed. OAuth 2.0 did exactly what it was designed to do.🧵
1
6
443
AI agents inherit full user privileges by default. There's no native mechanism in current IAM systems to scope agent access below the level of the delegating human. Keycard CEO @ianlivingstone sat down with @tfir_io to talk about why the identity model needs to change ↓
1
2
10
671
Most expo booths run raffles with badge scans. For @OneRSAC, we built an agent that runs the raffle, so entering it was the demo. Then we offered to rig it in the visitor's favor 🧵
10
19
1,145
@openclaw manages calendars, pushes code, queries CRMs, monitors infrastructure, and delegates to sub-agents. It holds every key, all the time. Persistent agents that run 24/7 with access to production services are different than coding agents 🧵
3
1
14
2,747
Agents find credentials on disk, pull them into context, and send them through tool calls. 29 million secrets leaked on @github last year alone. The problem isn't the leak. It's that nothing verifies where they're replayed from. 🧵
1
9
690
Taking agents from demo to production is where most teams get stuck. MCP, auth, tool orchestration, governance: the pieces exist, but wiring them together is the hard part. On April 2 in SF, we're co-hosting AX Night with @StainlessAPI for an evening of demos and Q&A with speakers from @OpenAI, @googlecloud, @vercel, Keycard, and Stainless.
2
2
10
1,565
Your coding agents inherit your credentials and your permissions. No identity system in the stack can tell the difference between you and the agent acting in your name. Today: Keycard for Coding Agents 🧵
4
14
161
62,201
RSAC is a week out. Booth #2351 at Moscone South Expo. Everyone on the floor will be talking about agent security this year. The difference is where you enforce it. We enforce it before the credential exists. Come see it. We're also raffling off prizes you'll actually want at the booth.
1
11
580
Your agent hits 7 APIs on behalf of a user. Are you building 7 separate OAuth implementations, or handing it one over-privileged token and hoping for the best? Keycard: one login, one JWT. Each tool call gets an ephemeral token scoped to the task. Used once, discarded. If policy says no, the credential never exists.
1
4
559
Kicking off RSA week early. We're co-hosting a reception with @Boldstartvc, Surf AI, and GainSecurity for security leaders and entrepreneurs. March 22. 1 Hotel, SF. 6 PM to 9 PM. Great conversations, food, and drinks before RSA officially begins. Registration required (approval-based) 👇
1
1
9
740
Agents are making decisions, accessing APIs, and acting autonomously. The identity models we have weren't built for this. Our CEO @ianlivingstone is joined by fellow panelists Karl McGuinness (ex-@okta), Amanda Robson (@mtf_vc), and a guest from @AnthropicAI to talk about what needs to change. March 25 in SF. Panel + happy hour 👇
1
1
10
899