Google Agent Identity
Google Cloud
SPIFFE-based cryptographic identity for agents on Gemini Enterprise Agent Platform, usable as an IAM principal with auto-rotated certs.
Identities, scoped access, and access reviews for AI agents as non-human principals.
Agents need their own identities, least-privilege access, owners, and access reviews — the same controls people get. Compare identity-provider, governance, and privileged-access vendors on how they register, authorise, and audit agents.
Tools from the major platform vendors are listed first; independent and open-source options follow below.
Google Cloud
SPIFFE-based cryptographic identity for agents on Gemini Enterprise Agent Platform, usable as an IAM principal with auto-rotated certs.
Microsoft
Entra identity platform for AI agents: agent identities and blueprints with Conditional Access, ID Protection and governance.
8 matching non-vendor tools in this filtered view.
Policy-based, just-in-time access for AI agents via an MCP Authorization Server and MCP Identity Gateway with credential injection.
Okta (Auth0)
Developer identity for AI agents: user login, Token Vault for third-party APIs, CIBA human approvals and fine-grained authorization for RAG.
Descope
Control plane for AI agent identity: OAuth 2.1 MCP auth, token vault connections, scoped policies and a user-linked audit trail.
Palo Alto Networks (Idira)
Discovers AI agents across SaaS, cloud and dev environments and brokers their MCP tool access with just-in-time privilege and audit.
Discovers, registers and governs AI agents in Okta Universal Directory with scoped tokens, vaulted secrets and access reviews.
Ping Identity
Runtime identity for AI agents: Agent IAM Core, an Agent Gateway enforcing fine-grained authorization, and agent detection.
SailPoint
Discovers and governs AI agents in SailPoint Identity Security Cloud with human owners, access reviews and revocation.
Saviynt
Saviynt's AI identity security platform: discovers agents, MCP servers and NHIs, maps access paths and governs agent lifecycle.
Okta made Agent SSO generally available, built on the Cross App Access standard and included in core Okta SSO.
SourceSaviynt launched Zuma, an AI identity security platform with agent discovery, runtime intent-aware access, and governance for AI agents and non-human identities.
SourceAn agent that reuses a person's credentials or a shared API key cannot be scoped, reviewed, or revoked on its own, and its actions cannot be told apart from the human's in audit logs. A dedicated agent identity with a named human owner makes least privilege, access reviews, and kill switches possible.
OAuth 2.x remains the base. The Model Context Protocol's authorization spec builds on OAuth 2.1 for agent-to-tool access, and its enterprise-managed authorization extension lets an identity provider decide which agents can reach which MCP servers. The OpenID Foundation's AuthZEN work covers fine-grained authorization decisions.
The identity and access management team or the CISO, not the AI platform team — which is why it is tracked separately from agent control planes. Most vendors here extend an existing identity provider, governance, or privileged-access product to agents.
Compare the active category against the platform foundation layer, the cross-category updates feed, and the sourcing/contribution guide.
Review Microsoft Foundry, Amazon Bedrock, and Gemini Enterprise Agent Platform as the foundation layer behind this category.
Check the market-intelligence feed for high-impact moves, plus the expandable full log for releases, deprecations, acquisitions, and other notable changes.
See sourcing standards, contribution rules, and project scope before adding or updating tracked tools.