Skip to main content

Secure access for AI agents

Choose the identity model for each AI agent

Use delegated user identity when an agent acts for an interactive user. Use a Pomerium service-account JWT for a headless agent or background job.

What this pattern controls

Delegated user

Carry the interactive user identity through the agent.

Service account

Use a stored JWT for a headless agent.

Consistent policy

Apply the same route and tool policy boundary.

Interactive user

Delegate the signed-in user to the agent

Use delegation when the agent acts for an interactive user. Pomerium applies policy to the delegated user identity.

  • Use an mcp: client route to obtain a Pomerium external token.
  • Pass that token to an LLM API that supports delegated MCP access.
  • Keep the original user identity visible to route and tool policy.

Headless agent

Use a service account for background work

Use a service account for a headless agent or background job. A stored service-account JWT is a credential and can be long-lived.

  • Create a Pomerium service account JWT for a headless agent.
  • Store the JWT securely and set an expiration when supported.
  • Complete upstream OAuth interactively before a headless service account reuses the user connection.

Technical sources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo