Skip to content

GenAuth ​

GenAuth provides agent identity and delegated authorization. These diagrams show how people, agents, the IdP, SSO, and apps work together.

Agent Identity on one page ​

Follow the person and agent through authentication, delegation, and app access, then look at the audit chain below.

The diagrams include planned capabilities (current support). The “Revoke in one click, <1 s” and “Unbind = instantly void” labels are design targets; issued tokens currently remain valid until expiry (revocation behavior).

Agent Identity overview: identity, delegation, and app access flows between a person, an agent, and GenAuth

People, agents, and apps ​

The person delegates authority and remains accountable; the agent acts on their behalf. The identity provider (IdP) authenticates them, and single sign-on (SSO) connects them to apps. Each app controls access and can expose two entry paths: one for user login and one for agent identity.

The five roles of people, agents, the IdP, SSO, and apps, with user and agent entry paths

Core problem ​

Traditional OAuth was designed for human users and backend services. Agent scenarios are more complex: agents call tools, access MCP, operate webpages, and continue work across sessions. Permissions must be explicitly delegated, scoped, and audited.

GenAuth makes agents first-class participants in the authorization model.

Capabilities ​

CapabilityDescription
Identity GatewayCreates an identity abstraction between users, agents, MCP, and business systems
Delegated AuthorizationConverts human authorization into expiring, scoped, and revocable agent permissions
MCP Hub ProfilesProvides standard profiles for connecting agents to external tools and data sources
Audit TrailRecords the complete chain of human, agent, time, resource, and action

CLI workflow ​

GenAuth provides genauth-cli for managing user pools, applications, and OIDC scopes from the command line. Developers can use interactive commands to complete OIDC setup, while agents and CI jobs can use --json, --no-input, and environment variables for deterministic automation.

Read GenAuth CLI for installation, login, application creation, and genauth oidc setup.

Policy boundary ​

GenAuth defines the boundary of agent action:

  • Which resources the agent can access.
  • Which user the agent can represent.
  • Whether the action requires secondary confirmation.
  • Whether the action can be traced and reviewed.

Best fit ​

GenAuth is best suited for teams building agent products from day zero, enterprises upgrading existing identity systems into agentic authorization, and platforms that need MCP, Profile, and Authorization as standard capabilities.