AI Agent Authentication & Least-Privilege IAM in 2026: Securing MCP, Tool Credentials, and Token Delegation
In 2026, autonomous AI agents actively execute code, query production databases, and trigger cloud deployments. Yet the majority of enterprise agent deployments still rely on hardcoded, static admin API keysโexposing critical infrastructure to indirect prompt injections. This architectural guide details how to transition to Zero-Trust Agent Authorization, OAuth 2.0 Token Exchange (RFC 8693), and Policy-as-Code gateways.
- 1. Quick Summary & Core Principles
- 2. The Identity Crisis of AI Agents
- 3. Why Static API Keys Fail for Agents
- 4. OAuth 2.0 Token Exchange (RFC 8693)
- 5. Securing Model Context Protocol (MCP)
- 6. Policy-as-Code with Cedar & OPA
- 7. Python Zero-Trust Gateway Implementation
- 8. Architectural Comparison Matrix
- 9. Compliance, Audit Trails & Non-Repudiation
- 10. Decision Framework & Related Tools
1. Quick Summary & Core Principles
- Never pass raw bearer tokens into an LLM's prompt context window. Agents should only handle abstract capability references; credential resolution and injection must occur out-of-band via an isolated Tool Broker Gateway.
- Adopt OAuth 2.0 Token Exchange (RFC 8693) for user delegation. Instead of provisioning an agent with static service credentials, exchange the user's primary access token for an ephemeral, downscoped delegate token with a strict TTL (< 15 minutes).
- Enforce Policy-as-Code (Cedar or OPA) before dispatch. Natural language system prompt rules ("Please do not delete production tables") are purely advisory and easily circumvented by prompt injections. Authorization decisions must be deterministic and executed outside the LLM.
- Implement Just-In-Time (JIT) Human Approval Gates for high-blast-radius operations such as database schema alterations, production Git pushes, or financial transfers.
In 2026, autonomous AI agents have shifted from passive auto-complete assistants into active digital workers. Whether resolving GitHub issues via OpenHands, interacting with cloud infrastructure via Model Context Protocol (MCP), or executing untrusted Python in an E2B Sandbox, agents require authenticated access to enterprise services.
2. The Identity Crisis of Autonomous AI Agents
Traditional Identity and Access Management (IAM) systems were designed around two rigid categories: interactive human users (authenticated via MFA/SSO) and deterministic backend services (authenticated via mTLS certificates or machine service accounts). Autonomous agents break both assumptions:
Traditional Microservice Invocation:
[Predictable Service A] โโโโโโโโ Hardcoded API Request โโโโโโโโโถ [Protected Service B]
Autonomous AI Agent Invocation:
[Human User] โโโถ [LLM Agent Orchestrator] โโโถ [Non-Deterministic Reasoning Loop]
โ
(Encountered Unverified Web Data / Malicious Pull Request)
โ
โผ
[Indirect Prompt Injection Attack]
โ
โผ
[Unauthorized Tool Invocation?]
When an agent acts autonomously, it operates as an intermediate delegate. It represents a human user, yet explores dynamic execution paths across disparate tools. If the agent's identity model is conflated with an all-powerful service account, any prompt injection transforms the agent into a confused deputy.
3. The Failure of Static API Keys & Traditional Bearer Tokens
Most initial agent deployments inject static API keys into container environment variables. In production, this approach creates four catastrophic architectural vulnerabilities:
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ The Catastrophic Blast Radius of Static Agent Credentials โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 1. Zero Context Awareness: A static GitHub PAT cannot distinguish between an agent โ
โ fixing a typo in a documentation PR and an agent force-pushing to the main branch. โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 2. Infinite Lifetime: Static keys remain valid indefinitely until manually rotated. โ
โ Compromised tokens often go unnoticed for months in agent execution logs. โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 3. All-or-Nothing Scoping: Most third-party SaaS APIs lack granular write permissions.โ
โ Granting write access to post a Jira comment often grants permission to delete โ
โ entire corporate project boards. โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 4. Prompt Exfiltration Susceptibility: Once a bearer token enters an LLM context โ
โ window, it is mathematically accessible to prompt reconstruction and jailbreaks. โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Any sensitive secret or bearer token that enters the prompt context window of an LLM must be treated as immediately compromised. Enterprise agent systems must ensure credentials reside solely in isolated gateway memory.
4. The Modern Agent IAM Architecture: OAuth 2.0 Token Exchange (RFC 8693)
To deliver secure delegation, modern architectures utilize OAuth 2.0 Token Exchange (RFC 8693). When a user requests an agent task, the system exchanges the primary user token for an ephemeral, downscoped delegate token:
โโโโโโโโโโโโ 1. Initiate Task ("Analyze Q3 Financials")
โ User โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโ โ
โ โผ
โ 2. Primary OAuth Token โโโโโโโโโโโโโโโโโโโโโโ
โ (Subject Token: User-Identity) โ AI Agent Core โ
โผ โ (Orchestrator) โ
โโโโโโโโโโโโโโโโ โโโโโโโโโโโฌโโโโโโโโโโโ
โ Enterprise โ โ
โ Identity IdP โโโโโ 3. RFC 8693 Token Exchange Request โโโโโโโโโโโโโโโ
โ (Okta/Auth0) โ - Subject Token: User Access Token
โโโโโโโโฌโโโโโโโโ - Actor Token: Agent Service Principal
โ - Requested Scope: ["finance.reports:read"]
โ - TTL: 300 seconds
โผ
4. Issues Ephemeral Downscoped Token
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Tool Broker Gateway โ
โ โโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ Policy Engine (Cedar)โโโโโโโถโ Credential Injector โ โ
โ โโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโฌโโโโโโโโโโโโ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโ
โ
โ 5. Authenticated Tool Call
โผ
โโโโโโโโโโโโโโโโโโโโโ
โ Target API / MCP โ
โ (Read-Only Scope) โ
โโโโโโโโโโโโโโโโโโโโโ
By generating compound tokens containing both the initiating user (sub) and the executing agent instance (act), the security team maintains an unforgeable identity chain. The token is restricted to the specific sub-operation and expires within minutes.
5. Securing Model Context Protocol (MCP) Tool Access
The Model Context Protocol (MCP) provides standard RPC interfaces for agent tools. Hardening MCP servers in production requires three foundational controls:
- Fine-Grained Capability Scoping: Expose explicit single-purpose tools (e.g.
github.issue.add_comment) rather than general shell executions (system.exec_bash). - Out-of-Band Secret Masking: Pass abstract vault references (e.g.
vault://creds/staging_db) to the agent. The Tool Broker intercepts the call and injects actual credentials over local TLS connections. - Just-In-Time (JIT) Approval Gates: For sensitive capabilities (deleting repositories, transferring funds, dropping database tables), execution pauses and prompts a human supervisor via webhook/Slack before executing.
6. Policy-as-Code for Agents: AWS Cedar & Open Policy Agent (OPA)
Natural language instructions inside system prompts fail under adversarial stress. Enterprise authorization must be evaluated deterministically using policy-as-code engines like AWS Cedar or Open Policy Agent (OPA):
// AWS Cedar Policy Example for AI Agent Tool Invocation
// 1. Permit read operations across assigned repositories
permit (
principal in Role::"CodingAgent",
action in [Action::"clone_repo", Action::"read_file", Action::"run_tests"],
resource in Repository::"Engineering"
);
// 2. Permit branch creation only when bound to an active Jira ticket
permit (
principal in Role::"CodingAgent",
action in [Action::"create_branch", Action::"open_pull_request"],
resource in Repository::"Engineering"
)
when {
context.has_valid_jira_ticket == true &&
context.ticket_assignee == principal.delegated_user
};
// 3. Strict forbidden rule: Never permit direct push to protected branches
forbid (
principal,
action in [Action::"git_push_direct", Action::"delete_repository"],
resource
)
when {
resource.branch in ["main", "master", "release/*"]
};
Before any tool executes, the Tool Broker evaluates the Cedar policy in under 2 milliseconds, blocking unauthorized attempts before any network packets leave the cluster.
7. Production Implementation: Building a Zero-Trust Agent Authorization Gateway in Python
The following production-ready Python implementation demonstrates how an enterprise gateway enforces policy evaluation, masks credentials from the LLM, and logs cryptographic audit trails:
"""
Zero-Trust Agent Authorization Gateway
Ecosystem: Python 3.11+, Pydantic v2, Cryptographic Audit Trails
"""
import time
import hmac
import hashlib
import json
from enum import Enum
from typing import Dict, Any, Optional
from pydantic import BaseModel, Field
class ActionRiskLevel(str, Enum):
LOW = "low" # Read-only operations, safe lookups
MEDIUM = "medium" # Creating drafts, opening PRs, writing staging data
CRITICAL = "critical" # Production writes, deletions, financial transfers
class ToolCallIntent(BaseModel):
tool_name: str
target_resource: str
action: str
arguments: Dict[str, Any]
risk_level: ActionRiskLevel
class AgentContext(BaseModel):
agent_id: str
delegated_user_id: str
session_id: str
assigned_scopes: list[str]
class AuthorizationDecision(BaseModel):
is_authorized: bool
requires_human_approval: bool
audit_token: str
reason: Optional[str] = None
class AgentZeroTrustGateway:
"""
Mediates all agent tool invocations. Enforces policy evaluation,
out-of-band credential injection, and immutable audit logging.
"""
def __init__(self, secret_key: str):
self._signing_key = secret_key.encode("utf-8")
# In production, load from Open Policy Agent / AWS Cedar daemon
self._policy_rules = {
"github.read": ActionRiskLevel.LOW,
"github.create_pr": ActionRiskLevel.MEDIUM,
"database.execute_select": ActionRiskLevel.LOW,
"database.drop_table": ActionRiskLevel.CRITICAL,
"kubernetes.delete_pod": ActionRiskLevel.CRITICAL
}
def evaluate_tool_intent(
self,
agent_ctx: AgentContext,
intent: ToolCallIntent
) -> AuthorizationDecision:
"""
Determines if the agent is authorized to execute the proposed tool intent.
"""
# Step 1: Check if tool requires scope that agent does not hold
required_scope = f"{intent.tool_name}:{intent.action}"
if required_scope not in agent_ctx.assigned_scopes and "*:*" not in agent_ctx.assigned_scopes:
return AuthorizationDecision(
is_authorized=False,
requires_human_approval=False,
audit_token=self._generate_audit_hash(agent_ctx, intent, "REJECTED_SCOPE"),
reason=f"Agent lacks required permission scope: {required_scope}"
)
# Step 2: Evaluate operational risk level
if intent.risk_level == ActionRiskLevel.CRITICAL:
# Critical actions always require Just-In-Time human sign-off
return AuthorizationDecision(
is_authorized=False,
requires_human_approval=True,
audit_token=self._generate_audit_hash(agent_ctx, intent, "PENDING_HUMAN_APPROVAL"),
reason="High-risk destructive operation requires human verification."
)
# Step 3: Action authorized under delegation
return AuthorizationDecision(
is_authorized=True,
requires_human_approval=False,
audit_token=self._generate_audit_hash(agent_ctx, intent, "AUTHORIZED"),
reason=None
)
def execute_with_isolated_credentials(
self,
agent_ctx: AgentContext,
intent: ToolCallIntent,
decision: AuthorizationDecision
) -> Dict[str, Any]:
"""
Injects credentials out-of-band. The raw credentials are NEVER
exposed to the LLM context window.
"""
if not decision.is_authorized:
raise PermissionError(f"Execution blocked: {decision.reason}")
# Ephemeral token retrieved from Vault / Token Exchange gateway
ephemeral_token = self._mint_ephemeral_token(agent_ctx, intent)
# Execute the tool securely via out-of-band injection
execution_result = self._dispatch_to_tool(intent, ephemeral_token)
return {
"status": "success",
"audit_hash": decision.audit_token,
"data": execution_result
}
def _generate_audit_hash(self, ctx: AgentContext, intent: ToolCallIntent, status: str) -> str:
payload = f"{ctx.agent_id}:{ctx.delegated_user_id}:{intent.tool_name}:{status}:{time.time()}"
return hmac.new(self._signing_key, payload.encode("utf-8"), hashlib.sha256).hexdigest()
def _mint_ephemeral_token(self, ctx: AgentContext, intent: ToolCallIntent) -> str:
# Simulates RFC 8693 token exchange with 5-minute TTL
return f"ephemeral_jwt_sub_{ctx.delegated_user_id}_act_{ctx.agent_id}_exp_{int(time.time()) + 300}"
def _dispatch_to_tool(self, intent: ToolCallIntent, token: str) -> Dict[str, Any]:
return {"records_affected": 1, "executed_action": intent.action}
8. Architectural Comparison Matrix
The following matrix compares the 4 leading agent authentication models across key enterprise dimensions:
| Dimension | 1. Static API Keys (Legacy) | 2. OAuth Token Exchange (RFC 8693) | 3. Policy-as-Code Gateway (Cedar/OPA) | 4. Cryptographic DIDs / Agent IDs |
|---|---|---|---|---|
| Credential Lifetime | Months / Years (Static) | 5 โ 15 Min (Ephemeral) | Zero token access (Gateway mediated) | Session-bound asymmetric keys |
| LLM Context Leakage Risk | Extreme (Key in prompt/env) | Medium (Key in runtime memory) | Zero (Masked out-of-band) | Zero (Signed crypto challenges) |
| Blast Radius | Entire enterprise workspace | Strictly bounded to task | Bounded by code policy | Bounded by signed credential claim |
| Revocation Latency | Manual (Hours/Days) | Automatic on completion | Instantaneous (Policy update) | Instantaneous (CRL / OCSP) |
| Human-in-the-Loop Gates | None | Limited (Re-auth prompts) | Native (Dynamic risk triggers) | Multi-sig confirmation |
| SOC2 / ISO 27001 Readiness | โ Fails audit controls | โ Fully Compliant | โญ Gold Standard | โญ Emerging Standard |
| Implementation Effort | Trivial (1 day) | Moderate (1โ2 weeks) | Moderate (1โ2 weeks) | High (Specialized cryptography) |
| Best Production Fit | Prototypes only | Multi-tenant SaaS | Enterprise internal stacks | Autonomous inter-org agents |
9. Compliance, Audit Trails & Non-Repudiation
When an autonomous agent mutates infrastructure or executes financial transactions, enterprise compliance frameworks require non-repudiation. Every action must be recorded in an immutable, cryptographically signed audit envelope:
{
"audit_version": "2026.1",
"timestamp": "2026-09-11T14:22:18.491Z",
"trace_id": "trace-8f92a11b-c741",
"actor": {
"agent_id": "agent-swe-core-09",
"delegated_user": "usr_998124_alice",
"delegation_token_fingerprint": "sha256:4b912e80..."
},
"prompt_context_hash": "sha256:d891e4a3...",
"intent": {
"tool": "aws_s3_gateway",
"action": "delete_object",
"resource": "arn:aws:s3:::internal-backups/archive-2025.tar.gz"
},
"policy_evaluation": {
"engine": "Cedar-v3",
"verdict": "ALLOW",
"evaluated_policies": ["policy_allow_backup_rotation_2026"]
},
"signature": "MEQCIG7zY8f+k7..."
}
By writing signed envelopes to Write-Once-Read-Many (WORM) storage, organizations satisfy SOC2 Type II, HIPAA, and ISO 27001 requirements while maintaining complete forensic visibility.
Choose the appropriate agent authentication pattern based on your operational boundaries:
- If building multi-tenant SaaS agents acting for end-users, implement OAuth 2.0 Token Exchange (RFC 8693) with short TTLs.
- If orchestrating internal enterprise automation across sensitive APIs, deploy a Policy-as-Code Tool Broker (Cedar/OPA) with secret masking.
- If performing high-risk destructive or financial actions, integrate Just-In-Time Human Approval Gates via LangGraph.
- If executing untrusted arbitrary code generated by agents, isolate environments in an E2B MicroVM Sandbox.
Explore Related IAM & Agent Infrastructure Tools on AgDex.ai
Autenticaciรณn y Gestiรณn de Acceso (IAM) de Mรญnimo Privilegio para Agentes IA en 2026: Asegurando MCP y Delegaciรณn de Tokens
En 2026, los agentes autรณnomos de IA ejecutan cรณdigo, consultan bases de datos productivas y despliegan infraestructura en la nube. Sin embargo, la gran mayorรญa de implementaciones empresariales aรบn depende de claves de API estรกticas con privilegios absolutos, exponiendo sistemas crรญticos a ataques de inyecciรณn indirecta de prompts. Esta guรญa arquitectรณnica analiza la autorizaciรณn Zero-Trust, el intercambio de tokens OAuth 2.0 (RFC 8693) y pasarelas de polรญtica como cรณdigo.
- 1. Resumen Rรกpido y Principios Clave
- 2. La Crisis de Identidad de los Agentes
- 3. Por Quรฉ Fallan las Claves Estรกticas
- 4. Intercambio de Tokens OAuth (RFC 8693)
- 5. Seguridad en Model Context Protocol (MCP)
- 6. Polรญtica como Cรณdigo con Cedar y OPA
- 7. Implementaciรณn de Pasarela Zero-Trust en Python
- 8. Matriz Comparativa de Arquitecturas
- 9. Cumplimiento, Trazabilidad y No Repudio
- 10. Marco de Decisiรณn y Herramientas
1. Resumen Rรกpido y Principios Clave
- Nunca inserte tokens bearer en el contexto de prompt de un LLM. Los agentes solo deben manejar referencias abstractas de capacidad; la resoluciรณn e inyecciรณn de credenciales debe ocurrir fuera de banda mediante una pasarela aislada (Tool Broker).
- Adopte OAuth 2.0 Token Exchange (RFC 8693) para delegaciรณn de usuarios. En lugar de asignar claves estรกticas al agente, intercambie el token de acceso del usuario por un token delegado efรญmero con alcance reducido y caducidad estricta (< 15 minutos).
- Aplique Polรญtica como Cรณdigo (Cedar u OPA) antes del despacho. Las instrucciones en lenguaje natural en el prompt de sistema ("Por favor no borres tablas productivas") son orientativas y se eluden con inyecciones adversarias. Las decisiones de autorizaciรณn deben ser deterministas y ejecutarse fuera del LLM.
- Implemente controles de Aprobaciรณn Humana Just-In-Time (JIT) para operaciones destructivas como cambios en esquemas de base de datos, publicaciones en ramas principales o transferencias financieras.
En 2026, los agentes de IA autรณnomos han evolucionado de simples asistentes de autocompletado a trabajadores digitales activos. Ya sea resolviendo incidencias en GitHub mediante OpenHands, interactuando con infraestructura cloud a travรฉs de Model Context Protocol (MCP), o ejecutando cรณdigo Python en E2B Sandbox, los agentes necesitan acceso autenticado seguro.
2. La Crisis de Identidad de los Agentes Autรณnomos
Los sistemas tradicionales de gestiรณn de identidades y accesos (IAM) se diseรฑaron para dos categorรญas rรญgidas: usuarios humanos interactivos (autenticados por MFA/SSO) y servicios deterministas de backend (con certificados mTLS o cuentas de servicio). Los agentes autรณnomos rompen ambos supuestos:
Invocaciรณn Tradicional de Microservicios:
[Servicio A Predecible] โโโโโโ Peticiรณn API Codificada โโโโโโโถ [Servicio B Protegido]
Invocaciรณn de Agente Autรณnomo de IA:
[Usuario Humano] โโโถ [Orquestador de Agente LLM] โโโถ [Bucle de Razonamiento Dinรกmico]
โ
(Encuentra Datos Web No Verificados / PR Maliciosa)
โ
โผ
[Ataque de Inyecciรณn Indirecta de Prompt]
โ
โผ
[ยฟEjecuciรณn No Autorizada de Herramienta?]
Cuando un agente actรบa de manera autรณnoma, opera como un delegado intermedio. Representa a un usuario humano, pero navega por rutas de ejecuciรณn dinรกmicas a travรฉs de herramientas heterogรฉneas. Si su identidad se equipara con una cuenta de servicio todopoderosa, cualquier inyecciรณn de prompt lo convierte en un intermediario confundido (confused deputy).
3. Por Quรฉ Fallan las Claves de API Estรกticas y Tokens Tradicionales
La mayorรญa de los primeros despliegues inyectan claves de API estรกticas en variables de entorno del contenedor. En producciรณn, este enfoque genera cuatro vulnerabilidades arquitectรณnicas crรญticas:
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Radio de Impacto Catastrรณfico de Credenciales Estรกticas en Agentes โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 1. Cero Conciencia de Contexto: Un PAT estรกtico de GitHub no puede distinguir entre un โ
โ agente corrigiendo una errata y un agente forzando un push a la rama main. โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 2. Vida รtil Infinita: Las claves estรกticas siguen activas hasta su rotaciรณn manual. โ
โ Tokens comprometidos pasan desapercibidos durante meses en registros de agentes. โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 3. Alcance Todo o Nada: La mayorรญa de APIs SaaS carecen de permisos de escritura finos.โ
โ Conceder acceso para comentar en Jira suele otorgar permiso para borrar proyectos. โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 4. Vulnerabilidad de Exfiltraciรณn: Si un token entra al contexto del LLM, es โ
โ matemรกticamente accesible mediante tรฉcnicas de reconstrucciรณn de prompts. โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Cualquier secreto sensible o token bearer que ingrese a la ventana de contexto de un LLM debe considerarse comprometido de inmediato. Los sistemas empresariales deben asegurar que las credenciales residan exclusivamente en la memoria aislada de la pasarela.
4. Arquitectura Moderna de IAM: Intercambio de Tokens OAuth 2.0 (RFC 8693)
Para ofrecer una delegaciรณn segura, las arquitecturas modernas implementan el estรกndar OAuth 2.0 Token Exchange (RFC 8693). Cuando el usuario solicita una tarea, el sistema intercambia el token principal por un token delegado temporal con alcance mรญnimo:
โโโโโโโโโโโโ 1. Iniciar Tarea ("Analizar Finanzas Q3")
โ Usuario โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโ โ
โ โผ
โ 2. Token OAuth Primario โโโโโโโโโโโโโโโโโโโโโโ
โ (Subject Token: Identidad de Usuario) โ Nรบcleo del Agente โ
โผ โ (Orquestador) โ
โโโโโโโโโโโโโโโโ โโโโโโโโโโโฌโโโโโโโโโโโ
โ Proveedor โ โ
โ de Identidad โโโโโ 3. Peticiรณn RFC 8693 Token Exchange โโโโโโโโโโโโโโ
โ (Okta/Auth0) โ - Subject Token: Token de Acceso de Usuario
โโโโโโโโฌโโโโโโโโ - Actor Token: Identidad de Servicio del Agente
โ - Alcance Solicitado: ["finance.reports:read"]
โ - TTL: 300 segundos
โผ
4. Emite Token Efรญmero Reducido
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Pasarela Mediadora (Tool Broker) โ
โ โโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ Motor Polรญtico Cedar โโโโโโโถโ Inyector Credencialesโ โ
โ โโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโฌโโโโโโโโโโโโ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโ
โ
โ 5. Llamada a Herramienta Autenticada
โผ
โโโโโโโโโโโโโโโโโโโโโ
โ API Destino / MCP โ
โ (Solo Lectura) โ
โโโโโโโโโโโโโโโโโโโโโ
Al generar tokens compuestos que identifican tanto al usuario solicitante (sub) como a la instancia del agente (act), los equipos de seguridad mantienen una cadena de auditorรญa inalterable. El token se limita a la suboperaciรณn y caduca en minutos.
5. Seguridad en el Protocolo de Contexto de Modelo (MCP)
El protocolo Model Context Protocol (MCP) proporciona interfaces RPC abiertas para conectar herramientas con agentes. La protecciรณn de servidores MCP en producciรณn exige tres controles:
- Declaraciรณn de Capacidades Granulares: Exponer herramientas especรญficas de propรณsito รบnico (como
github.issue.add_comment) en lugar de accesos genรฉricos de shell (system.exec_bash). - Enmascaramiento Fuera de Banda de Secretos: Pasar referencias abstractas (ej.
vault://creds/staging_db) al agente. El Tool Broker intercepta la llamada e inyecta las credenciales reales sobre TLS local. - Puertas de Aprobaciรณn Humana Just-In-Time: Para capacidades de alto impacto (borrar repositorios, transferir fondos, eliminar tablas), la ejecuciรณn se congela y solicita confirmaciรณn a un operador antes de proseguir.
6. Polรญtica como Cรณdigo para Agentes: AWS Cedar y Open Policy Agent (OPA)
Las restricciones en lenguaje natural dentro del prompt fallan ante ataques adversarios. La autorizaciรณn empresarial debe evaluarse de forma determinista mediante motores de polรญtica como cรณdigo como AWS Cedar u Open Policy Agent (OPA):
// Ejemplo de Polรญtica AWS Cedar para Agentes de Cรณdigo
// 1. Permitir lectura y anรกlisis en repositorios asignados
permit (
principal in Role::"CodingAgent",
action in [Action::"clone_repo", Action::"read_file", Action::"run_tests"],
resource in Repository::"Engineering"
);
// 2. Permitir creaciรณn de ramas solo vinculadas a un ticket Jira vรกlido
permit (
principal in Role::"CodingAgent",
action in [Action::"create_branch", Action::"open_pull_request"],
resource in Repository::"Engineering"
)
when {
context.has_valid_jira_ticket == true &&
context.ticket_assignee == principal.delegated_user
};
// 3. Regla de prohibiciรณn estricta: Jamรกs permitir push directo a ramas protegidas
forbid (
principal,
action in [Action::"git_push_direct", Action::"delete_repository"],
resource
)
when {
resource.branch in ["main", "master", "release/*"]
};
Antes de ejecutar cualquier herramienta, el Tool Broker evalรบa la polรญtica Cedar en menos de 2 milisegundos, bloqueando intentos no autorizados antes de emitir paquetes a la red.
7. Implementaciรณn de Pasarela Zero-Trust en Python
La siguiente clase en Python demuestra cรณmo una pasarela empresarial valida intenciones de herramientas frente a polรญticas, oculta credenciales al LLM y registra pistas criptogrรกficas de auditorรญa:
"""
Zero-Trust Agent Authorization Gateway
Ecosystem: Python 3.11+, Pydantic v2, Cryptographic Audit Trails
"""
import time
import hmac
import hashlib
import json
from enum import Enum
from typing import Dict, Any, Optional
from pydantic import BaseModel, Field
class ActionRiskLevel(str, Enum):
LOW = "low" # Operaciones de lectura y consultas seguras
MEDIUM = "medium" # Creaciรณn de borradores, apertura de PRs
CRITICAL = "critical" # Escrituras en producciรณn, borrados, finanzas
class ToolCallIntent(BaseModel):
tool_name: str
target_resource: str
action: str
arguments: Dict[str, Any]
risk_level: ActionRiskLevel
class AgentContext(BaseModel):
agent_id: str
delegated_user_id: str
session_id: str
assigned_scopes: list[str]
class AuthorizationDecision(BaseModel):
is_authorized: bool
requires_human_approval: bool
audit_token: str
reason: Optional[str] = None
class AgentZeroTrustGateway:
"""
Gestiona todas las invocaciones de herramientas del agente.
Aplica evaluaciรณn de polรญticas, inyecciรณn segura de tokens y registro inmutable.
"""
def __init__(self, secret_key: str):
self._signing_key = secret_key.encode("utf-8")
self._policy_rules = {
"github.read": ActionRiskLevel.LOW,
"github.create_pr": ActionRiskLevel.MEDIUM,
"database.execute_select": ActionRiskLevel.LOW,
"database.drop_table": ActionRiskLevel.CRITICAL,
"kubernetes.delete_pod": ActionRiskLevel.CRITICAL
}
def evaluate_tool_intent(
self,
agent_ctx: AgentContext,
intent: ToolCallIntent
) -> AuthorizationDecision:
required_scope = f"{intent.tool_name}:{intent.action}"
if required_scope not in agent_ctx.assigned_scopes and "*:*" not in agent_ctx.assigned_scopes:
return AuthorizationDecision(
is_authorized=False,
requires_human_approval=False,
audit_token=self._generate_audit_hash(agent_ctx, intent, "REJECTED_SCOPE"),
reason=f"El agente no posee el alcance requerido: {required_scope}"
)
if intent.risk_level == ActionRiskLevel.CRITICAL:
return AuthorizationDecision(
is_authorized=False,
requires_human_approval=True,
audit_token=self._generate_audit_hash(agent_ctx, intent, "PENDING_HUMAN_APPROVAL"),
reason="Operaciรณn destructiva de alto riesgo requiere verificaciรณn humana."
)
return AuthorizationDecision(
is_authorized=True,
requires_human_approval=False,
audit_token=self._generate_audit_hash(agent_ctx, intent, "AUTHORIZED"),
reason=None
)
def execute_with_isolated_credentials(
self,
agent_ctx: AgentContext,
intent: ToolCallIntent,
decision: AuthorizationDecision
) -> Dict[str, Any]:
if not decision.is_authorized:
raise PermissionError(f"Ejecuciรณn bloqueada: {decision.reason}")
ephemeral_token = self._mint_ephemeral_token(agent_ctx, intent)
execution_result = self._dispatch_to_tool(intent, ephemeral_token)
return {
"status": "success",
"audit_hash": decision.audit_token,
"data": execution_result
}
def _generate_audit_hash(self, ctx: AgentContext, intent: ToolCallIntent, status: str) -> str:
payload = f"{ctx.agent_id}:{ctx.delegated_user_id}:{intent.tool_name}:{status}:{time.time()}"
return hmac.new(self._signing_key, payload.encode("utf-8"), hashlib.sha256).hexdigest()
def _mint_ephemeral_token(self, ctx: AgentContext, intent: ToolCallIntent) -> str:
return f"ephemeral_jwt_sub_{ctx.delegated_user_id}_act_{ctx.agent_id}_exp_{int(time.time()) + 300}"
def _dispatch_to_tool(self, intent: ToolCallIntent, token: str) -> Dict[str, Any]:
return {"records_affected": 1, "executed_action": intent.action}
8. Matriz Comparativa de Arquitecturas
La siguiente matriz compara los 4 enfoques de autenticaciรณn para agentes en dimensiones empresariales clave:
| Dimensiรณn | 1. Claves de API Estรกticas | 2. Token Exchange (RFC 8693) | 3. Pasarela Cedar / OPA | 4. DIDs y Credenciales Criptogrรกficas |
|---|---|---|---|---|
| Vida รtil Credencial | Meses / Aรฑos (Estรกtica) | 5 โ 15 Minutos (Efรญmera) | Cero exposiciรณn (Mediaciรณn pasarela) | Claves asimรฉtricas vinculadas a sesiรณn |
| Riesgo Fuga en Prompt | Extremo (Clave en contexto/env) | Medio (Token en memoria runtime) | Cero (Oculto fuera de banda) | Cero (Desafรญos criptogrรกficos firmados) |
| Radio de Impacto | Espacio de trabajo empresarial completo | Estrictamente acotado a la tarea | Acotado por polรญtica determinista | Acotado por declaraciรณn firmada |
| Latencia Revocaciรณn | Manual (Horas/Dรญas) | Automรกtica al finalizar tarea | Instantรกnea (Actualizaciรณn de regla) | Instantรกnea (Listas CRL / OCSP) |
| Puertas Humanas (HITL) | Nula | Limitada (Re-autenticaciรณn) | Nativa (Gatillos dinรกmicos de riesgo) | Confirmaciรณn multifirma |
| Cumplimiento SOC2 / ISO | โ Suspende auditorรญa | โ Totalmente compatible | โญ Estรกndar de Oro | โญ Estรกndar Emergente |
| Complejidad Desarrollo | Trivial (1 dรญa) | Moderada (1โ2 semanas) | Moderada (1โ2 semanas) | Alta (Criptografรญa avanzada) |
| Ajuste en Producciรณn | Solo prototipos y demos | SaaS multi-inquilino | Infraestructuras empresariales | Agentes inter-organizaciones |
9. Cumplimiento, Trazabilidad y No Repudio
Cuando un agente autรณnomo modifica infraestructura o efectรบa transacciones financieras, los auditores exigen garantรญas de no repudio. Cada acciรณn debe registrarse en una envoltura de auditorรญa inmutable firmada digitalmente:
{
"audit_version": "2026.1",
"timestamp": "2026-09-11T14:22:18.491Z",
"trace_id": "trace-8f92a11b-c741",
"actor": {
"agent_id": "agent-swe-core-09",
"delegated_user": "usr_998124_alice",
"delegation_token_fingerprint": "sha256:4b912e80..."
},
"prompt_context_hash": "sha256:d891e4a3...",
"intent": {
"tool": "aws_s3_gateway",
"action": "delete_object",
"resource": "arn:aws:s3:::internal-backups/archive-2025.tar.gz"
},
"policy_evaluation": {
"engine": "Cedar-v3",
"verdict": "ALLOW",
"evaluated_policies": ["policy_allow_backup_rotation_2026"]
},
"signature": "MEQCIG7zY8f+k7..."
}
Al archivar estas pistas en sistemas de almacenamiento WORM (Write Once, Read Many), las empresas satisfacen normativas SOC2 Type II, HIPAA e ISO 27001 asegurando visibilidad forense completa.
Seleccione el patrรณn de autenticaciรณn adecuado segรบn sus lรญmites de operaciรณn:
- Si desarrolla agentes SaaS multi-inquilino, adopte OAuth 2.0 Token Exchange (RFC 8693) con tokens de corta duraciรณn.
- Si gestiona automatizaciones corporativas sobre APIs sensibles, despliegue una Pasarela Polรญtica como Cรณdigo (Cedar/OPA) con ocultaciรณn de secretos.
- Si ejecuta acciones destructivas o financieras de alto impacto, integre Puertas de Aprobaciรณn Humana Just-In-Time mediante LangGraph.
- Si procesa cรณdigo arbitrario generado por modelos, aรญsle la ejecuciรณn en un E2B MicroVM Sandbox.
Explora herramientas de IAM e infraestructura de agentes en AgDex.ai
AI-Agent-Authentifizierung & Least-Privilege-IAM 2026: MCP-Tools, Zugangsdaten und Token-Delegation absichern
Im Jahr 2026 fรผhren autonome KI-Agenten eigenstรคndig Code aus, manipulieren Produktionsdatenbanken und steuern Cloud-Deployments. Dennoch basiert die Mehrzahl unternehmensweiter Implementierungen auf statischen Admin-API-Keys mit unbeschrรคnkten Rechten โ ein ideales Einfallstor fรผr indirekte Prompt-Injections. Dieser Architektur-Leitfaden zeigt den รbergang zu Zero-Trust-Autorisierung, OAuth 2.0 Token Exchange (RFC 8693) und Policy-as-Code-Gateways.
- 1. Schnellรผbersicht & Kernprinzipien
- 2. Die Identitรคtskrise autonomer KI-Agenten
- 3. Warum statische API-Schlรผssel versagen
- 4. OAuth 2.0 Token Exchange (RFC 8693)
- 5. Absicherung des Model Context Protocols (MCP)
- 6. Policy-as-Code mit Cedar & OPA
- 7. Python-Implementierung des Zero-Trust-Gateways
- 8. Architektur-Vergleichsmatrix
- 9. Compliance, Prรผfpfade & Nicht-Abstreitbarkeit
- 10. Entscheidungsmatrix & Relevante Tools
1. Schnellรผbersicht & Kernprinzipien
- รbergeben Sie niemals echte Bearer-Tokens in das Prompt-Kontextfenster eines LLMs. Agenten sollten nur abstrakte Funktionsreferenzen verwalten; die Token-Injektion muss out-of-band รผber ein isoliertes Tool-Broker-Gateway erfolgen.
- Nutzen Sie OAuth 2.0 Token Exchange (RFC 8693) fรผr Benutzerdelegationen. Anstelle statischer Dienstkonten tauschen Sie das Zugriffstoken des Benutzers gegen ein flรผchtiges, berechtigungslimitiertes Delegations-Token mit kurzer Lebensdauer (< 15 Minuten).
- Erzwingen Sie Policy-as-Code (Cedar oder OPA) vor jedem Tool-Aufruf. Verbale System-Prompt-Regeln ("Bitte lรถsche niemals Tabellen") sind unverbindlich und durch Jailbreaks manipulierbar. Autorisierungsentscheidungen mรผssen deterministisch auรerhalb des LLMs fallen.
- Integrieren Sie Just-In-Time (JIT) Human-in-the-Loop-Freigaben fรผr zerstรถrerische Aktionen wie Datenbankรคnderungen, Produktiv-Pushes oder Finanztransaktionen.
Im Jahr 2026 sind autonome KI-Agenten vollwertige digitale Mitarbeiter. Ob beim automatisierten Beheben von GitHub-Issues mit OpenHands, dem Steuern von Cloud-Diensten via Model Context Protocol (MCP) oder der isolierten Python-Ausfรผhrung in einer E2B Sandbox โ sichere Identitรคtsmodelle sind Pflicht.
2. Die Identitรคtskrise autonomer KI-Agenten
Traditionelle IAM-Systeme trennen strikt zwischen menschlichen Benutzern (MFA/SSO) und deterministischen Backend-Services (mTLS/Service Accounts). Autonome Agenten durchbrechen diese Grenzen:
Klassischer Microservice-Aufruf:
[Service A (Deterministisch)] โโโโ Hardcoded API-Aufruf โโโโโถ [Geschรผtzter Service B]
Aufruf durch autonomen KI-Agenten:
[Menschlicher Nutzer] โโโถ [LLM-Agent-Orchestrator] โโโถ [Nicht-deterministische Reasoning-Schleife]
โ
(Trifft auf ungeprรผfte Webdaten / Schad-Pull-Request)
โ
โผ
[Indirekte Prompt-Injection-Attacke]
โ
โผ
[Unautorisierte Tool-Ausfรผhrung?]
Ein Agent agiert als intermediรคrer Delegat: Er handelt im Auftrag eines Menschen, trifft jedoch autonome Entscheidungen รผber externe APIs hinweg. Wird er mit einem allmรคchtigen Service-Account ausgestattet, fรผhrt jede Prompt-Injection zum Confused-Deputy-Exploit.
3. Warum statische API-Schlรผssel fรผr Agenten versagen
Werden statische API-Schlรผssel in Container-Umgebungsvariablen hinterlegt, entstehen gravierende Sicherheitsrisiken:
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Der verheerende Explosionsradius statischer Agenten-Zugangsdaten โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 1. Fehlender Kontext: Ein GitHub-PAT unterscheidet nicht, ob ein Agent einen Rechtschreib- โ
โ fehler behebt oder destruktiv den main-Branch รผberschreibt. โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 2. Unendliche Gรผltigkeit: Statische Schlรผssel bleiben aktiv, bis sie manuell widerrufen โ
โ werden. Kompromittierte Tokens bleiben oft monatelang unentdeckt. โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 3. Grobe Berechtigungen: Viele SaaS-APIs kennen keine feingranularen Schreibrechte. โ
โ Rechte zum Kommentieren erlauben oft das Lรถschen ganzer Unternehmensprojekte. โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 4. Prompt-Exfiltration: Sobald ein Bearer-Token in den Prompt-Kontext gelangt, ist er โ
โ durch Prompt-Reconstruction-Angriffe mathematisch angreifbar. โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Jedes sensible Geheimnis oder Bearer-Token, das das Prompt-Kontextfenster eines LLMs erreicht, gilt als kompromittiert. Zugangsdaten dรผrfen sich ausschlieรlich im isolierten Speicher des Gateways befinden.
4. Moderne Agent-IAM: OAuth 2.0 Token Exchange (RFC 8693)
Moderne Unternehmensarchitekturen nutzen OAuth 2.0 Token Exchange (RFC 8693). Wenn ein Nutzer einen Agenten beauftragt, tauscht das Identity-Gateway das primรคre Nutzerschlรผssel-Token gegen ein kurzlebiges, funktionsgebundenes Delegations-Token aus:
โโโโโโโโโโโโ 1. Aufgabe initiieren ("Q3-Finanzbericht prรผfen")
โ Benutzer โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโ โ
โ โผ
โ 2. Primรคres OAuth-Token โโโโโโโโโโโโโโโโโโโโโโ
โ (Subject Token: Nutzer-Identitรคt) โ KI-Agenten-Kern โ
โผ โ (Orchestrator) โ
โโโโโโโโโโโโโโโโ โโโโโโโโโโโฌโโโโโโโโโโโ
โ Enterprise โ โ
โ IdP Provider โโโโโ 3. RFC 8693 Token Exchange Request โโโโโโโโโโโโโโโ
โ (Okta/Auth0) โ - Subject Token: Nutzer-Zugriffstoken
โโโโโโโโฌโโโโโโโโ - Actor Token: Agent-Dienstkonto
โ - Angefordertes Scope: ["finance.reports:read"]
โ - TTL: 300 Sekunden
โผ
4. Erzeugt flรผchtiges Delegations-Token
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Tool-Broker-Gateway โ
โ โโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ Policy-Engine (Cedar)โโโโโโโถโ Credential-Injektor โ โ
โ โโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโฌโโโโโโโโโโโโ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโ
โ
โ 5. Authentifizierter Tool-Aufruf
โผ
โโโโโโโโโโโโโโโโโโโโโ
โ Ziel-API / MCP โ
โ (Nur-Lese-Rechte) โ
โโโโโโโโโโโโโโโโโโโโโ
Durch Verbund-Tokens, die sowohl den Nutzer (sub) als auch den ausfรผhrenden Agenten (act) kryptografisch binden, bleibt die Prรผfkette lรผckenlos gewahrt. Das Token erlischt nach wenigen Minuten automatisch.
5. Absicherung des Model Context Protocols (MCP)
Das Model Context Protocol (MCP) hat sich als universelle RPC-Schnittstelle fรผr Agenten-Tools etabliert. Die Absicherung in Produktivumgebungen erfordert drei Kernmaรnahmen:
- Granulare Funktionsdeklaration: Tools mรผssen auf konkrete Einzeloperationen beschrรคnkt sein (z. B.
github.issue.add_comment) statt pauschale Shell-Rechte einzurรคumen (system.exec_bash). - Out-of-Band-Geheimnismaskierung: Dem Agenten werden nur abstrakte Vault-Referenzen รผbergeben (z. B.
vault://creds/staging_db). Der Tool-Broker lรถst diese intern auf und fรผhrt den Aufruf รผber TLS aus. - Just-In-Time (JIT) Freigaben: Bei kritischen Befehlen (Lรถschen von Repositories, Finanzรผberweisungen) unterbricht die MCP-Pasarela die Ausfรผhrung und fordert eine explizite Bestรคtigung eines menschlichen Operators an.
6. Policy-as-Code fรผr Agenten: AWS Cedar & Open Policy Agent (OPA)
Verbale Schutzmaรnahmen in Prompts scheitern bei gezielten Manipulationen. Berechtigungsentscheidungen mรผssen durch Policy-Engines wie AWS Cedar oder OPA deterministisch getroffen werden:
// AWS-Cedar-Richtlinienbeispiel fรผr Coding-Agenten
// 1. Erlaube Lese- und Testoperationen in autorisierten Repositories
permit (
principal in Role::"CodingAgent",
action in [Action::"clone_repo", Action::"read_file", Action::"run_tests"],
resource in Repository::"Engineering"
);
// 2. Erlaube Branch-Erstellung nur bei gรผltigem Jira-Ticket
permit (
principal in Role::"CodingAgent",
action in [Action::"create_branch", Action::"open_pull_request"],
resource in Repository::"Engineering"
)
when {
context.has_valid_jira_ticket == true &&
context.ticket_assignee == principal.delegated_user
};
// 3. Striktes Verbot: Direkte Pushes auf geschรผtzte Branches blockieren
forbid (
principal,
action in [Action::"git_push_direct", Action::"delete_repository"],
resource
)
when {
resource.branch in ["main", "master", "release/*"]
};
Die Cedar-Engine wertet Anfragen in unter 2 Millisekunden aus und blockiert unerlaubte Aufrufe, noch bevor Netzwerkpakete das Gateway verlassen.
7. Python-Implementierung des Zero-Trust-Gateways
Die folgende einsatzbereite Python-Klasse verifiziert Tool-Absichten, verbirgt Tokens vor dem Sprachmodell und erzeugt manipulationssichere Audit-Hashes:
"""
Zero-Trust Agent Authorization Gateway
Ecosystem: Python 3.11+, Pydantic v2, Cryptographic Audit Trails
"""
import time
import hmac
import hashlib
import json
from enum import Enum
from typing import Dict, Any, Optional
from pydantic import BaseModel, Field
class ActionRiskLevel(str, Enum):
LOW = "low" # Leseoperationen, sichere Abfragen
MEDIUM = "medium" # Entwรผrfe erstellen, PRs รถffnen
CRITICAL = "critical" # Produktivschreibvorgรคnge, Lรถschungen, Finanzen
class ToolCallIntent(BaseModel):
tool_name: str
target_resource: str
action: str
arguments: Dict[str, Any]
risk_level: ActionRiskLevel
class AgentContext(BaseModel):
agent_id: str
delegated_user_id: str
session_id: str
assigned_scopes: list[str]
class AuthorizationDecision(BaseModel):
is_authorized: bool
requires_human_approval: bool
audit_token: str
reason: Optional[str] = None
class AgentZeroTrustGateway:
"""
Vermittelt alle Tool-Aufrufe des Agenten.
Erzwingt Richtlinien, injiziert Secrets out-of-band und protokolliert Audits.
"""
def __init__(self, secret_key: str):
self._signing_key = secret_key.encode("utf-8")
self._policy_rules = {
"github.read": ActionRiskLevel.LOW,
"github.create_pr": ActionRiskLevel.MEDIUM,
"database.execute_select": ActionRiskLevel.LOW,
"database.drop_table": ActionRiskLevel.CRITICAL,
"kubernetes.delete_pod": ActionRiskLevel.CRITICAL
}
def evaluate_tool_intent(
self,
agent_ctx: AgentContext,
intent: ToolCallIntent
) -> AuthorizationDecision:
required_scope = f"{intent.tool_name}:{intent.action}"
if required_scope not in agent_ctx.assigned_scopes and "*:*" not in agent_ctx.assigned_scopes:
return AuthorizationDecision(
is_authorized=False,
requires_human_approval=False,
audit_token=self._generate_audit_hash(agent_ctx, intent, "REJECTED_SCOPE"),
reason=f"Agent besitzt nicht die erforderliche Berechtigung: {required_scope}"
)
if intent.risk_level == ActionRiskLevel.CRITICAL:
return AuthorizationDecision(
is_authorized=False,
requires_human_approval=True,
audit_token=self._generate_audit_hash(agent_ctx, intent, "PENDING_HUMAN_APPROVAL"),
reason="Destruktive Operation erfordert Freigabe durch Menschen."
)
return AuthorizationDecision(
is_authorized=True,
requires_human_approval=False,
audit_token=self._generate_audit_hash(agent_ctx, intent, "AUTHORIZED"),
reason=None
)
def execute_with_isolated_credentials(
self,
agent_ctx: AgentContext,
intent: ToolCallIntent,
decision: AuthorizationDecision
) -> Dict[str, Any]:
if not decision.is_authorized:
raise PermissionError(f"Ausfรผhrung blockiert: {decision.reason}")
ephemeral_token = self._mint_ephemeral_token(agent_ctx, intent)
execution_result = self._dispatch_to_tool(intent, ephemeral_token)
return {
"status": "success",
"audit_hash": decision.audit_token,
"data": execution_result
}
def _generate_audit_hash(self, ctx: AgentContext, intent: ToolCallIntent, status: str) -> str:
payload = f"{ctx.agent_id}:{ctx.delegated_user_id}:{intent.tool_name}:{status}:{time.time()}"
return hmac.new(self._signing_key, payload.encode("utf-8"), hashlib.sha256).hexdigest()
def _mint_ephemeral_token(self, ctx: AgentContext, intent: ToolCallIntent) -> str:
return f"ephemeral_jwt_sub_{ctx.delegated_user_id}_act_{ctx.agent_id}_exp_{int(time.time()) + 300}"
def _dispatch_to_tool(self, intent: ToolCallIntent, token: str) -> Dict[str, Any]:
return {"records_affected": 1, "executed_action": intent.action}
8. Architektur-Vergleichsmatrix
Vergleich der 4 fรผhrenden Authentifizierungsmodelle fรผr KI-Agenten:
| Dimension | 1. Statische API-Keys | 2. Token Exchange (RFC 8693) | 3. Cedar / OPA Gateway | 4. Krypto-DIDs / Agent-IDs |
|---|---|---|---|---|
| Token-Lebensdauer | Monate / Jahre (Statisch) | 5 โ 15 Min (Flรผchtig) | Kein Token-Zugriff (Vermittelt) | Sitzungsgebundene Krypto-Schlรผssel |
| Leakage-Risiko im Prompt | Extrem (Key im Prompt/Env) | Mittel (Key im Runtime-Speicher) | Null (Maskiert out-of-band) | Null (Signierte Krypto-Challenges) |
| Schadensradius | Gesamte Organisationsebene | Strikt auf Aufgabe beschrรคnkt | Deterministisch durch Code limitiert | Durch signierten Claim begrenzt |
| Widerrufs-Latenz | Manuell (Stunden/Tage) | Automatisch nach Abschluss | Sofort (Aktualisierung der Regel) | Sofort (CRL- / OCSP-Listen) |
| Human-in-the-Loop-Gates | Keine | Eingeschrรคnkt (Re-Auth-Prompt) | Nativ (Dynamische Risikotrigger) | Multisig-Bestรคtigung |
| SOC2 / ISO 27001 Reife | โ Audit nicht bestanden | โ Vollstรคndig konform | โญ Goldstandard | โญ Aufstrebender Standard |
| Implementierungsaufwand | Trivial (1 Tag) | Moderat (1โ2 Wochen) | Moderat (1โ2 Wochen) | Hoch (Spezialisierte Krypto) |
| Produktionsempfehlung | Nur Prototypen und Tests | Multi-Tenant-SaaS-Systeme | Unternehmensinterne Kernsysteme | Unternehmensรผbergreifende Agenten |
9. Compliance, Prรผfpfade & Nicht-Abstreitbarkeit
Verรคndert ein Agent Infrastrukturen oder Buchungssysteme, fordern Auditoren gerichtsfeste Nachweise. Jede Mutation muss in einem manipulationssicheren, signierten Umschlag erfasst werden:
{
"audit_version": "2026.1",
"timestamp": "2026-09-11T14:22:18.491Z",
"trace_id": "trace-8f92a11b-c741",
"actor": {
"agent_id": "agent-swe-core-09",
"delegated_user": "usr_998124_alice",
"delegation_token_fingerprint": "sha256:4b912e80..."
},
"prompt_context_hash": "sha256:d891e4a3...",
"intent": {
"tool": "aws_s3_gateway",
"action": "delete_object",
"resource": "arn:aws:s3:::internal-backups/archive-2025.tar.gz"
},
"policy_evaluation": {
"engine": "Cedar-v3",
"verdict": "ALLOW",
"evaluated_policies": ["policy_allow_backup_rotation_2026"]
},
"signature": "MEQCIG7zY8f+k7..."
}
Durch das Speichern in unverรคnderlichen WORM-Speichern (Write Once, Read Many) erfรผllen Unternehmen Vorgaben nach SOC2 Type II, HIPAA und ISO 27001 bei lรผckenloser forensischer Transparenz.
Wรคhlen Sie das Authentifizierungsmuster passend zu Ihren Anforderungen:
- Fรผr Multi-Tenant-SaaS-Agenten im Nutzerauftrag: Verwenden Sie OAuth 2.0 Token Exchange (RFC 8693) mit flรผchtigen Tokens.
- Fรผr interne Unternehmensautomatisierung auf sensiblen APIs: Setzen Sie auf Policy-as-Code-Gateways (Cedar/OPA) mit Secret-Maskierung.
- Fรผr destruktive oder finanzielle Kernprozesse: Integrieren Sie Just-In-Time Human Approval Gates via LangGraph.
- Fรผr die Ausfรผhrung von KI-generiertem Fremdcode: Isolieren Sie Prozesse in einer E2B MicroVM Sandbox.
Relevante IAM- & Agent-Infrastruktur-Tools auf AgDex.ai
ใ2026ๅนด็ใ่ชๅพๅAIใจใผใธใงใณใใฎ่ช่จผใจๆๅฐๆจฉ้IAM๏ผMCPใใผใซๆจฉ้ๅ้ขใปใใผใฏใณๅงไปปใฎๅฎๅ จๅฎ่ฃ ใฌใคใ
2026ๅนดใ่ชๅพๅAIใจใผใธใงใณใใฏใฝใผในใณใผใใฎไฟฎๆญฃใๆฌ็ชใใผใฟใใผในใฎ็ งไผใใฏใฉใฆใใคใณใใฉใฎ่ชๅๅคๆดใๆ ใๅญๅจใจใชใใพใใใใใใใๅคใใฎใจใณใฟใผใใฉใคใบๅฎ่ฃ ใงใฏไพ็ถใจใใฆ็ฎก็่ ๆจฉ้ใๆใค้็APIใญใผใ็ฐๅขๅคๆฐใซใใฟๆธใใใใฆใใใ้ๆฅใใญใณใใใคใณใธใงใฏใทใงใณใซใใๅฃๆป ็ใชๆผๆดฉใชในใฏใซๆใใใฆใใพใใๆฌ็จฟใงใฏZero-Trust่ช่จผใOAuth 2.0 Token Exchange (RFC 8693)ใPolicy-as-Codeใฒใผใใฆใงใคใซใใ้ฒๅพกใขใผใญใใฏใใฃใ่งฃ่ชฌใใพใใ
- 1. ่ฆ็ดใจใขใผใญใใฏใใฃๅบๆฌๅๅ
- 2. ่ชๅพๅAIใจใผใธใงใณใใฎใขใคใใณใใฃใใฃๅฑๆฉ
- 3. ้็APIใญใผ้็จใฎๆง้ ็ๆฌ ้ฅ
- 4. OAuth 2.0 Token Exchange (RFC 8693) ใฎๅฎ่ฃ
- 5. Model Context Protocol (MCP) ใฎๅฎๅ จใช้็จ
- 6. Cedar / OPA ใซใใ Policy-as-Code ้ฒๅพก
- 7. PythonใซใใZero-Trustใฒใผใใฆใงใคๅฎ่ฃ
- 8. ใขใผใญใใฏใใฃๆฏ่ผใใใชใฏใน
- 9. ็ฃๆปใญใฐใปๅฆ่ช้ฒๆญขใปSOC2/ISO้ฉๅๆง
- 10. ใขใผใญใใฏใใฃ้ธๅฎๆ้ใจ้ข้ฃใใผใซ
1. ่ฆ็ดใจใขใผใญใใฏใใฃๅบๆฌๅๅ
- LLMใฎใใญใณใใใณใณใใญในใๅ ใซ็ใฎBearer Tokenใ็ตถๅฏพใซๆธกใใชใใใจใ ใจใผใธใงใณใใซใฏๆฝ่ฑกๅใใใๆฉ่ฝ่ญๅฅๅญใฎใฟใๆฑใใๅฎ้ใฎ่ช่จผๆ ๅ ฑใฎ่งฃๆฑบใปๆณจๅ ฅใฏ้้ขใใใTool Broker Gateway็ต็ฑใงOut-of-band๏ผๅธฏๅๅค๏ผใซ่กใใพใใ
- ใฆใผใถใผๅงไปปใซใฏOAuth 2.0 Token Exchange (RFC 8693)ใๆก็จใใใใจใ ใจใผใธใงใณใใซ้็ใช็นๆจฉใฏใฌใใณใทใฃใซใๆธกใใฎใงใฏใชใใใฆใผใถใผใฎใขใฏใปในใใผใฏใณใ็ญๅฝ๏ผๆๅนๆ้15ๅๆชๆบ๏ผใใคๆๅฐในใณใผใใฎๅงไปปใใผใฏใณใธใจใชใณใใใณใๅคๆใใพใใ
- ่ช็ถ่จ่ชใงใฏใชใPolicy-as-Code๏ผCedarใพใใฏOPA๏ผใงไบๅๆค่จผใใใใจใ ใทในใใ ใใญใณใใๅ ใฎ่ช็ถ่จ่ชใซใผใซ๏ผใๆฌ็ชDBใฎใใผใฟใๆถใใฆใฏใชใใชใใ๏ผใฏ่ฑ็ๆปๆใซใใๅฎนๆใซ่ฟๅใใใพใใ่ชๅฏๅคๅฎใฏLLMใฎๅค้จใงๆฑบๅฎ่ซ็ใซๅฆ็ใใใชใใใฐใชใใพใใใ
- ็ ดๅฃ็ๅคๆดใ้ซใชในใฏๅฆ็ใซใฏJust-In-Time (JIT)ใฎไบบ้ๆฟ่ชใฒใผใใ่จญใใใใจใ ใใผใฟใใผในในใญใผใใฎๅคๆดใmainใใฉใณใใธใฎใใใทใฅใ้้ใชใฉใฎๅฆ็ใฏใจใผใธใงใณใใฎๅฎๅ จ่ชๅพๅฎ่กใใ้คๅคใใ็ขบ่ชในใใใใๅฟ ้ ใจใใพใใ
2026ๅนดใ่ชๅพๅAIใจใผใธใงใณใใฏๅๅ็ใชใณใผใ่ฃๅฎใ่ถ ใใๆฌๆ ผ็ใชใฟในใฏ่ชๅๅใฏใผใซใผใธใจ้ฒๅใใพใใใOpenHandsใซใใGitHubใคใทใฅใผ่งฃๆฑบใModel Context Protocol (MCP)ใไปใใใฏใฉใฆใใคใณใใฉๆไฝใE2B Sandboxๅ ใงใฎPythonใณใผใๅฎ่กใชใฉใไผๆฅญใทในใใ ใจ้ฃๆบใใใจใผใธใงใณใใซใฏๅ ็ขใช่ช่จผๅบ็คใไธๅฏๆฌ ใงใใ
2. ่ชๅพๅAIใจใผใธใงใณใใฎใขใคใใณใใฃใใฃๅฑๆฉ
ๅพๆฅใฎIAMใฏใไบบ้ใฎๅฏพ่ฉฑ็ใฆใผใถใผ๏ผMFA/SSO่ช่จผ๏ผใใจใๆฑบๅฎ่ซ็ใชใใใฏใจใณใใตใผใใน๏ผmTLSใใตใผใในใขใซใฆใณใ๏ผใใฎ2ๆฅตใฎใฟใๅๆใจใใฆใใพใใใใใใใ่ชๅพๅใจใผใธใงใณใใฏใใฎๅๆใๆ นๅบใใ็ ดๅฃใใพใ๏ผ
ๅพๆฅใฎใใคใฏใญใตใผใใน้ๅผใณๅบใ:
[ๆฑบๅฎ่ซ็ใชService A] โโโโโโ ้็APIใชใฏใจในใ โโโโโโโถ [ไฟ่ญทใใใService B]
่ชๅพๅAIใจใผใธใงใณใใฎๅผใณๅบใๆง้ :
[ไบบ้ใฎใฆใผใถใผ] โโโถ [LLMใจใผใธใงใณใๅบ็ค] โโโถ [้ๆฑบๅฎ่ซ็ใชๆจ่ซใปๆๆๆฑบๅฎใซใผใ]
โ
(ๆชๆค่จผใฎWebใใผใฟ / ๆชๆใใPRใณใผใใฎ่ชญใฟ่พผใฟ)
โ
โผ
[้ๆฅใใญใณใใใคใณใธใงใฏใทใงใณๆปๆ]
โ
โผ
[ไธๆญฃใชใใผใซๅฎ่กใฎ่ฉฆ่ก๏ผ]
ใจใผใธใงใณใใฏไบบ้ใฎใๅงไปปไปฃ็ไบบ๏ผIntermediate Delegate๏ผใใจใใฆๆฏใ่ใใพใใใๅ็ใชใใผใซ้ธๆใ่กใใใๅไฝใไบๅใซไบๆธฌใงใใพใใใใจใผใธใงใณใใซๅผทๅใชๅบๅฎใตใผใในใขใซใฆใณใใไปไธใใใจใใใญใณใใใคใณใธใงใฏใทใงใณใๅใใ็ฌ้ใซใ้จใใใไปฃ็ไบบ๏ผConfused Deputy๏ผใใจใชใใ็คพๅ ๅ จๅใไธๆญฃๆไฝใใใใใฏใใขใซๅค่ฒใใพใใ
3. ้็APIใญใผ้็จใฎๆง้ ็ๆฌ ้ฅ
ใณใณใใใฎ็ฐๅขๅคๆฐใซ้็APIใญใผใๆธกใ้็จใฏใๆฌ็ช็ฐๅขใซใใใฆไปฅไธใฎ4ใคใฎ่ดๅฝ็ใช่ๅผฑๆงใๆใใพใ๏ผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ใจใผใธใงใณใใซใใใ้็ใฏใฌใใณใทใฃใซใฎ็ ดๅฃ็ๅฝฑ้ฟ็ฏๅฒ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 1. ๆ่่ช่ญใฎๅฎๅ
จใชๆฌ ๅฆ: GitHub PATใฏใใใญใฅใกใณใใฎ่ชคๅญไฟฎๆญฃPRใใจใmainใใฉใณใใธใฎ โ
โ ็ ดๅฃ็ๅผทๅถใใใทใฅใใๅบๅฅใงใใใๅไธใฎๅผทใๆจฉ้ใงๅฎ่กใใฆใใพใใ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 2. ็ก้ใฎๆๅนๆ้: ้็ใญใผใฏๆๅใญใผใใผใทใงใณใพใงๆไน
็ใซๆๅนใงใใใใใๆผๆดฉใใ โ
โ ใใผใฏใณใใญใฐใซๆฎๅญใใใพใพๆฐใถๆ้ๆพ็ฝฎใใใๅฑ้บใใใใ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 3. ๆจฉ้ในใณใผใใฎ็ฒใ: ๅคใใฎSaaS APIใฏใใณใกใณใๆ็จฟใใซๅฟ
่ฆใชๆจฉ้ใไปไธใใใจใ โ
โ ใใญใธใงใฏใๅ
จไฝใฎๅ้คๆจฉ้ใพใงๆฑใๅใใใงไธใใฆใใพใใ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 4. ใณใณใใญในใใใใฎๆผๆดฉ: ใใผใฏใณใLLMใฎใใญใณใใๅ
ใซๆธกใใใๅ ดๅใใใญใณใใๅๆง็ฏ โ
โ ๆปๆใซใใฃใฆๅค้จใธ็ใพใใใชในใฏใๆฐๅญฆ็ใซๆ้คใงใใชใใ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
LLMใฎใใญใณใใใณใณใใญในใใฆใฃใณใใฆใซๅ ฅๅใใใ็งๅฏ้ตใใใผใฏใณใฏใใใฎ็ฌ้ใซๆผๆดฉใใใใฎใจ่ฆๅใใชใใใฐใชใใพใใใไผๆฅญๅใใขใผใญใใฏใใฃใงใฏใใฏใฌใใณใทใฃใซใๅค้จใฒใผใใฆใงใคใฎไฟ่ญทใกใขใชๅ ใฎใฟใซไฟๆใใใใจใ้ๅใงใใ
4. OAuth 2.0 Token Exchange (RFC 8693) ใฎๅฎ่ฃ
ๅฎๅ จใชๅงไปปใๅฎ็พใใใใใๅ ้ฒ็ใชใจใณใฟใผใใฉใคใบใฏOAuth 2.0 Token Exchange (RFC 8693)ใๆก็จใใฆใใพใใใฟในใฏ้ๅงๆใซใฆใผใถใผใฎไธปใใผใฏใณใ็ญๅฝใปๆๅฐในใณใผใใฎๅงไปปใใผใฏใณใธใจไบคๆใใพใ๏ผ
โโโโโโโโโโโโ 1. ใฟในใฏ้ๅงๆ็คบ ("Q3่ฒกๅๅ ฑๅๆธใๅๆ")
โ ใฆใผใถใผ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโ โ
โ โผ
โ 2. ใใฉใคใใชOAuthใใผใฏใณ โโโโโโโโโโโโโโโโโโโโโโ
โ (Subject Token: ใฆใผใถใผ่ญๅฅๅญ) โ ใจใผใธใงใณใใณใข โ
โผ โ (ใชใผใฑในใใฌใผใฟ) โ
โโโโโโโโโโโโโโโโ โโโโโโโโโโโฌโโโโโโโโโโโ
โ ใจใณใฟใผ โ โ
โ ใใฉใคใบIdP โโโโโ 3. RFC 8693 Token Exchange ใชใฏใจในใ โโโโโโโโโโโโ
โ (Okta/Auth0) โ - Subject Token: ใฆใผใถใผใฎใขใฏใปในใใผใฏใณ
โโโโโโโโฌโโโโโโโโ - Actor Token: ใจใผใธใงใณใใฎใตใผใในใใชใณใทใใซ
โ - ่ฆๆฑในใณใผใ: ["finance.reports:read"]
โ - ๆๅนๆ้ (TTL): 300็ง
โผ
4. ในใณใผใ็ธฎๅฐๆธใฟใฎ็ญๅฝใใผใฏใณใ็บ่ก
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ใใผใซใใญใผใซใผใฒใผใใฆใงใค โ
โ โโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ ใใชใทใผใจใณใธใณ โโโโโโโถโ ่ช่จผๆ
ๅ ฑใคใณใธใงใฏใฟ โ โ
โ โ (AWS Cedar) โ โโโโโโโโโโโโฌโโโโโโโโโโโโ โ
โ โโโโโโโโโโโโโโโโโโโโโโโโ โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโ
โ
โ 5. ่ช่จผไปใใใผใซๅผใณๅบใ
โผ
โโโโโโโโโโโโโโโโโโโโโ
โ ๅฏพ่ฑกAPI / MCP โ
โ (่ชญใฟๅใๅฐ็จๆจฉ้)โ
โโโโโโโโโโโโโโโโโโโโโ
ใฆใผใถใผ๏ผsub๏ผใจใจใผใธใงใณใๅฎไฝ๏ผact๏ผใ็ดใฅใใ่คๅใใผใฏใณใ็ๆใใใใจใงใๆนใใไธ่ฝใช็ฃๆป่จผ่ทกใ็ถญๆใใใพใใใใผใฏใณใฏๅฏพ่ฑกใฎใตใๆไฝใซ้ๅฎใใใๆฐๅใง่ชๅๅคฑๅนใใพใใ
5. Model Context Protocol (MCP) ใฎๅฎๅ จใช้็จ
Model Context Protocol (MCP)ใฏใจใผใธใงใณใใใผใซใฎๆจๆบใคใณใฟใผใใงใผในใงใใใๆฌ็ช็ฐๅขใงใฎๅฎๅ จใช้็จใฎใใใซๆฌกใฎ3ๅๅใๅพนๅบใใพใ๏ผ
- ๅไธ่ฒฌๅใฎๆฉ่ฝในใณใผใๅฎฃ่จ: ๆฑ็จใทใงใซ๏ผ
system.exec_bash๏ผใๅ ฌ้ใใใgithub.issue.add_commentใฎใใใซๅ ทไฝ็ใช้ๅฎใใผใซใๅฎฃ่จใใใ - ๅธฏๅๅคใฎใทใผใฏใฌใใใในใญใณใฐ: ใจใผใธใงใณใใซใฏ
vault://creds/staging_dbใฎใใใชๅ็ งURIใฎใฟใๆธกใใTool Brokerใไธญ็ถๆใซๅ ้จTLS็ต็ฑใงๅฎใใผใฏใณใๆณจๅ ฅใใใ - Just-In-Time (JIT) ไบบ้ๆฟ่ชใฒใผใ: ่ณ็ฃๅฃฒ่ฒทใใใผใใซๅ้คใๅผทๅถใใใทใฅใชใฉใฎ้ๅคงๅฆ็ใงใฏๅฎ่กใไธๆๅๆญขใใSlackใWeb็ป้ข็ต็ฑใง็ฎก็่ ใฎ็ฝฒๅๆฟ่ชใๅพ ๆฉใใใ
6. Cedar / OPA ใซใใ Policy-as-Code ้ฒๅพก
่ช็ถ่จ่ชใซใใใใญใณใใๅถๅพกใฏๆชๆใใๆปๆใซๅฏพใใฆ่ๅผฑใงใใ่ชๅฏๅคๅฎใฏAWS CedarใOpen Policy Agent (OPA)ใชใฉใฎๆฑบๅฎ่ซ็ใจใณใธใณใซใใฃใฆๅฎ่กใใใพใ๏ผ
// ใณใผใใฃใณใฐใจใผใธใงใณใๅใ AWS Cedar ใใชใทใผๅฎ็พฉไพ
// 1. ๆๅฎใใใใจใณใธใใขใชใณใฐใชใใธใใชใฎ่ชญใฟๅใใปใในใใ่จฑๅฏ
permit (
principal in Role::"CodingAgent",
action in [Action::"clone_repo", Action::"read_file", Action::"run_tests"],
resource in Repository::"Engineering"
);
// 2. ๆ
ๅฝJiraใใฑใใใๆๅนใชๅ ดๅใฎใฟใใฉใณใไฝๆใจPRไฝๆใ่จฑๅฏ
permit (
principal in Role::"CodingAgent",
action in [Action::"create_branch", Action::"open_pull_request"],
resource in Repository::"Engineering"
)
when {
context.has_valid_jira_ticket == true &&
context.ticket_assignee == principal.delegated_user
};
// 3. ๅณๆ ผใช็ฆๆญขใซใผใซ๏ผไฟ่ญทใใฉใณใใธใฎ็ดๆฅใใใทใฅใฏไธๅ็ฆๆญข
forbid (
principal,
action in [Action::"git_push_direct", Action::"delete_repository"],
resource
)
when {
resource.branch in ["main", "master", "release/*"]
};
Tool BrokerใฏCedarใใชใทใผใ2ใใช็งๆชๆบใง่ฉไพกใใไธๆญฃใชใชใฏใจในใใใใฑใใ้ๅบๅใซ้ฎๆญใใพใใ
7. PythonใซใใZero-Trustใฒใผใใฆใงใคๅฎ่ฃ
ไปฅไธใฎPythonใณใผใใฏใใใผใซใฎๆๅณๆค่จผใLLMใธใฎ่ช่จผๆ ๅ ฑ้้็คบใใใใณๆๅท็ฝฒๅไปใ็ฃๆปใญใฐใฎ็ๆใ่กใๆฌ็ชๅใๅฎ่ฃ ใงใ๏ผ
"""
Zero-Trust Agent Authorization Gateway
Ecosystem: Python 3.11+, Pydantic v2, Cryptographic Audit Trails
"""
import time
import hmac
import hashlib
import json
from enum import Enum
from typing import Dict, Any, Optional
from pydantic import BaseModel, Field
class ActionRiskLevel(str, Enum):
LOW = "low" # ่ชญใฟๅใๆไฝใๅฎๅ
จใชๆค็ดข
MEDIUM = "medium" # ใใฉใใไฝๆใPRใชใผใใณใในใใผใธใณใฐๆธใ่พผใฟ
CRITICAL = "critical" # ๆฌ็ชๆธใ่พผใฟใๅ้คใ่ณ้็งปๅ
class ToolCallIntent(BaseModel):
tool_name: str
target_resource: str
action: str
arguments: Dict[str, Any]
risk_level: ActionRiskLevel
class AgentContext(BaseModel):
agent_id: str
delegated_user_id: str
session_id: str
assigned_scopes: list[str]
class AuthorizationDecision(BaseModel):
is_authorized: bool
requires_human_approval: bool
audit_token: str
reason: Optional[str] = None
class AgentZeroTrustGateway:
"""
ใจใผใธใงใณใใฎใใผใซๅผใณๅบใใไปฒไปใใใฒใผใใฆใงใคใ
ใใชใทใผ่ฉไพกใๅธฏๅๅคใใผใฏใณๆณจๅ
ฅใๆนใใ้ฒๆญข็ฃๆปใญใฐใๅผทๅถใ
"""
def __init__(self, secret_key: str):
self._signing_key = secret_key.encode("utf-8")
self._policy_rules = {
"github.read": ActionRiskLevel.LOW,
"github.create_pr": ActionRiskLevel.MEDIUM,
"database.execute_select": ActionRiskLevel.LOW,
"database.drop_table": ActionRiskLevel.CRITICAL,
"kubernetes.delete_pod": ActionRiskLevel.CRITICAL
}
def evaluate_tool_intent(
self,
agent_ctx: AgentContext,
intent: ToolCallIntent
) -> AuthorizationDecision:
required_scope = f"{intent.tool_name}:{intent.action}"
if required_scope not in agent_ctx.assigned_scopes and "*:*" not in agent_ctx.assigned_scopes:
return AuthorizationDecision(
is_authorized=False,
requires_human_approval=False,
audit_token=self._generate_audit_hash(agent_ctx, intent, "REJECTED_SCOPE"),
reason=f"ใจใผใธใงใณใใซๅฟ
่ฆใชๆจฉ้ในใณใผใใใใใพใใ: {required_scope}"
)
if intent.risk_level == ActionRiskLevel.CRITICAL:
return AuthorizationDecision(
is_authorized=False,
requires_human_approval=True,
audit_token=self._generate_audit_hash(agent_ctx, intent, "PENDING_HUMAN_APPROVAL"),
reason="็ ดๅฃ็ใช้ซใชในใฏๆไฝใฎใใไบบ้ใฎๆฟ่ชใๅฟ
่ฆใงใใ"
)
return AuthorizationDecision(
is_authorized=True,
requires_human_approval=False,
audit_token=self._generate_audit_hash(agent_ctx, intent, "AUTHORIZED"),
reason=None
)
def execute_with_isolated_credentials(
self,
agent_ctx: AgentContext,
intent: ToolCallIntent,
decision: AuthorizationDecision
) -> Dict[str, Any]:
if not decision.is_authorized:
raise PermissionError(f"ๅฎ่กใๆๅฆใใใพใใ: {decision.reason}")
ephemeral_token = self._mint_ephemeral_token(agent_ctx, intent)
execution_result = self._dispatch_to_tool(intent, ephemeral_token)
return {
"status": "success",
"audit_hash": decision.audit_token,
"data": execution_result
}
def _generate_audit_hash(self, ctx: AgentContext, intent: ToolCallIntent, status: str) -> str:
payload = f"{ctx.agent_id}:{ctx.delegated_user_id}:{intent.tool_name}:{status}:{time.time()}"
return hmac.new(self._signing_key, payload.encode("utf-8"), hashlib.sha256).hexdigest()
def _mint_ephemeral_token(self, ctx: AgentContext, intent: ToolCallIntent) -> str:
return f"ephemeral_jwt_sub_{ctx.delegated_user_id}_act_{ctx.agent_id}_exp_{int(time.time()) + 300}"
def _dispatch_to_tool(self, intent: ToolCallIntent, token: str) -> Dict[str, Any]:
return {"records_affected": 1, "executed_action": intent.action}
8. ใขใผใญใใฏใใฃๆฏ่ผใใใชใฏใน
ไธป่ฆใช4ใคใฎใจใผใธใงใณใ่ช่จผใขใใญใผใใฎๆฏ่ผ๏ผ
| ๆฏ่ผ่ปธ | 1. ้็APIใญใผ๏ผๆงๆฅๆนๅผ๏ผ | 2. OAuth Token Exchange | 3. Cedar / OPA ใฒใผใใฆใงใค | 4. ๆๅทDIDs / ใจใผใธใงใณใID |
|---|---|---|---|---|
| ใฏใฌใใณใทใฃใซๆๅนๆ้ | ๆฐใถๆใๆฐๅนด๏ผ้็๏ผ | 5ใ15ๅ๏ผ็ญๅฝ๏ผ | ใผใญ้ฒๅบ๏ผใฒใผใใฆใงใคไปฒไป๏ผ | ใปใใทใงใณ้ฃๅใฎ้ๅฏพ็งฐๆๅท้ต |
| ใใญใณใใๆผๆดฉใชในใฏ | ๆฅตๅคง๏ผใใญใณใใใป็ฐๅขๅคๆฐๅ ๏ผ | ไธญ็จๅบฆ๏ผใฉใณใฟใคใ ใกใขใชๅ ๏ผ | ใผใญ๏ผๅธฏๅๅคใในใญใณใฐ๏ผ | ใผใญ๏ผๆๅท็ฝฒๅใใฃใฌใณใธ๏ผ |
| ไบๆ ๆใฎ่ขซๅฎณ็ฏๅฒ | ใฏใผใฏในใใผในๅ จไฝใซๆณขๅ | ๅงไปปใใใ็นๅฎใฟในใฏใฎใฟ | ๆฑบๅฎ่ซ็ใใชใทใผใงๅณๆ ผๅถ้ | ๆค่จผๅฏ่ฝใฏใฌใใณใทใฃใซใซ้ๅฎ |
| ๅคฑๅนใฌใคใใณใท | ๆๅ๏ผๆฐๆ้ใๆฐๆฅ๏ผ | ใฟในใฏๅฎไบๆใซ่ชๅๅคฑๅน | ๅณๆ๏ผใใชใทใผๆดๆฐใงๅๆ ๏ผ | ๅณๆ๏ผCRL / OCSPใชในใ๏ผ |
| ไบบ้ๆฟ่ชใฒใผใ | ใชใ | ้ๅฎ็๏ผๅ่ช่จผใใญใณใใ๏ผ | ใใคใใฃใ๏ผใชในใฏ้ฃๅๅ๏ผ | ใใซใใทใฐ็ฝฒๅๆค่จผ |
| SOC2 / ISO 27001 ้ฉๅๆง | โ ็ฃๆปไธ้ฉๅ | โ ๅฎๅ จ้ฉๅ | โญ ใดใผใซใในใฟใณใใผใ | โญ ๆฌกไธไปฃๆจๆบ |
| ๅฎ่ฃ ้ฃๆๅบฆ | ๆฅตๅฐ๏ผ1ๆฅ๏ผ | ไธญ็จๅบฆ๏ผ1ใ2้ฑ้๏ผ | ไธญ็จๅบฆ๏ผ1ใ2้ฑ้๏ผ | ้ซ๏ผๅฐ้็ใชๆๅท่จญ่จ๏ผ |
| ๆจๅฅจๆฌ็ชใฆใผในใฑใผใน | ใใญใใฟใคใใปๆค่จผใฎใฟ | ใใซใใใใณใSaaS้ฃๆบ | ไผๆฅญๅ ๅบๅนนใทในใใ ่ชๅๅ | ไผๆฅญ้ใ่ทจใ่ชๅพใจใผใธใงใณใ |
9. ็ฃๆปใญใฐใปๅฆ่ช้ฒๆญขใปSOC2/ISO้ฉๅๆง
ใจใผใธใงใณใใใคใณใใฉใๅคๆดใใ้ใ็ฃๆปไบบใฏใ่ชฐใ่จฑๅฏใใใฎใใใใฆใผใถใผใฎๆๅณ้ใใใใๆค่จผใใพใใๅใขใฏใทใงใณใฏๆๅท็ฝฒๅไปใใฎไธๅค็ฃๆปใจใณใใญใผใใจใใฆ่จ้ฒใใใพใ๏ผ
{
"audit_version": "2026.1",
"timestamp": "2026-09-11T14:22:18.491Z",
"trace_id": "trace-8f92a11b-c741",
"actor": {
"agent_id": "agent-swe-core-09",
"delegated_user": "usr_998124_alice",
"delegation_token_fingerprint": "sha256:4b912e80..."
},
"prompt_context_hash": "sha256:d891e4a3...",
"intent": {
"tool": "aws_s3_gateway",
"action": "delete_object",
"resource": "arn:aws:s3:::internal-backups/archive-2025.tar.gz"
},
"policy_evaluation": {
"engine": "Cedar-v3",
"verdict": "ALLOW",
"evaluated_policies": ["policy_allow_backup_rotation_2026"]
},
"signature": "MEQCIG7zY8f+k7..."
}
็ฝฒๅใใใใจใณใใญใผใใๆนใใ้ฒๆญข๏ผWORM: Write Once, Read Many๏ผในใใฌใผใธใซๆธใ่พผใใใจใงใSOC2 Type IIใHIPAAใISO 27001ๅบๆบใๆบใใใชใใๅฎๅ จใชใใฉใฌใณใธใใฏ่ฟฝ่ทกใๅฏ่ฝใซใชใใพใใ
ใทในใใ ใฎ้็จๅข็ใซๅฟใใฆ้ฉๅใช่ช่จผใใฟใผใณใ้ธๆใใฆใใ ใใ๏ผ
- ใจใณใใฆใผใถใผใฎไปฃ็ใงๅใใใซใใใใณใSaaSใจใผใธใงใณใ๏ผ็ญๅฝใใผใฏใณใซใใOAuth 2.0 Token Exchange (RFC 8693)ใๅฐๅ ฅใ
- ๆฉๅฏAPIใซใขใฏใปในใใไผๆฅญๅ ่ชๅๅใจใผใธใงใณใ๏ผใทใผใฏใฌใใใในใญใณใฐใๅใใPolicy-as-Codeใฒใผใใฆใงใค๏ผCedar/OPA๏ผใ้ ๅใ
- ้ซใชในใฏใช็ ดๅฃ็ๆไฝใ้่ๅๅผ๏ผLangGraphใๆดป็จใใJust-In-Timeไบบ้ๆฟ่ชใฒใผใใ่จญ็ฝฎใ
- ็ๆใณใผใใๅฎ่กใใใณใผใใฃใณใฐใจใผใธใงใณใ๏ผE2B MicroVM Sandboxๅ ใงๅฎๅ จใซ้้ขๅฎ่กใ
AgDex.ai ใง้ข้ฃใใIAMใใใณใจใผใธใงใณใๅบ็คใใผใซใๆขใ
ุงูู ุตุงุฏูุฉ ูุฅุฏุงุฑุฉ ุงูุตูุงุญูุงุช ุงูุฏููุง (Least-Privilege IAM) ููููุงุก ุงูุฐูุงุก ุงูุงุตุทูุงุนู ูู 2026: ุชุฃู ูู ุจุฑูุชูููู MCP ูุจูุงูุงุช ุงุนุชู ุงุฏ ุงูุฃุฏูุงุช ูุชูููุถ ุงูุฑู ูุฒ
ูู ุนุงู 2026ุ ุจุงุช ูููุงุก ุงูุฐูุงุก ุงูุงุตุทูุงุนู ูููุฐูู ุงูุฃููุงุฏ ุงูุจุฑู ุฌูุฉ ููุณุชุนูู ูู ููุงุนุฏ ุงูุจูุงูุงุช ุงูุฅูุชุงุฌูุฉ ููุทูููู ุนู ููุงุช ุงููุดุฑ ุงูุณุญุงุจู ุฐุงุชูุงู. ูู ุน ุฐููุ ูุง ุชุฒุงู ู ุนุธู ุงูุจูู ุงูู ุคุณุณูุฉ ุชุนุชู ุฏ ุนูู ู ูุงุชูุญ API ุซุงุจุชุฉ ุฐุงุช ุตูุงุญูุงุช ูุงู ูุฉุ ู ู ุง ูุนุฑุถ ุงูุจููุฉ ุงูุชุญุชูุฉ ููุฌู ุงุช ุญูู ุงูุชุนููู ุงุช ุบูุฑ ุงูู ุจุงุดุฑุฉ (Indirect Prompt Injection). ูุณุชุนุฑุถ ูุฐุง ุงูุฏููู ุงูู ุนู ุงุฑู ุฃุณุณ ุชูููุถ Zero-Trust ูุชุจุงุฏู ุฑู ูุฒ OAuth 2.0 (RFC 8693) ูุจูุงุจุงุช ุงูุณูุงุณุฉ ุงูุจุฑู ุฌูุฉ (Policy-as-Code).
- 1. ู ูุฎุต ุณุฑูุน ูุงูู ุจุงุฏุฆ ุงูุฃุณุงุณูุฉ
- 2. ุฃุฒู ุฉ ูููุฉ ูููุงุก ุงูุฐูุงุก ุงูุงุตุทูุงุนู
- 3. ูุดู ู ูุงุชูุญ API ุงูุซุงุจุชุฉ ูู ุจูุฆุงุช ุงููููุงุก
- 4. ุชูููุถ ุงูุฑู ูุฒ ุนุจุฑ OAuth (RFC 8693)
- 5. ุชุฃู ูู ุจุฑูุชูููู ุณูุงู ุงููู ูุฐุฌ (MCP)
- 6. ุงูุณูุงุณุฉ ูููุฏ ุจุฑู ุฌู ุนุจุฑ Cedar ู OPA
- 7. ุจูุงุก ุจูุงุจุฉ Zero-Trust ุจูุบุฉ ุจุงูุซูู
- 8. ู ุตูููุฉ ุงูู ูุงุฑูุฉ ุงูู ุนู ุงุฑูุฉ ุงูุดุงู ูุฉ
- 9. ุงูุงู ุชุซุงู ูุณุฌูุงุช ุงูุชุฏููู ูุนุฏู ุงูุฅููุงุฑ
- 10. ุฅุทุงุฑ ุงุชุฎุงุฐ ุงููุฑุงุฑ ูุงูุฃุฏูุงุช ุฐุงุช ุงูุตูุฉ
1. ู ูุฎุต ุณุฑูุน ูุงูู ุจุงุฏุฆ ุงูู ุนู ุงุฑูุฉ ุงูุฃุณุงุณูุฉ
- ูุง ุชู ุฑุฑ ุฃุจุฏุงู ุฑู ูุฒ Bearer ุงูุตุฑูุญุฉ ุฅูู ูุงูุฐุฉ ุณูุงู ุงูุชูุฌูู (Prompt) ููู ูุฐุฌ LLM. ูุฌุจ ุฃู ูุชุนุงู ู ุงููููู ููุท ู ุน ู ุฑุงุฌุน ุชุฌุฑูุฏูุฉ ูููุฏุฑุงุชุ ููุฌุจ ุฃู ุชุชู ุงูู ุตุงุฏูุฉ ูุญูู ุจูุงูุงุช ุงูุงุนุชู ุงุฏ ูู ูุทุงู ู ุนุฒูู ุฎุงุฑุฌ ุจูุฆุฉ ุงููู ูุฐุฌ ุนุจุฑ ุจูุงุจุฉ ูุณูุทุฉ (Tool Broker Gateway).
- ุงุนุชู ุฏ ู ุนูุงุฑ ุชุจุงุฏู ุฑู ูุฒ OAuth 2.0 (RFC 8693) ููุชูููุถ. ุจุฏูุงู ู ู ุชุฒููุฏ ุงููููู ุจู ูุงุชูุญ ูุตูู ุซุงุจุชุฉุ ูู ุจุชุจุงุฏู ุฑู ุฒ ูุตูู ุงูู ุณุชุฎุฏู ุจุฑู ุฒ ุชูููุถ ู ุคูุช ุนุงุจุฑ ุฐู ูุทุงู ุตูุงุญูุงุช ู ููุต ูุตูุงุญูุฉ ุฒู ููุฉ ุตุงุฑู ุฉ (ุฃูู ู ู 15 ุฏูููุฉ).
- ุงูุฑุถ ุงูุณูุงุณุฉ ูููุฏ (Cedar ุฃู OPA) ูุจู ุงูุชูููุฐ. ุงูุชุนููู ุงุช ุงููุตูุฉ ุจุงููุบุฉ ุงูุทุจูุนูุฉ ("ูุฑุฌู ุนุฏู ุญุฐู ุงูุฌุฏุงูู ุงูุฅูุชุงุฌูุฉ") ูู ุฅุฑุดุงุฏุงุช ูุงุจูุฉ ูููุณุฑ ุนุจุฑ ูุฌู ุงุช ุงูุญูู. ูุฌุจ ุฃู ุชููู ูุฑุงุฑุงุช ุงูู ูุญ ูุทุนูุฉ ูุญุชู ูุฉ ุฎุงุฑุฌ ุงููู ูุฐุฌ ุชู ุงู ุงู.
- ูุนูู ุจูุงุจุงุช ุงูู ูุงููุฉ ุงูุจุดุฑูุฉ ุงูููุฑูุฉ (Just-In-Time Approval Gates) ููุนู ููุงุช ุนุงููุฉ ุงูู ุฎุงุทุฑ ู ุซู ุชุนุฏูู ููุงูู ููุงุนุฏ ุงูุจูุงูุงุชุ ุฃู ุงูุฅุฑุณุงู ุงูู ุจุงุดุฑ ูููุฑูุน ุงูุฑุฆูุณูุฉ (Main)ุ ุฃู ุงูู ุนุงู ูุงุช ุงูู ุงููุฉ.
ูู ุนุงู 2026ุ ุชุญูู ูููุงุก ุงูุฐูุงุก ุงูุงุตุทูุงุนู ู ู ุฃุฏูุงุช ุฅูู ุงู ุชููุงุฆู ุจุณูุทุฉ ุฅูู ุนู ุงู ุฑูู ููู ู ุณุชูููู. ูุณูุงุก ูุงู ุฐูู ูุญู ุงูู ุดููุงุช ุงูุจุฑู ุฌูุฉ ุนุจุฑ OpenHandsุ ุฃู ุงูุชูุงุนู ู ุน ุงูุณุญุงุจุฉ ุนุจุฑ Model Context Protocol (MCP)ุ ุฃู ุชูููุฐ ูุตูุต ุจุฑู ุฌูุฉ ูู ุจูุฆุฉ E2B Sandboxุ ุชุชุทูุจ ูุฐู ุงูุฃูุธู ุฉ ูุตููุงู ู ูุซูุงู ูู ุญูู ุงู ููุจูุงูุงุช ุงูู ุคุณุณูุฉ.
2. ุฃุฒู ุฉ ูููุฉ ูููุงุก ุงูุฐูุงุก ุงูุงุตุทูุงุนู ุงูู ุณุชูููู
ุชู ุชุตู ูู ุฃูุธู ุฉ ุฅุฏุงุฑุฉ ุงููููุฉ ูุงููุตูู (IAM) ุงูุชูููุฏูุฉ ุญูู ุตูููู ููุท: ุงูู ุณุชุฎุฏู ูู ุงูุจุดุฑููู (ุงูู ูุซููู ุนุจุฑ MFA/SSO) ูุงูุฎุฏู ุงุช ุงูุฎูููุฉ ุงูุญุชู ูุฉ (ุงูู ูุซูุฉ ุนุจุฑ ุดูุงุฏุงุช mTLS ุฃู ุญุณุงุจุงุช ุงูุฎุฏู ุฉ). ูููุณุฑ ุงููููู ุงูุฐูู ููุง ุงูุตูููู ุชู ุงู ุงู:
ุงุณุชุฏุนุงุก ุงูุฎุฏู
ุงุช ุงูุชูููุฏู:
[ุฎุฏู
ุฉ ุฃ ุญุชู
ูุฉ] โโโโโโโโโโ ุทูุจ API ู
ุญุฏุฏ ู
ุณุจูุงู โโโโโโโโโโโถ [ุฎุฏู
ุฉ ุจ ู
ุญู
ูุฉ]
ุงุณุชุฏุนุงุก ุงููููุงุก ุงูุฃุฐููุงุก ุงูู
ุณุชูููู:
[ู
ุณุชุฎุฏู
ุจุดุฑู] โโโถ [ู
ูุณู ูููู LLM] โโโถ [ุญููุฉ ุชูููุฑ ูุงุณุชุฏูุงู ุบูุฑ ุญุชู
ูุฉ]
โ
(ูุฑุงุกุฉ ุจูุงูุงุช ููุจ ุบูุฑ ู
ูุซููุฉ / ููุฏ ุทูุจ ุณุญุจ ุฎุจูุซ)
โ
โผ
[ูุฌูู
ุญูู ุงูุชุนููู
ุงุช ุบูุฑ ุงูู
ุจุงุดุฑ]
โ
โผ
[ู
ุญุงููุฉ ุชูููุฐ ุฃุฏูุงุช ุบูุฑ ู
ุตุฑุญ ุจูุงุ]
ุนูุฏู ุง ูุนู ู ุงููููู ุฐุงุชูุงูุ ูุฅูู ูุชุตุฑู ูู ู ููุถ ูุณูุท (Intermediate Delegate)ุ ููู ูู ุซู ุงูู ุณุชุฎุฏู ูููู ูุณุชูุดู ู ุณุงุฑุงุช ูุฑุงุฑ ุบูุฑ ู ุชููุนุฉ ุนุจุฑ ุฃุฏูุงุช ู ุชุนุฏุฏุฉ. ูุฅุฐุง ุงุฑุชุจุทุช ูููุชู ุจุญุณุงุจ ุฎุฏู ุฉ ูุชู ุชุน ุจุตูุงุญูุงุช ูุงู ูุฉุ ูุฅู ุฃู ุญูู ุชุนููู ุงุช ูุญููู ุฅูู ูุงุฆุจ ู ุฎุฏูุน (Confused Deputy) ูุนุจุซ ุจุงูุฃูุธู ุฉ ุงูุญูููุฉ.
3. ูุดู ู ูุงุชูุญ API ุงูุซุงุจุชุฉ ูุงูุฑู ูุฒ ุงูุชูููุฏูุฉ
ูุคุฏู ุงูุงุนุชู ุงุฏ ุนูู ุญูู ู ูุงุชูุญ API ุงูุซุงุจุชุฉ ุฏุงุฎู ู ุชุบูุฑุงุช ุจูุฆุฉ ุงูุญุงููุงุช ุฅูู ุฃุฑุจุน ุซุบุฑุงุช ู ุนู ุงุฑูุฉ ูุงุชูุฉ ูู ุจูุฆุงุช ุงูุฅูุชุงุฌ:
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ูุทุงู ุงูุฎุทุฑ ุงููุงุฑุซู ููุจูุงูุงุช ุงูุซุงุจุชุฉ ุงูู
ู
ููุญุฉ ูููููุงุก โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 1. ุงูุนุฏุงู
ุงููุนู ุจุงูุณูุงู: ูุง ูู
ูุฒ ู
ูุชุงุญ GitHub PAT ุงูุซุงุจุช ุจูู ุฅุตูุงุญ ุฎุทุฃ ู
ุทุจุนู ูู ูุซููุฉ โ
โ ูุจูู ุฅุฑุณุงู ุฏูุน ุฅุฌุจุงุฑู ู
ุฏู
ุฑ ููุฑุน main ุงูุฑุฆูุณู. โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 2. ุงูุตูุงุญูุฉ ุงููุงููุงุฆูุฉ: ุชุธู ุงูู
ูุงุชูุญ ุณุงุฑูุฉ ุญุชู ุชุฏููุฑูุง ูุฏููุงูุ ูุชุธู ุงูุฑู
ูุฒ ุงูู
ุณุฑุจุฉ โ
โ ู
ุฌูููุฉ ูุดููุฑ ุฏุงุฎู ุณุฌูุงุช ุงููููุงุก. โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 3. ูุทุงู ุงูุตูุงุญูุงุช ุงูุดุงู
ู (All-or-Nothing): ุชูุชูุฑ ุฃุบูุจ ูุงุฌูุงุช SaaS ูุตูุงุญูุงุช ุชุฏููู ุฏูููุฉุโ
โ ูู
ูุญ ุงููููู ุญู ุงูุชุนููู ูู Jira ูุฏ ูู
ูุญู ุถู
ูุงู ุตูุงุญูุฉ ุญุฐู ู
ุดุงุฑูุน ุงูู
ุคุณุณุฉ ุจุฃูู
ููุง. โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 4. ูุงุจููุฉ ุงูุชุณุฑูุจ ู
ู ุงูุณูุงู: ุจู
ุฌุฑุฏ ุฏุฎูู ุงูุฑู
ุฒ ุฅูู ุณูุงู ุงููู
ูุฐุฌุ ูุตุจุญ ูุงุจูุงู ููุงุณุชุฎุฑุงุฌ โ
โ ุนุจุฑ ุชูููุงุช ุฅุนุงุฏุฉ ุจูุงุก ุงูุชูุฌูู ูุงููุณุฑ ุงูุฃู
ูู. โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
ุฃู ุณุฑ ุญุณุงุณ ุฃู ุฑู ุฒ Bearer ูุฏุฎู ุฅูู ูุงูุฐุฉ ุณูุงู ูู ูุฐุฌ ุงูุฐูุงุก ุงูุงุตุทูุงุนู ูุฌุจ ุงุนุชุจุงุฑู ู ุฎุชุฑูุงู ูู ุงูุญุงู. ูุฌุจ ุฃู ุชุจูู ุจูุงูุงุช ุงูุงุนุชู ุงุฏ ุญุตุฑูุงู ุฏุงุฎู ุงูุฐุงูุฑุฉ ุงูุขู ูุฉ ูุจูุงุจุงุช ุงูุนุฒู ุงูุฎุงุฑุฌูุฉ.
4. ุงูู ุนู ุงุฑูุฉ ุงูุญุฏูุซุฉ: ุชุจุงุฏู ุงูุฑู ูุฒ ุนุจุฑ OAuth 2.0 (RFC 8693)
ูุชุญููู ุงูุชูููุถ ุงูุขู ูุ ุชุณุชุฎุฏู ุงูุฃูุธู ุฉ ุงูุญุฏูุซุฉ ู ุนูุงุฑ OAuth 2.0 Token Exchange (RFC 8693). ุนูุฏ ุชูููู ุงููููู ุจู ูู ุฉุ ูุชู ุชุจุงุฏู ุฑู ุฒ ุงูู ุณุชุฎุฏู ุจุฑู ุฒ ุชูููุถ ู ุคูุช ุฐู ุตูุงุญูุงุช ู ุญุฏูุฏุฉ ุจุฏูุฉ:
โโโโโโโโโโโโ 1. ุจุฏุก ุงูู
ูู
ุฉ ("ุชุญููู ุชูุฑูุฑ ุฃุฑุจุงุญ ุงูุฑุจุน ุงูุซุงูุซ")
โ ุงูู
ุณุชุฎุฏู
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโ โ
โ โผ
โ 2. ุฑู
ุฒ OAuth ุงูุฃุณุงุณู โโโโโโโโโโโโโโโโโโโโโโ
โ (Subject Token: ูููุฉ ุงูู
ุณุชุฎุฏู
) โ ููุงุฉ ุงููููู โ
โผ โ (ุงูู
ูุณู) โ
โโโโโโโโโโโโโโโโ โโโโโโโโโโโฌโโโโโโโโโโโ
โ ู
ุฒูุฏ ุงููููุฉ โ โ
โ ุงูู
ุคุณุณู โโโโโ 3. ุทูุจ ุชุจุงุฏู ุงูุฑู
ูุฒ RFC 8693 โโโโโโโโโโโโโโโโโโโโโ
โ (Okta/Auth0) โ - Subject Token: ุฑู
ุฒ ูุตูู ุงูู
ุณุชุฎุฏู
โโโโโโโโฌโโโโโโโโ - Actor Token: ูููุฉ ุฎุฏู
ุฉ ุงููููู
โ - ุงููุทุงู ุงูู
ุทููุจ: ["finance.reports:read"]
โ - ุงูุตูุงุญูุฉ ุงูุฒู
ููุฉ: 300 ุซุงููุฉ
โผ
4. ุฅุตุฏุงุฑ ุฑู
ุฒ ู
ุคูุช ู
ููุต ุงูุตูุงุญูุงุช
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ุจูุงุจุฉ ูุณูุท ุงูุฃุฏูุงุช (Tool Broker) โ
โ โโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ ู
ุญุฑู ุงูุณูุงุณุงุช Cedar โโโโโโโถโ ุญุงูู ุจูุงูุงุช ุงูุงุนุชู
ุงุฏ โ โ
โ โโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโฌโโโโโโโโโโโโ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโ
โ
โ 5. ุงุณุชุฏุนุงุก ุงูุฃุฏุงุฉ ุงูู
ูุซู
โผ
โโโโโโโโโโโโโโโโโโโโโ
โ ูุงุฌูุฉ API / MCP โ
โ (ุตูุงุญูุฉ ูุฑุงุกุฉ ููุท)โ
โโโโโโโโโโโโโโโโโโโโโ
ู
ู ุฎูุงู ุชูููุฏ ุฑู
ูุฒ ู
ุฑูุจุฉ ุชุฑุจุท ูููุฉ ุงูู
ุณุชุฎุฏู
ุงูู
ุณุชุฏุนู (sub) ุจูููุฉ ุงููููู ุงูู
ููุฐ (act)ุ ุชุญุงูุธ ูุฑู ุงูุฃู
ุงู ุนูู ุณูุณูุฉ ุชุฏููู ุบูุฑ ูุงุจูุฉ ููุชุฒููุฑ ุชูุชูู ุตูุงุญูุชูุง ุขููุงู ุจุนุฏ ุฏูุงุฆู ู
ุนุฏูุฏุฉ.
5. ุชุฃู ูู ุจุฑูุชูููู ุณูุงู ุงููู ูุฐุฌ (Model Context Protocol)
ูู ุซู ุจุฑูุชูููู MCP ุงูู ุนูุงุฑ ุงูู ูุชูุญ ูุงุณุชุฏุนุงุก ุงูุฃุฏูุงุช ุจูุงุณุทุฉ ุงููููุงุกุ ุฅูุง ุฃู ุญู ุงูุชู ูู ุงูุฅูุชุงุฌ ุชุชุทูุจ ุซูุงุซุฉ ุถูุงุจุท ุฑุฆูุณูุฉ:
- ุชุตุฑูุญ ุงููุฏุฑุงุช ุฏููู ุงูุชุฎุตูุต: ุชูููุฑ ุฃุฏูุงุช ู
ุญุฏุฏุฉ ุงููุธููุฉ ุจุฏูุฉ (ู
ุซู
github.issue.add_comment) ุจุฏูุงู ู ู ุชูููุฑ ู ูุฌูุงุช ุฃูุงู ุฑ ุนุงู ุฉ (system.exec_bash). - ุญุฌุจ ุงูุฃุณุฑุงุฑ ุฎุงุฑุฌ ุงููุทุงู: ุชู
ุฑูุฑ ู
ุฑุงุฌุน ุชุฌุฑูุฏูุฉ (ู
ุซู
vault://creds/staging_db) ููููููุ ููุชููู ูุณูุท ุงูุฃุฏูุงุช ุญูู ุจูุงูุงุช ุงูุงุนุชู ุงุฏ ุงูุญููููุฉ ุนุจุฑ ุงุชุตุงู TLS ุฏุงุฎูู ู ุดูุฑ. - ุจูุงุจุงุช ุงูุชุญูู ุงูุจุดุฑู ุงููุญุธูุฉ: ุชุนููู ุงูุชูููุฐ ูุทูุจ ู ูุงููุฉ ู ุดุฑูุฉ ููุฑูุฉ ูุจู ุชูููุฐ ุงูุนู ููุงุช ุงูุญุณุงุณุฉ (ุญุฐู ููุงุนุฏ ุงูุจูุงูุงุชุ ุชุญููู ุงูุฃู ูุงูุ ุฃู ุงููุดุฑ ููุฅูุชุงุฌ).
6. ุงูุณูุงุณุฉ ูููุฏ ุจุฑู ุฌู ูููููุงุก: AWS Cedar ู Open Policy Agent
ุชูุดู ุงูุชูุฌููุงุช ุงูููุธูุฉ ูู ุญู ุงูุฉ ุงููููุงุก ุฃู ุงู ูุฌู ุงุช ุงูุชุฌุงูุฒ. ูุฌุจ ุชูููู ูุฑุงุฑุงุช ุงูู ูุญ ุญุชู ูุงู ุจูุงุณุทุฉ ู ุญุฑูุงุช ุณูุงุณุงุช ู ุซู AWS Cedar ุฃู OPA:
// ู
ุซุงู ุณูุงุณุฉ AWS Cedar ููููู ุจุฑู
ุฌุฉ ุฐุงุชู
// 1. ุงูุณู
ุงุญ ุจุงููุฑุงุกุฉ ูุงูุงุฎุชุจุงุฑ ูู ุงูู
ุณุชูุฏุนุงุช ุงูู
ุฎุตุตุฉ
permit (
principal in Role::"CodingAgent",
action in [Action::"clone_repo", Action::"read_file", Action::"run_tests"],
resource in Repository::"Engineering"
);
// 2. ุงูุณู
ุงุญ ุจุฅูุดุงุก ุงููุฑูุน ูุทูุจุงุช ุงูุณุญุจ ููุท ุนูุฏ ูุฌูุฏ ุชุฐูุฑุฉ Jira ุตุงูุญุฉ
permit (
principal in Role::"CodingAgent",
action in [Action::"create_branch", Action::"open_pull_request"],
resource in Repository::"Engineering"
)
when {
context.has_valid_jira_ticket == true &&
context.ticket_assignee == principal.delegated_user
};
// 3. ุญุธุฑ ู
ุทูู: ู
ูุน ุงูุฏูุน ุงูู
ุจุงุดุฑ ูููุฑูุน ุงูู
ุญู
ูุฉ ู
ูุนุงู ุจุงุชุงู
forbid (
principal,
action in [Action::"git_push_direct", Action::"delete_repository"],
resource
)
when {
resource.branch in ["main", "master", "release/*"]
};
ูููู ูุณูุท ุงูุฃุฏูุงุช ุณูุงุณุงุช Cedar ูู ุฃูู ู ู 2 ู ููู ุซุงููุฉุ ู ู ุง ูู ูุน ุงูุทูุจุงุช ุบูุฑ ุงูู ุตุฑุญ ุจูุง ูุจู ุฅุฑุณุงู ุฃู ุญุฒู ุฉ ุจูุงูุงุช ุนุจุฑ ุงูุดุจูุฉ.
7. ุจูุงุก ุจูุงุจุฉ Zero-Trust ุจูุบุฉ ุจุงูุซูู
ููุถุญ ุงูููุฏ ุงูุชุงูู ุจูุบุฉ ุจุงูุซูู ููููุฉ ุจูุงุก ุจูุงุจุฉ ููุชุญูู ู ู ููุฉ ุงุณุชุฏุนุงุก ุงูุฃุฏุงุฉุ ูุญุฌุจ ุงูุฃุณุฑุงุฑ ุนู ุงููู ูุฐุฌุ ูุชูููุฏ ุจุตู ุฉ ุชุฏููู ุบูุฑ ูุงุจูุฉ ููุชุฒููุฑ:
"""
Zero-Trust Agent Authorization Gateway
Ecosystem: Python 3.11+, Pydantic v2, Cryptographic Audit Trails
"""
import time
import hmac
import hashlib
import json
from enum import Enum
from typing import Dict, Any, Optional
from pydantic import BaseModel, Field
class ActionRiskLevel(str, Enum):
LOW = "low" # ุนู
ููุงุช ูุฑุงุกุฉ ูุจุญุซ ุขู
ูุฉ
MEDIUM = "medium" # ุฅูุดุงุก ู
ุณูุฏุงุชุ ูุชุญ ุทูุจุงุช ุณุญุจ
CRITICAL = "critical" # ูุชุงุจุฉ ุจุงูุฅูุชุงุฌุ ุญุฐู ุจูุงูุงุชุ ู
ุนุงู
ูุงุช ู
ุงููุฉ
class ToolCallIntent(BaseModel):
tool_name: str
target_resource: str
action: str
arguments: Dict[str, Any]
risk_level: ActionRiskLevel
class AgentContext(BaseModel):
agent_id: str
delegated_user_id: str
session_id: str
assigned_scopes: list[str]
class AuthorizationDecision(BaseModel):
is_authorized: bool
requires_human_approval: bool
audit_token: str
reason: Optional[str] = None
class AgentZeroTrustGateway:
"""
ุจูุงุจุฉ ูุณูุทุฉ ูุฌู
ูุน ุงุณุชุฏุนุงุกุงุช ุงูุฃุฏูุงุช.
ุชูุฑุถ ุชูููู
ุงูุณูุงุณุงุชุ ูุญูู ุงูุจูุงูุงุช ุฎุงุฑุฌ ุงููุทุงูุ ูุณุฌูุงุช ุชุฏููู ุบูุฑ ูุงุจูุฉ ููุชุบููุฑ.
"""
def __init__(self, secret_key: str):
self._signing_key = secret_key.encode("utf-8")
self._policy_rules = {
"github.read": ActionRiskLevel.LOW,
"github.create_pr": ActionRiskLevel.MEDIUM,
"database.execute_select": ActionRiskLevel.LOW,
"database.drop_table": ActionRiskLevel.CRITICAL,
"kubernetes.delete_pod": ActionRiskLevel.CRITICAL
}
def evaluate_tool_intent(
self,
agent_ctx: AgentContext,
intent: ToolCallIntent
) -> AuthorizationDecision:
required_scope = f"{intent.tool_name}:{intent.action}"
if required_scope not in agent_ctx.assigned_scopes and "*:*" not in agent_ctx.assigned_scopes:
return AuthorizationDecision(
is_authorized=False,
requires_human_approval=False,
audit_token=self._generate_audit_hash(agent_ctx, intent, "REJECTED_SCOPE"),
reason=f"ุงููููู ููุชูุฑ ุฅูู ูุทุงู ุงูุตูุงุญูุฉ ุงูู
ุทููุจ: {required_scope}"
)
if intent.risk_level == ActionRiskLevel.CRITICAL:
return AuthorizationDecision(
is_authorized=False,
requires_human_approval=True,
audit_token=self._generate_audit_hash(agent_ctx, intent, "PENDING_HUMAN_APPROVAL"),
reason="ุนู
ููุฉ ุญุฑุฌุฉ ุชุชุทูุจ ุชุฃููุฏุงู ูู
ูุงููุฉ ุจุดุฑูุฉ ู
ุณุจูุฉ."
)
return AuthorizationDecision(
is_authorized=True,
requires_human_approval=False,
audit_token=self._generate_audit_hash(agent_ctx, intent, "AUTHORIZED"),
reason=None
)
def execute_with_isolated_credentials(
self,
agent_ctx: AgentContext,
intent: ToolCallIntent,
decision: AuthorizationDecision
) -> Dict[str, Any]:
if not decision.is_authorized:
raise PermissionError(f"ุชู
ุญุธุฑ ุงูุชูููุฐ: {decision.reason}")
ephemeral_token = self._mint_ephemeral_token(agent_ctx, intent)
execution_result = self._dispatch_to_tool(intent, ephemeral_token)
return {
"status": "success",
"audit_hash": decision.audit_token,
"data": execution_result
}
def _generate_audit_hash(self, ctx: AgentContext, intent: ToolCallIntent, status: str) -> str:
payload = f"{ctx.agent_id}:{ctx.delegated_user_id}:{intent.tool_name}:{status}:{time.time()}"
return hmac.new(self._signing_key, payload.encode("utf-8"), hashlib.sha256).hexdigest()
def _mint_ephemeral_token(self, ctx: AgentContext, intent: ToolCallIntent) -> str:
return f"ephemeral_jwt_sub_{ctx.delegated_user_id}_act_{ctx.agent_id}_exp_{int(time.time()) + 300}"
def _dispatch_to_tool(self, intent: ToolCallIntent, token: str) -> Dict[str, Any]:
return {"records_affected": 1, "executed_action": intent.action}
8. ู ุตูููุฉ ุงูู ูุงุฑูุฉ ุงูู ุนู ุงุฑูุฉ ุงูุดุงู ูุฉ
ู ูุงุฑูุฉ ุจูู 4 ูู ุงุฐุฌ ูู ุตุงุฏูุฉ ูุชูููุถ ูููุงุก ุงูุฐูุงุก ุงูุงุตุทูุงุนู ูู ุจูุฆุงุช ุงูู ุคุณุณุงุช:
| ุงูุจุนุฏ ุงูู ุนู ุงุฑู | 1. ุงูู ูุงุชูุญ ุงูุซุงุจุชุฉ (ุงูุชูููุฏูุฉ) | 2. ุชุจุงุฏู ุงูุฑู ูุฒ (RFC 8693) | 3. ุจูุงุจุฉ Cedar / OPA | 4. ุงููููุงุช ุงูู ุดูุฑุฉ (DIDs) |
|---|---|---|---|---|
| ุตูุงุญูุฉ ุจูุงูุงุช ุงูุงุนุชู ุงุฏ | ุดููุฑ / ุณููุงุช (ุซุงุจุชุฉ) | 5 โ 15 ุฏูููุฉ (ู ุคูุชุฉ) | ุตูุฑ ูุตูู ู ุจุงุดุฑ (ุนุจุฑ ุงูุจูุงุจุฉ) | ู ูุงุชูุญ ุชุดููุฑ ู ุฑุชุจุทุฉ ุจุงูุฌูุณุฉ |
| ู ุฎุงุทุฑ ุงูุชุณุฑูุจ ูู ุงูุชูุฌูู | ูุตูู (ุงูู ูุชุงุญ ุจุงูุณูุงู/ุงูุจูุฆุฉ) | ู ุชูุณุทุฉ (ุงูุฑู ุฒ ุจุฐุงูุฑุฉ ุงูุชุดุบูู) | ู ูุนุฏู ุฉ (ู ุญุฌูุจ ุฎุงุฑุฌ ุงููุทุงู) | ู ูุนุฏู ุฉ (ุชุญุฏูุงุช ุชุดููุฑ ู ููุนุฉ) |
| ูุทุงู ุงูุฎุทุฑ ุนูุฏ ุงูุงุฎุชุฑุงู | ู ุณุงุญุฉ ุนู ู ุงูู ุคุณุณุฉ ูุงู ูุฉ | ู ููุฏ ุจุงูู ูู ุฉ ุงูู ููุถุฉ ููุท | ู ููุฏ ุจุงูุณูุงุณุฉ ุงูุจุฑู ุฌูุฉ | ู ููุฏ ุจุงูุดูุงุฏุฉ ุงูุฑูู ูุฉ ุงูู ููุนุฉ |
| ุฒู ู ุงุณุชุฌุงุจุฉ ุงูุฅูุบุงุก | ูุฏูู (ุณุงุนุงุช/ุฃูุงู ) | ุชููุงุฆู ููุฑ ุงูุชูุงุก ุงูู ูู ุฉ | ูุญุธู (ุจู ุฌุฑุฏ ุชุญุฏูุซ ุงููุงุนุฏุฉ) | ูุญุธู (ููุงุฆู CRL / OCSP) |
| ุจูุงุจุงุช ุงูุชุญูู ุงูุจุดุฑู | ุบูุฑ ู ุชููุฑุฉ | ู ุญุฏูุฏุฉ (ุฅุนุงุฏุฉ ู ุตุงุฏูุฉ) | ุฃุตููุฉ (ุญุณุจ ุฏุฑุฌุฉ ุงูู ุฎุงุทุฑุฉ) | ุชูููุน ู ุชุนุฏุฏ ุงูุฃุทุฑุงู |
| ุฌุงูุฒูุฉ SOC2 / ISO 27001 | โ ุฑุณูุจ ุจุงูุชุฏููู | โ ุงู ุชุซุงู ูุงู ู | โญ ุงูู ุนูุงุฑ ุงูุฐูุจู | โญ ู ุนูุงุฑ ู ุณุชูุจูู ูุงุนุฏ |
| ุฌูุฏ ุงูุชุทููุฑ ูุงูุชูููุฐ | ุจุณูุท ุฌุฏุงู (ููู ูุงุญุฏ) | ู ุชูุณุท (ุฃุณุจูุน ุฅูู ุฃุณุจูุนูู) | ู ุชูุณุท (ุฃุณุจูุน ุฅูู ุฃุณุจูุนูู) | ู ุฑุชูุน (ุชุดููุฑ ู ุชุฎุตุต) |
| ุฃูุถู ู ูุงุกู ุฉ ููุฅูุชุงุฌ | ุงููู ุงุฐุฌ ุงูุชุฌุฑูุจูุฉ ููุท | ุชุทุจููุงุช SaaS ู ุชุนุฏุฏุฉ ุงูุนู ูุงุก | ุงูุฃูุธู ุฉ ุงูุฏุงุฎููุฉ ููู ุคุณุณุงุช | ุงููููุงุก ุงูุนุงุจุฑูู ููู ุคุณุณุงุช |
9. ุงูุงู ุชุซุงู ูุณุฌูุงุช ุงูุชุฏููู ูุนุฏู ุงูุฅููุงุฑ
ุนูุฏ ููุงู ูููู ุจุชุนุฏูู ุจููุฉ ุชุญุชูุฉ ุฃู ุฅุฌุฑุงุก ู ุนุงู ูุงุช ู ุงููุฉุ ุชุชุทูุจ ุงูู ุนุงููุฑ ุฏูููุงู ูุงุทุนุงู ุนูู ุนุฏู ุงูุฅููุงุฑ. ูุชู ุชุณุฌูู ูู ุฎุทูุฉ ูู ุบูุงู ุชุฏููู ู ุดูุฑ ุบูุฑ ูุงุจู ููุชุนุฏูู:
{
"audit_version": "2026.1",
"timestamp": "2026-09-11T14:22:18.491Z",
"trace_id": "trace-8f92a11b-c741",
"actor": {
"agent_id": "agent-swe-core-09",
"delegated_user": "usr_998124_alice",
"delegation_token_fingerprint": "sha256:4b912e80..."
},
"prompt_context_hash": "sha256:d891e4a3...",
"intent": {
"tool": "aws_s3_gateway",
"action": "delete_object",
"resource": "arn:aws:s3:::internal-backups/archive-2025.tar.gz"
},
"policy_evaluation": {
"engine": "Cedar-v3",
"verdict": "ALLOW",
"evaluated_policies": ["policy_allow_backup_rotation_2026"]
},
"signature": "MEQCIG7zY8f+k7..."
}
ุนุจุฑ ูุชุงุจุฉ ูุฐู ุงูุณุฌูุงุช ุงูู ููุนุฉ ุนูู ูุณุงุฆุท ุชุฎุฒูู WORM (ุงููุชุงุจุฉ ู ุฑุฉ ูุงููุฑุงุกุฉ ุนุฏุฉ ู ุฑุงุช)ุ ุชุณุชููู ุงูู ุคุณุณุงุช ู ุนุงููุฑ SOC2 Type II ู HIPAA ู ISO 27001 ู ุน ุงูุญูุงุธ ุนูู ุดูุงููุฉ ุฑูู ูุฉ ูุงู ูุฉ.
ุงุฎุชุฑ ูู ูุฐุฌ ุงูู ุตุงุฏูุฉ ุงูู ูุงุฆู ุจุญุณุจ ู ุชุทูุจุงุช ูุฃุจุนุงุฏ ุงูุชุดุบูู ุงูุฎุงุตุฉ ุจู:
- ุฅุฐุง ููุช ุชุจูู ูููุงุก SaaS ู ุชุนุฏุฏู ุงูู ุณุชุฃุฌุฑูู ููุงุจุฉ ุนู ุงูู ุณุชุฎุฏู ูู: ุทุจู OAuth 2.0 Token Exchange (RFC 8693) ู ุน ุฑู ูุฒ ูุตูุฑุฉ ุงูุฃุฌู.
- ุฅุฐุง ููุช ุชุฏูุฑ ุฃุชู ุชุฉ ุฏุงุฎููุฉ ููู ุคุณุณุฉ ุนูู ูุงุฌูุงุช ุญุณุงุณุฉ: ุงูุดุฑ ุจูุงุจุฉ ุงูุณูุงุณุฉ ูููุฏ (Cedar/OPA) ู ุน ุญุฌุจ ุงูุฃุณุฑุงุฑ ุฎุงุฑุฌ ุงููุทุงู.
- ุฅุฐุง ูุงูุช ุงูุนู ููุงุช ุชุชุถู ู ู ุฎุงุทุฑ ู ุงููุฉ ุฃู ุชุฏู ูุฑูุฉ ุนุงููุฉ: ุงุฏู ุฌ ุจูุงุจุงุช ุงูุชุญูู ุงูุจุดุฑู ุงูููุฑูุฉ ุนุจุฑ LangGraph.
- ุฅุฐุง ูุงู ุงููููู ูููุฐ ุฃููุงุฏุงู ุจุฑู ุฌูุฉ ุนุดูุงุฆูุฉ ู ููุฏุฉ: ุงุนุฒูู ุชู ุงู ุงู ุฏุงุฎู E2B MicroVM Sandbox.