Better Agent Auth — Bereket Habtemeskel & Paola Estefania, Better Auth

summarized

TLDR

Better Auth proposes a protocol for AI agent authentication that gives agents their own identity instead of using user credentials. It addresses discovery, fine-grained authorization, and traceability through a directory of capabilities and agent-specific private keys. The protocol aims to make agent interactions more secure and auditable.

Key points

  • Agents should have their own identity rather than using user credentials.
  • The protocol includes a directory for capability discovery, allowing agents to find available services automatically.
  • Fine-grained authorization is achieved through capabilities, which are more specific than scopes.
  • Traceability is provided by logging which agent did what on behalf of which user.
  • Revocation of agent access is possible by revoking the agent's identity or host.
  • The protocol uses OpenAPI specs to translate endpoints into capabilities for services that don't natively support the protocol.
  • Agents use private keys to sign tokens, giving them a unique identity that can be tracked and revoked.
  • The demo shows integration with MCP (Model Context Protocol) where agents request capabilities, get approved, and actions are logged.

Tools mentioned

Techniques

  • capability-based authorization
  • agent identity with private keys
  • discovery via directory
  • translating OpenAPI to capabilities
  • device flow for approval
Transcript (captions)
Well, hello everyone. Can you hear me all? Okay. Yes. Perfect. Well, welcome to our talk, our workshop actually. Um, I know maybe you were expecting uh Burgett also. he couldn't come but we make this workshop together for you. Okay. So as you see you have there a QR code you can go ahead and go there is um our page for Asian health protocol so that you have it and I don't have to spell it for you. Um, okay. So, my whole idea today is instead of like me telling you stuff and you do this and show you how to do stuff, I want us to take one hour at least to think about Asian security, Asians because sometimes we are excited about like this new AI era, right? But we never think about or maybe yes, but not as much as I wished. What happens when you for example say hey agents what are my maybe my schedule for tomorrow what are send an email have you ever thought of this how many of you like raise your hand like how many of you use AI agents every day okay higher don't be shy okay great how many of you give them access to your Gmail to your calendar to your personal accounts how many of you oh so much less Okay. The ones that do like what do you do like you connect an MCP server? Okay. Yes. And they have another one. Good. Maybe you connect like your personal token to like endpoint. Okay. So what happened when we do this? We're actually doing like the agent is acting on behalf of us but pretending to be us. So do you think that's a good idea? Yes or no? Who thinks it's a good idea? >> Not a great idea. Why? >> Exactly. And why we didn't thought about this like before. Okay. So it doesn't matter. Here we are. We are thinking about it. I always remember uh the time like when internet came like I'm almost 40 so I remember and everybody was so happy about it. But then started to question like okay everything the whole data is public it's like we are in the same moment today right like we are really excited about AI and then after we start to think about security but it's good so why I put there hire your agent the analogy I want you to think about let's say you have a company or a part of a company and you hire someone do you give them you need them to have access two things of the company, right? So, what you do with these people when you showing or when you show, what did they give to you? You have a your own email, right? Your own access, your own credentials. So, if you think about it in Asian world, what are we doing without agents? We are it's like we are doing like the CEO credentials, right? You never say like, okay, this is the credentials of CEO, go and read the email. No, because everything anything could happen. This is the same. The idea will be hire your agent in a sense of give them your agents authority instead of your credentials. Do you think it's a good idea? How? Yes or no? [laughter] Okay. My idea is like I know sometimes um we could be shy but I want I think it would be nice like we can interact a bit because it's a moment that thanks to a engineer and all of us being here all of your time we can get together and think about something. I think it's not common, right? So, make 100% off of it. Um, okay, great. So, did you all got the page there, the QR codes? Yeah. Great. So, remember like my idea of saying, "Okay, agent read my emails, right?" Have you ever thought like how the agent gets to there? How it gets to your email? First of all, how do Asians know what they can do? >> Huh? >> Okay, great. So, you you do it by hand, right? It's not that something automatic. >> Yes. >> Exactly. >> But >> Exactly. But some huh >> exactly context window also too. But you always somehow connected something to the Asian that okay this is what you can do right. So what if we have like an ideal world or that can go to maybe a directory and say oh this is the whole thing I can do and this is all the things I can execute. That would be a smartest idea right? Have you ever used a phone book? Yeah right. this is safe like who I can call so I go and look in the phone book and then I have how to call it I have the number they will be the same what what I want to do and how do I call it so that's is our first problem discovery how agents discover what they can do and the idea will be it will be an automatic way not just us all the time telling how and connecting and stuff right then also there's another part it would be nice to tell the agents or like grant Asians what they can do and we're not but really specific the ones that connected the Gmail accounts maybe they all gave them read access right just read so we can I don't know don't send or like not remove anything so it's more safe okay but what if you have so many important uh information there that then if the agent something gets um wrong and somebody else can read your data it's good either. It's not safe in any way. So what if we can get all these what the agent can do all these tools as he mentioned and you can grant access to every tool like this yes this no this reading is okay that would be a better idea right so we think about authorization to that agent not like to act behalf of me and have everything I can do then the agent can do it's like going back to the higher example that a person like I just hired has all the same access that the CEO or maybe you hire have an assistant uh or a friend that do something for you like in your real life you will never give your access to all your things right and if you do you change them after so this is the same thing and also okay we have an ideal world when agents can discover what they can do then we can tell them what they can do or not but how do we trace them down. How do we trace today what the apps do on our behalf when you authorize them? >> Huh? >> Exactly. Audi logs. So perfect audification, right? Which agent did what on behalf of which user. In order to do that, that comes to our main thing. Give the agent's identity. If we have if every agent has identity, we can trace them down. We can know what agent did what when in behalf of which user. It seems like it's so much so much better, right? And also what else you can do when you can trace someone regarding to the whole hiring thing, you can fire them if they do something wrong. You can revoke access in the same way the agent will be revoked if you know who they are. If something were wrong with today's things, you have to disconnect the whole thing, right? Yes or no? So imagine have Oh, this same up. Sorry for the word. You can't remove it. That's it. So we have tracibility. We have the whole thing. Okay. So as it come out as a sum up we have the discovery issue where the agent can go find the service and read the capabilities authorization what this agent can do can do scope down and who is this agent are you on board with this do you think it's a good idea you have any questions like champion okay great [snorts] have you ever heard of a capabilities raise your hand Yes. Okay. Do you all know what a capability is? Who doesn't know? Okay. Almost the whole room. Okay. So the idea of using capabilities is instead of using scopes, you know, like scope is like a big thing. For example, we have the read scope. So it what what does mean it's like nothing so specific. The other capability is what can do, but it's more cap down. So I can actually determine what an action agent can do. So the idea is going back to the example I put in the beginning. Let's say you talk to the AI in the chat and you say, "Okay, give me my emails from the last week." So the agent has an intent to do something, right? It has to be a way that that intent has to be mapped to a tool or maybe several tools. So that's kind of the idea. The tools will be like capabilities and an intent will be matched to that. So that's what we're solving with discoverability. If you ever read the the protocol that we are proposing or maybe read it later, you will see um our idea of a well-known Asian configuration endpoint. If you know about a little bit about identity, you remember OIDC, right? connect these are the same well known and the idea is like to a nation have like a public place to know how they can interact with a service like everything the kind of encryption uh etc. So it will be something like this and also a place to list capabilities and stuff. But what happened for example in a world like today that we still I hope I hope in the future we adopt this but in the meantime all the services they're still working just with O. So how do we do it in the meantime? What do we need to agents to be able to know which what they can use from each service? Let's say Gmail. We can build something like a directory. So the idea is um to have something I'm going to see it here. So let's say most of the you're familiar for open API open API spec. Yes. Okay. So most of the common services we use they all implement open API. So we have like a kind of a place to we as a developers or engineers we can say okay what this service can do. So the idea is to use that and convert the two capabilities. So at the beginning until we every service is speak. So let's say for example do you guys use I don't know tell me a service you use ah >> open AI okay Gmail we have it there but let's say for example let's see if it works open AI open APIJSON and sometimes they have public they have the publics but we need like a JSON Uh, I don't see it. API opening. Okay, I do know. I think it's this one. No. Well, you know what? That were wrong. >> Notion. Not has a really good one. I wanted to use another one from you guys, but the notion is more reachable. So here you see so if you have for example not every service has but the open API JSON what we doing with the protocol is translating this oh I already register it. So, I'm going to show you guys. Yeah. Where is this one? Sorry. Don't see it here. Okay. It will form something like this. This is like an example, but it's like the same. So, you will get all the capabilities from the endpoints. You see sometimes you see like a delete again. So it would kind of be idea to approach like a middleware to this point. Yes. Oh, sorry guys. Thank you for telling me. And okay, here is better. Oh, thank you. Sorry guys. Okay. So the idea is to see here it's like you can translate the endpoints to capabilities. So because we are still this is just because we still we don't have so much services or let's say none like implementation stuff but the idea is like in the meantime we have something that translate this. So what this mean? It means like let me check. It means like you will have something for example do you have there in the agent of protocol you see do you have a directory this directory we have for example the Gmail one that we did the same. So you see you have for example 20 list of capabilities. So the idea is like you grab what the service can do, what is exposing maybe through open or maybe you do it yourself because uh for example maybe you want to automate a workflow. So the idea is like everything get list here. So the directory will be like a phone directory for the agent. Are you following me? >> Yeah. The what? Sorry. >> Yes. I mean it's a good point. Did you hear? Did you hear him? Like fine grain out. Okay. So the idea is yes in a sense of having the most scope thing as possible but still fine out is still goes like minting a token to the user. We want to meet a token for the agent. So what we are switching is the principle. We now want that the agents are a principal actor. But it's a really good thing. That's why we inspire on that. I think it's one of the best things we can do. Okay, great. Um so going back to the capabilities the idea is what I just said like having this scope once you have like the readings or like maybe uh just the gets or the deletes or the post like everything is quite discerned so you can decide whe you have any questions. >> Yes. Yeah. Yeah. That's that really sucks. Uh the idea is you can do it manually. You can actually declare everything so in the directory or in the future the agent know how to do. It's like less common. But yeah, it could happen. But the idea is like in in the meantime we do this until services implement these sessions out. But yeah, it's a good question. [snorts] Um okay so remember like our problems right so now we we are trying to get a solution for how like the agents the agents know what they do with the directory then we have a way to authorize them through the capabilities and now if you remember we said it was a good idea to get them identity right so what we come is giving agents like a private key like famous private key. So each agent will have its own and that will be attached to the identity. Um so in that sense because every agent has its own identity. Now if you I see you want me to put this on light mode too. Uh what did you say that before? Okay, let's go back to this there. That's better. Great. zoom in. Okay, there. So now that the agent will have like a access to its own private key, they can sign tokens, they can have like their own metered tokens and everything is encrypted with the private key. So what this means like for now on instead of like a service let's say Gmail seeing like a user interacted with the service we can have a log that we actually say okay this agent is doing something on my behalf that is connected to the user but it's actually for example agent from cursor or an agent from cloud or an agent from whatever. So we are changing the paradigm. We stop seeing as an agent is like hiding behind the user and now the agent is there as a principal acting. So is is for me was really exciting. So do you have any concerns about this private key private key public policy key things? Yeah. Exactly. That's beautiful, right? You can say, "Oh, this is not doing what I supposed to be doing, and I go and I revoke it." So, it's cool. And maybe you can think of like, okay, the the I revoke it, but the access token is still there. So, what you can do is like deleting with the GDI. So, bye. >> Yes. Mhm. Always the token always the agents they always have a user they are reporting to you. They are never detached. So always the the agent is like with a user. >> Yeah. >> Yes. >> Yes. Exactly. you have like all the information the agent also the host we are in introducing a new thing that is called host that is like the place when you are like creating this agent from so you actually can also delete the host you can say okay this host is not authorized so you can see the host you can see the agent ID you can see the user you can see everything okay great more questions okay don't be shy like we are here for this Yes. >> Can you speak a little bit higher? >> Yeah, that's a great question. Um, actually it's more like an enterprise focus, right? So because we did this in February, the things changed so much until now. Like for example, Asians are not so ephemeral. Maybe you have a forever long Asians, right? Or maybe you have two Asians or maybe you have Asian design of a company and they have policies. So we are working on that in a new draft and we are addressing that too. Um because it's something quite um important to address. So yes, I was about to say that in the end, but yeah, we're about to release a new draft with uh if you have this is an open source. It's a project that we want to all of us own. So if you have some ideas like you reach out like like that one for example, it's really good. So we can improve it's good for ourselves and good for everyone. And I don't want this to be just like for enterprise just to all of us that use AI that be safe. So thank you. Okay. So that was that was just discussing about the V1 to V2. Um great. So three layers then one protocol. Why we say this? Because if you go and in the searching the website you will see we publish like a first version just like a draft or a ancient plugin inside of a draft. The idea is you can use this and play around and see what you come up with. So in the agent plug-in you can uh use it like on the server side so a server can verify an agent or issue grants or force whatever constraint that you have been doing with that also on the SDK side uh we ship it with an MCP so you can connect it to your cloud to try it out you connect it to your whatever you're using course or whatever you're using with MCPS and also the other layer is the directory it's just a place like a phone book like where the intent match what the action. So intent will be matching the capabilities. Um so the idea is that we can see it in action. So what we will do if you want you can go to what I shared in the QR code. Let's go to the page. Okay, you will see a directory there. Did you all find the directory button? You will you will come into this and you will see a connect button. So you have to login first for sure. And you will see a connect and then you will see the MCP. So you can connect that for example to the cloud. I have it here. I wanted to to show you guys a bit what we were talking about. So let's say we say I'm going to ask for emails. Okay, I just did a bunch of demo emails, but I'm going to show it to you guys so I don't show like personal information. But for example, I have my NCP connected. So you will see something like this uh connectors customize. Here you see Asia D. You will see something like this. Then you can approve, disapprove, always deny just the Asian D. um MCP and if it's that my idea is like you try it out just with MTP of Asian D. So the agent doesn't have access to other tools. So it's like the principal one to see how it interact and how it gets the identity. Our whole idea is like when you use this MCP the agent will have an identity we request you for capabilities and we'll try to execute it and you we will see the logs and everything um uh running. Okay. So let's see for example um hey bring me my last email. Oh sorry it's going to use the H&L connectors. Can you see it's too small? It's okay. Okay. Okay. you see is using the because it has the NCP is using the directory to see from my intent of like bring me my last email which capabilities are out there and he's asking for approval. We are using here device uh device flow. Do you know the device flow? Are you familiar? It's just like it's like connecting a device. So we are acting like is a if the agent is another device. So you can see uh the agent called is called email reader is that's for default. You can change later if you want to. It's requesting me to read at least my emails. We're going to approve. And I'm going to show you that guys later. So the idea here um is that the agent will connect we get the identity it uh will have the last email. Okay. Okay. We have a nice email. So we know agents can read emails. That's not the demo. The demo is what what happens. So remember we at the beginning we say if we gave identity we can have logs. So let's see what the agent did. So I know I have an active agent. There's an email reader that has this agent ID. He's in a local device. It has these things and also I can see here this agent with this user ID. Okay, I see the agent here just is the email reader and he got these results. So I'm actually tracking down what the agent did, right? So now let's say I want the agent to I don't know send an email by default what we are proposing is like all the hosts like for example clo has reading capabilities by default so then it wouldn't mess up youration with your inbox right so let's see uh let's send an email who has like a really short email that I can put in there >> hello really but no but actual one [laughter] >> who has like a good email. If not I can put like my own but if you want to show okay so I gonna put mine you see I to myself saying I'm gonna use hello world. I thought that your email was hello world was so cool. [laughter] Okay, so the idea here is if you as you just saw like the agent just have like the reading capabilities. Ideally, it will never could send the email without me granting it. So for example we can see it here right the only capabilities it has is two of these two. So it will try to see it here. We can also we also did like this extension for us to actually watch it better what the aation was doing. Okay. Okay. Authorize patch with security verification. Okay. So you see this um the agent now is using CA like asyn like it's client back channel authorization instead of like just showing me like a redirect and see a device that I approve I could approve from here. So for the demo I just going to approve and now that the agent has approved. I approve it. It will be actually sending the email. So you will see in the capabilities here that now you can send the capabilities of uh send emails and actually we can see here he just it just send the email right so what do we want to try this we're going to see if you see no no okay here is the email okay so what we want to try now let's say this something went wrong with the agent Somebody was trying to access my Gmail trying to propector whatever. So the idea of this whole thing is to have the trustability we just saw is on the logs right and what if we want to revoke it let's try you let's try to revoke it and try to for example read my emails. So we're going to revoke it first so it cannot see a thing. Oh I lost the page here. [snorts] So in agents we can revoke the agent. So bye-bye. And now we can say read that last email you just sent. Okay. You see the connection got revoked. So what happened now? Why it can't read it anyway? Because what we did is like he created another agent an identity because I revoked the one before but this is just happening because the get the list is a default capability in our host because for us it's safe. What if now I wanted to say um send an email saying hello to myself. It will do the same. It will ask for it. So actually it's working right. I can actually revoke it. I can see the logs. I can say what the agent can do or not. Don't you think it's a it's kind of nice to have this kind of workflow? It's more controlled. Yeah. You have any questions about this? How something that pops in your mind? Yeah. Yes. Yes. Yeah. Every constraint that you want to be careful about, you can put in the capabilities. So, it's good. Yeah. Yes. Yes. Yes, exactly. You can say maximum maximum time of executing. You can say the time. You can say everything. >> Yeah, it is. Thanks there. >> Mhm. Well, you can have both. >> Our idea is like to be safe but not to be annoying. Imagine every time you had to read something. Oh, I had to approve every time. You're going to hate us, you know. So the idea is like a host for example or inclus sorry I spoke in Spanish include um or like maybe a host like someone specific you want like for example let's say co can do everything and then like are recently joined just have like this specific access so you can do it like by user policies as I was talking about or you can do it like host policies. So you have to be like in the middle I think of like good UX uh the good user experience but also secure enough >> but ultimately >> yeah is the ser yeah yeah yeah because uh agent what we're doing like as I said you can try it out uh with the server part is the one going to verify the agent like back with the users going to verify the policies we're going to verify has access or not so yeah all the time verifying so Great. Um, so the whole idea was to show you this. Uh, I was trying to ask the to send. Um, I need to confirm. So you see, so I here I have the request. I didn't accept it. So let's say I deny it. It will be like the same. I just did. So ideally he wouldn't. You see that's red. Okay. So it's working good. So he wants me to allow it and I'm going to I'm going to So can you tell me agent status? So you can have all the time like track down what agent is doing if it's revoked or not. Yeah. >> Oh, are you saying if you have for example a skill that is saying to use the MCP server differently >> directly? >> Yeah. Well, actually what we are doing is we are infor in this just an example for you to see how the protocol is doing just like a demo but you can enforce for example that the agent the only thing that can use um is the MCP tools in this case that's what we did with the plug-in but yeah you have like for our next protocol it's going to be like more uh more cap down so the only way the agent can go out and ask for services is through the agent out protocol so it's a good really good question. Yeah. >> The what? Sorry. >> The proxy >> here. >> Yes. Uh you have this in the directory. Now you can use it like when you log into for example you are connecting a lot of services in the directory. So the agent when it connects to the MCP can know all the capabilities that it can do. So inside of the MC the proxy you can see for example the Gmail you can see all the capabilities that agent can do. You can see like the agents doing stuff the logs and everything. So every log is like cut down by provider. Okay. Okay. Um and about that um our actually proxy is just a directory. It's not a real proxy for us like proxy is a really bad idea. It's not scalable because proxy uses data. So in this case it's just like a directory matching intent with capabilities. Okay. Um so so back again if you want to try it you can like live you can use like the plugin the SDK. It's really nice because we started like from the problems and now actually the solutions right like the discovery authorization and identity. Um this is kind of a what I will show you guys like MCP how to connect it. Um the SDK side with the MCP is the one that is creating the the the keys and assign it to the to the agents and the server side is like verifying authorizing grant um giving the grants that are authorized by the user and and so on. So for me the most interesting thing of all is we need to stop giving credentials our credentials to our agents we need to give them authority this should we stop saying like pretend to be me instead of saying like act for me within these limits. So we are almost in the end. If you have any questions, something that pop into your mind or it could be also an addition of what I'm saying. I don't know if you ever thought of this. Do you think it's a good idea that we implement something like this? I'm not saying this one, but maybe. Yeah. Okay. The idea is that this is open for everyone. So I would love you guys to join us on Discord or you can send me a message, send me an email, be in the channel like be active because if we improve this for all it's going to be good for all of us. Yes. >> Yes. >> Yes. Yes, please. And please do. Yes, please do. Sure. >> No, it's totally diagnostic. >> Yes, >> exactly. That's the idea. >> Yes. Yeah, that's on our B2 and that's our prime focus now. So, yeah, that's a great idea. >> Great. Any anyone else? Yes. >> No, it's different. >> Yeah. >> No, we also I mean we have like as an inspiration like everything that's out there, but it's not the same. It's different. Yeah. Because they are not still treating ancient as a principle. We are treating nations as a principle. They have their own identity. So from that it's different in that way. >> I don't know. We don't I don't have that information. Yes. >> Sorry. What? >> Oh yeah. You see I it's connected because of the discovery but it's still the same like for me the most important part is like the Asian B principles have their own identity AI gateway doesn't have doesn't do that yet I hope it does but the whole idea is to have like traceability have the whole life cycle and to be able to track down and hunt if you want an agent so that you only have if you have identity on on each agent. and AI gateway is not providing that. Sure. Is there any more questions? Okay. Well, you can reach me in the that's my email if you want to email you want to contribute together would be nice. Uh that's my link in and the discord channel from the whole Asian protocol. Okay. Thank you so much. It's been a nice one. [applause] >> [music]

Frontier News · by Hyperjump Technology