{
  "id": 13547695,
  "title": "theAuth for AI Agents: Identity and Scoped Permissions",
  "url": "https://urgent.news/2026/10/10/theauth-for-ai-agents-identity-and-scoped-permissions",
  "topic": "ai",
  "section": "AI",
  "published": "2026-10-10T21:53:41.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/thegdsks/theauth-for-ai-agents-identity-and-scoped-permissions-3523"
  },
  "original_language": "en",
  "account": "TheAuth is open-source authentication software designed for both AI agents and humans. The repository can be found on GitHub, along with documentation and a quickstart guide. During a recent incident, a single API key was discovered in four different locations, belonging to a human user who had access to read and write sensitive information. The challenge lies in identifying which of the four instances conducted a particular action, such as deleting data on a specific day. The existing logs only indicate that the human user performed the action.\n\nThis guide aims to address the issue by assigning each AI agent its own unique identity, token, and permissions. By the end of the guide, a runnable script will be available for creating agents, restricting unauthorized actions, logging every decision, and revoking access to individual agents without affecting others. The guide utilizes theAuth, an open-source TypeScript library, which was partially developed by the author. The guide is the fifth in a series of eight and stands independently, allowing readers to start from this point.",
  "summary": "theAuth is open-source auth for AI agents and humans. Star the repo on GitHub · Read the docs · Run the quickstart · theauth.dev Last spring I found one API key in four places. It sat in a cron job, a Slack bot, a code-review agent, and a notebook a teammate had forgotten about. The key belonged to a human. It could read everything that human could read, and it could write most of it too. Nothing…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}