Supplementary information for AI agent identities
Key capabilities and benefits
The following table summarizes the key capabilities and benefits of securing your AI-driven solutions using AI agent identities:
| Capabilities | Benefits |
|---|---|
Specialized agent identity: Treats AI agents as distinct entities with unique identities and privileges, rather than using simple impersonation. |
Granular security and least privilege: Eliminates "over-privileged" accounts by applying tailored security policies specific to autonomous entities. |
Streamlined onboarding & lifecycle: Manual onboarding using OAuth 2.0 grant flow or automated onboarding via Dynamic Client Registration (DCR), with centralized lifecycle management. |
Operational efficiency: Reduces administrative overhead and "agent sprawl" while ensuring agents can be instantly revoked or rotated. |
Advanced access and token delegation: Sophisticated token exchange mechanisms to manage "on-behalf-of" permissions and resource scoping. |
Reduced complexity: Simplifies the "who, what, and how" of agent access using low-code tools, ensuring secure delegation without custom-coded security logic. |
Dedicated agent observability: Isolated logging and monitoring that separates agent telemetry from end users and static applications. |
Clear auditability: Provides an auditable trail of AI activity, making it easy to prove compliance and understand exactly when an AI agent acted autonomously. |
AI agent identity managed object types
The following table summarizes the managed object types related to AI agent identities:
| Managed object type | Description |
|---|---|
AI agent |
This is distinct from the user managed object type. It provides unique AI agent identities and allows for clear accountability and distinct audit trails for their activities, with Advanced Identity Cloud acting as the dedicated Identity Provider (IdP). |
AI agent privilege |
This lets AI agent identities have delegated privileges, ensuring that they can only access specific applications, act for specific end users or groups of end users, and use specific OAuth 2.0 scopes. |
Object model
The AI agent identity object model spans two systems: access management (system of record) and identity management (privileges store).
When you create an AI agent identity in access management, Advanced Identity Cloud automatically creates a linked identity management <realm>_aiagent object and records its UUID in the aiAgentIdentityUid field on the access management OAuth 2.0 client.
| Object type | System | Purpose |
|---|---|---|
OAuth 2.0 client (AI agent identity) |
Access management |
The agent’s OAuth 2.0 identity; defines grant types, scopes, and authentication method. Deleting this object cascades to all linked identity management objects. |
|
Identity management |
Created automatically when an access management AI agent identity is created. Stores the agent’s identity management UUID, which is referenced by privilege objects. |
|
Identity management |
Links the AI agent identity to a specific application ( |
Cascade behavior
Access management is the system of record for the entire AI identity object graph. Deleting an AI agent identity using the access management endpoint cascades immediately to:
-
Delete the linked identity management
<realm>_aiagentobject. -
Delete all
<realm>_aiagentprivilegerecords that reference the agent.
Application and user objects are independent and aren’t affected.
Key consequences:
-
Single-step deletion: Associated privileges are removed automatically without needing manual cleanup, preventing orphaned records.
-
Non-recoverable: Recreating an identity with the same client ID generates a new identity management UUID. Previous privileges are permanently lost and must be reconfigured.
Privilege evaluation
At token-exchange time, Advanced Identity Cloud evaluates the privileges of an AI agent identity in the following order:
-
Audience check: The token exchange request includes an
audienceparameter containing the application’s OAuth 2.0 client ID. Advanced Identity Cloud matches this against privileges whereresource.ssoEntities.oidcIdequals the audience value. -
Permission check: The requested scopes must be a subset of the scopes in the privilege’s
permissions.valueslist. Ifvaluesis empty, any scope permitted by both the AI agent identity and the application is allowed. -
Subject check: For on-behalf-of flows, the subject token’s user identity must appear in the privilege’s
subjectslist. For autonomous flows, thesubjectslist must be empty (or the privilege must have no subject restriction). -
Scope check: The final granted scopes are the intersection of: the scopes in the privilege, the scopes on the application, and the scopes on the AI agent identity.
| Privilege changes take effect after the privilege cache expires (10 seconds by default). A privilege you create or update may not be applied immediately in the next token exchange. |
API error reference
Common error responses when managing AI agent identities via the REST API:
| HTTP status | Condition | Resolution |
|---|---|---|
|
Missing required field in privilege request body (for example, no |
Ensure both |
|
Access token is missing, expired, or has insufficient scope |
Obtain a new service account access token with the required scopes ( |
|
AI agent identity or privilege does not exist at the specified path |
Verify the agent client ID or privilege UUID in the URL. Use the list endpoint to confirm the object exists. |
|
|
The AI agent identity already exists. Omit |
|
A privilege reference points to an identity management object that doesn’t exist (for example, an invalid AI agent identity UUID or application UUID) |
Verify the UUIDs in |
|
The AI agent feature is not enabled |
Verify that the AI agent feature is enabled. Learn more in Enable the AI agents feature in your tenant environment. |