Overview
Most AI agent security lives in the prompt: “don’t call this tool unless…”. That’s a hint, not a security boundary. This project moves the boundary to the API layer by giving every agent its own identity and making each downstream call carry a token the API can verify on its own: audience, scope, signature, and expiry.
When one agent hands work to another, the chain of who delegated to whom survives the hop. After the fact, you can prove which user authorized an action, which agent executed it, and how the authority was passed.
The full write-up is in Securing AI Agents in Practice.
What the Demo Does
A guest chats with a hotel assistant. Two agents act on the guest’s behalf:
- Hotel assistant agent: books a room using the user’s On-Behalf-Of (OBO) token, obtained through an OAuth 2.0 authorization code flow with PKCE. The token records the user in
suband the agent inact.sub, and is scoped tocreate_bookingsfor the hotel API only. - Taxi booking agent: books an airport taxi after the room is confirmed. It exchanges the assistant’s token at a custom Security Token Service (RFC 8693) for a chained token: same user in
sub, both agents nested inact, audience rebound to the taxi API, and scope narrowed totaxi_booking. The user never sees a second login.
Key Features
- Agent identity: each agent authenticates as itself instead of sharing a service account.
- Just-in-time authorization: sensitive actions require a user-approved, short-lived, single-audience token. No standing permissions.
- Nested delegation chains: the
actclaim is nested rather than overwritten, plus a flatdelegation_chainfor log indexing. - API-side enforcement: resource servers validate signature, audience, scope, and expiry, and reject anything that doesn’t match.
- Live audit dashboard: watch
sub,act,aud, and scope change on every tool call.
Architecture
Six services, all running in Docker:
| Service | Role |
|---|---|
frontend |
React chat app with Asgardeo login |
assistant-agent |
LangGraph agent (Gemini) with a SecureToolNode that injects OBO tokens or triggers token exchange |
backend |
Hotel booking API; tells user-direct bookings apart from agent-initiated ones |
taxi-booking-backend |
Taxi API with multi-issuer JWKS, audience binding, and recursive act parsing |
token-exchange-service |
Custom RFC 8693 STS that builds the nested delegation chain |
agent-monitor |
Live audit dashboard of the delegation chain |
Tech stack: Python, TypeScript/React, LangGraph, LangChain, Gemini, Asgardeo (identity provider), OAuth 2.0 / OIDC, JWT, Docker.