Connect · Agent identity

Every agent action,attributed.

Speakeasy ties every agent session to the person driving it. Sign-in runs through the identity provider you already operate, every action is checked against policy your security team can read, and every allow-or-deny decision is recorded under a real name.

Trusted byVerizonMistralFivetranDocuSignLaunchDarklyPlanetScale

01 · The problem

Agents multiply what one person can do. Accountability has to keep up.

Most gateways
Who's driving?
One shared service account for every agent
Allowed to make this call?
A server-level allowlist, the same for everyone
Who can answer later?
“The agent used the service account”
With agent identity
Who's driving?
A real user, signed in through your IdP
Allowed to make this call?
Policy scoped to the person, the system, and the action
Who can answer later?
The named user and the exact rule that allowed it

We built our access controls on IAM. When we rolled out agents, none of them worked. Speakeasy let us extend those controls to all our AI usage.

Thierry Dang

Security Operations, MoonPay

MoonPay

02 · The solution

The missing identity layer
Connect agents to people

Speakeasy sits between agents and the systems they act on. Identity comes from your directory, policy is written in language the owning team can read, and every decision leaves a record that stands up to an audit.

Signs in throughOktaMicrosoft Entra IDAuth0WorkOSGoogle WorkspacePing IdentityAny SAML / OIDC

03 · The results

Accountability you can measure

Putting identity in front of every agent moves the numbers security cares about.

100%

Agent actions attributed

Every action recorded under a named person from your directory.

0

Shared service accounts

Agents inherit identity from the person driving them.

2 days

To roll out org-wide

Sign-in through the IdP you already run, with nothing custom to build.

I don't want anyone using internal UIs or opening SaaS apps. The moment someone shifts a workflow to being AI-native it drops from a two-hour task down to minutes.

Shreyas Kumar

Co-founder, Fermat

Fermat

Questions

What is agent identity?
Agent identity ties every AI agent session to the real person driving it. Each session authenticates through your identity provider rather than a shared service account, every action is checked against that person's roles, and every decision is recorded under their name. When security asks who issued a refund, the answer is a named user and the rule that allowed it.
How do agents authenticate through our IdP?
Agent traffic stays anonymous until the person behind it signs in. The agent's client, whether Claude, Cursor, or a custom harness, starts a standard OAuth flow, and the person signs in through your identity provider. Speakeasy supports OAuth 2.1 with PKCE and dynamic client registration, so modern clients work without custom integration.
Which identity providers are supported?
Okta, Microsoft Entra ID, Auth0, WorkOS, Google Workspace, Ping Identity, and any SAML or OIDC provider. With Directory Sync connected, users, groups, and attributes stay current, and deprovisioned users lose their agent access immediately.
What does the audit trail capture?
Every authorization check records who made the call as a directory identity, what access was required against which system and tool, and whether the outcome was allow or deny. Each record carries the caller's directory snapshot from the moment of the call, so the answer holds up even after roles change. See the governance guide for the full authorization path.

AI everywhere.

Control here.