← Browse

World's Fair 2025

How to Secure Agents using OAuth — Jared Hanson (Keycard, Passport.js)

Overview

This talk addresses the critical need for robust security in AI agents by advocating for the adoption of OAuth 2.0. It highlights the current security risks associated with broadly scoped, long-lived API keys used by agents and proposes OAuth as a solution to transition from static secrets to dynamic, delegated access. The discussion emphasizes that while OAuth is complex, its core principles are straightforward and essential for securing increasingly connected and useful AI agents.

Who should watch

Key takeaways

Notable quotes

*Agents that are more connected are more useful.*
*We can give agents broad-based access and accept security risks or we can limit their capabilities and sacrifice business value.*
*The main benefit flows to the APIs. They don't have to care about anything to do with authentication anymore.*

Watch on YouTube →

Unofficial community note. Prefer the recording for nuance.