IAM-05

Tożsamość i dostęp

Tożsamość agentów nieosobowych — tożsamość kryptograficzna, OAuth/OIDC, bezpieczeństwo oparte na uprawnieniach, kradzież tokenów i egzekwowanie zero-trust.

Agent identity flow: an agent authenticates to an issuer, receives a short-lived scoped token, and presents it to a resource that verifies scope before actingagentnon-human idtoken issuerOAuth / mTLSresourceverifies scopeauthenticatescoped tokenleast privilege: the token grants only this task, expires fast, and is bound to the agent's identity
Filar

Tożsamość kryptograficzna agentów AI: mTLS, JWT i SPIFFE/SPIRE w praktyce

Dlaczego agenty AI potrzebują weryfikowalnej tożsamości nieosobowej i jak ją nadawać za pomocą mTLS, tokenów JWT oraz SPIFFE/SPIRE. Przewodnik wdrożeniowy.

Czytaj

Inne obszary