Listen "Now you see me, now you don't: Ephemeral Auth and AI agents"
Episode Synopsis
Agents are popping up everywhere: tiny bots spinning up for a task, then dying off. They shouldn’t carry long-lived credentials any more than you carry a master key everywhere you go. What if each agent got a just-for-this-mission credential—scoped, temporary, context-aware, and gone when its task ends? That’s ephemeral authentication. In this episode, F5's Lori MacVittie, Joel Moses, and special guest Bill Church dig into why traditional IAM (OAuth tokens, persistent keys) fails in agentic worlds. They’ll show how ephemeral auth can reduce blast radius, prevent credential replay, and force “least privilege in the moment.” Then they walk through how it might be built: token issuance on mission start, embedded attestation, automatic revocation, and scope tunneling per action. And yeah, there are tradeoffs—latency, credential churn, throttling limits. Listen in for the best path forward.Read the arXiv article, A Novel Zero-Trust Identity Framework for Agentic AI: Decentralized Authentication and Fine-Grained Access Control: https://arxiv.org/html/2505.19301v1?utm_source=chatgpt.comFind out more about the importance of policy in payload: https://www.f5.com/resources/white-papers/policy-in-payload-preparing-for-ai-agent-architectures
More episodes of the podcast Pop Goes the Stack
Reshaping the web for AI agents and LLMs
16/12/2025
We're on a brief hiatus, we'll be back soon
21/10/2025
Crossing the streams
07/10/2025
Agentic APIs Have PTSD
30/09/2025
ZARZA We are Zarza, the prestigious firm behind major projects in information technology.