Identity & credentials

A real agent has to authenticate to real systems. The naive way — a pile of environment-variable secrets the process inherits — hands the agent the whole keyring, turns "acting as the user" into impersonation by shared secret, and never asks whose identity to use in the first place. OAP resolves named credentials by need, and makes "whose identity" an explicit, governed choice.

Whose credentials? — the four modes

An agent's tools authenticate as someone. An AgentClass's identityMode decides who:

  • agent — the agent uses its own credentials (an operator account it owns). "Uses an operator account — has its own credentials."
  • userPassthrough — the agent uses the credentials of the person who started the session. "Uses YOUR account — calls services as you."
  • ask — at session start, the person is asked to choose: run as the agent, or run as me.
  • dynamic — an isolated recommender LLM suggests one of the two, but the person still confirms. The recommendation is advisory only.

There is no autonomous "selected" mode: ask and dynamic both end in the same human choice — ask presents it blank, dynamic pre-highlights a suggestion. The resolved answer (always agent or userPassthrough) is what everything at runtime reads.

Go deeper