
Whose Token Is It? Solving the MCP and OAuth2 Identity Problem for AI Agent Deploys
Every deploy, rollback, or scale call an AI agent makes must answer who authorized it: the developer, the agent, or the tenant. This post maps the three-identity model, the July 2026 MCP authorization rules, and the token-exchange pattern that keeps deploy-from-chat auditable.

Pangolin Puts SSO and WireGuard in Front of LLM Access Instead of API Keys: What Tunnel-Based Identity Means for Agent Credential Hygiene
Pangolin's AI Gateway authenticates LLM access with SSO-backed WireGuard tunnels instead of static API keys, and joins self-hosted models to the same gateway as public ones. Here's how the mechanism works, how it compares to Tailscale Aperture, and what it changes in your threat model.

What the MCP 2026-07-28 Spec Broke: Your Server's Auth Fix Checklist
The MCP 2026-07-28 spec turned every remote server into a formal OAuth 2.1 resource server, and working servers now fail closed. Here is the six-item fix checklist: metadata endpoint, 401 pointer, audience enforcement, issuer validation, and the DCR-to-CIMD plan.

Render Killed the Pasted AWS Key. Your Self-Hosted PaaS Is Now on the Clock.
Render's July 2026 OIDC releases made keyless auth to AWS, Anthropic, and OpenAI a GA platform feature. Here's the trust-chain machinery behind it and the two concrete paths — cluster-issuer federation or SPIFFE/SPIRE — for matching it on machines you own.

No More AI API Keys in Env Vars: Reproducing Render's Short-Lived Anthropic and OpenAI Credentials on Your Own Kubernetes
Render's July 2026 Managed OIDC trades long-lived Anthropic and OpenAI API keys for short-lived tokens minted from platform identity — and the same exchange runs on any Kubernetes cluster via projected service-account tokens, issuer registration, and a JWKS upload. The concrete recipe plus what Render still operates for you.

An Agent That Runs a Company Holds the Company's Credentials: 4 Identity Controls Pion's Launch Demands
Andon Labs' Pion hands persistent agents email, phone, and banking to run real businesses. Four controls — per-agent identity, least-privilege credential vending, spending governors, and signed audit trails — must come first, and deploy pipelines already show how.

Six Coding Agents on a Private Network: Threat-Model the Credential Blast Radius Before You Copy Railway's Sandbox
Railway's June 2026 sandboxes preinstall six coding agents with private-network reach to production data. Four Kubernetes controls — per-session identities, default-deny egress, approval-gated mutations, and auditable teardown — keep the convenience without the nine-second-wipe blast radius.

Who Sent This Agent, and Whose Authority Is It Spending? What the IETF's AIMS Draft Means for MCP Server Auth
The IETF's AIMS draft composes WIMSE, SPIFFE, and OAuth 2.0 into one agent identity model. Here is what a deploy-from-chat MCP server should borrow — and how to prove which agent called and whose authority it spent.

Authorizer Puts Agents on the Org Chart: A2A Token Exchange, OAuth-2.1 MCP, and Secretless Kubernetes Identity
Authorizer 2.4 gives AI agents first-class identities: RFC 8693 delegation with nested actor chains, an MCP server behind OAuth 2.1 with audience-bound tokens, and secretless Kubernetes workload auth — a credential model where agents hold scoped delegations instead of god-keys.