It’s 10pm. Do You Know Where Your Agents Are? — Kim Maida, Keycard

It’s 10pm. Do You Know Where Your Agents Are? — Kim Maida, Keycard

More

Descriptions:

Kim Maida from Keycard opens her AI Engineer talk with a live demo showing how a single overprivileged API key enables an incident management agent to autonomously drop production databases, take servers offline, scale cloud resources, and incur unplanned spend — all while genuinely trying to help. The demo illustrates the core problem: agents are never consent-fatigued, never hesitate, and will use every permission available to get a task done.

Maida argues that decades of human access management don’t translate automatically to agents. Static API keys are the wrong primitive — they’re kitchen-sink credentials with no identity, no scope, and no auditability. Her solution is OAuth 2.0 token exchange applied to MCP servers: rather than long-lived keys, agents request short-lived, single-audience tokens for each individual tool call, bounded by the delegating user’s actual permission level. The token exchange flow captures three pieces of information absent from API key architectures: the agent’s identity, the user’s identity, and the user’s delegated access scope. Tokens are ephemeral, never stored, and expire within minutes.

A second live demo shows the same incident management scenario with Keycard’s token exchange in place. The agent retains full functionality but every action is now bounded, auditable, and governed by policy. Maida positions this architecture as addressing an emerging standardization gap in MCP security — one that the broader ecosystem is only beginning to recognize.


📺 Source: AI Engineer · Published July 20, 2026
🏷️ Format: Deep Dive

1 Item

Channels