Non-Human Identity

Give your AI agents a real identity.

Agents act on behalf of users and call tools on their own. HelixIAM makes every agent a first-class subject — with delegation, attenuation, consent, and a kill-switch. This is the identity layer agentic software has been missing.

An identity per agent

Register each agent as its own subject with an owner, lifecycle, and scoped credentials — not a shared service account nobody can trace.

  • Agent registry & lifecycle
  • Owned, named, auditable
  • Scoped token issuance
  • Instant disable / kill-switch

On-behalf-of, done right

When an agent acts for a user, HelixIAM mints an RFC 8693 token carrying the user as sub and the agent as act — with realm access intersected down to what both are allowed.

  • RFC 8693 token exchange
  • sub = user, act = agent
  • Scope = intersection of both
  • Consent capture + audit trail

Attenuate & contain

Delegated tokens can only ever narrow, never widen. Cap scope, lifetime, and audience — and revoke a runaway agent everywhere in one click.

  • Monotonic scope narrowing
  • Short-lived, audience-bound tokens
  • may_act delegation policy
  • Realm-wide kill-switch

MCP-ready

Built on OAuth 2.1 with the emerging agent-auth standards, so your Model Context Protocol tools and autonomous workflows authenticate the same way everything else does.

  • OAuth 2.1 foundation
  • Protected-resource metadata (RFC 9728)
  • Dynamic client registration
  • Works with MCP tool servers

See HelixIAM on your own stack.

A 30-minute demo: realms, agents, workload identity, and a live migration off Keycloak — mapped to your use case.

No credit card. Self-hostable. Engineered in Europe.