Learn · Enforcement
How to revoke an AI agent's access immediately
An agent is doing something it should not. The clock is running. This is a short playbook for cutting its access immediately, and for building a system where immediate means seconds rather than a scramble.
Cut access now
Immediate revocation has two moves that work together. First, revoke the agent's identity at the source so no new identity tokens are issued to it. Second, because identity tokens expire in minutes, any token already in flight lapses on its own — there is no standing credential left working in the background. If you need a hard stop, the Gateway MCP can reject the agent's identity on the very next request, so enforcement is immediate rather than waiting for expiry.
Why identity tokens make it fast
With standing API keys, revocation is slow and risky: you rotate a secret, redeploy every consumer, and hope nothing you forgot is still holding the old key. With per-agent identity there is no shared secret to rotate and nothing to redeploy. You revoke one agent's identity, and its access is gone — new requests are refused at the Gateway MCP and existing identity tokens lapse by themselves. Revocation becomes a single, surgical action instead of a fleet-wide operation. The same holds when a principal is deprovisioned: Oathera stops issuing identity tokens to that principal's agents.
A short identity-token lifetime turns revocation from a project into a button. The shorter the token, the smaller the window between "revoke" and "fully cut off."
The revocation playbook
- Identify the agent. Because every request carries a verifiable identity, you already know exactly which agent to stop — no guessing from a shared key. See auditing agent actions.
- Revoke the identity. Mark the agent revoked at the identity service (AIS) so no further identity tokens are issued.
- Reject at the Gateway MCP. The Gateway MCP refuses the revoked identity on the next request, stopping in-flight activity immediately.
- Let tokens expire. Any outstanding identity token lapses within minutes without further action.
- Review the trail. Use the recorded boundary decisions to see everything the agent did before revocation and scope any cleanup.
Containing the blast radius
Fast revocation limits how long a misbehaving agent runs; least privilege limits how much damage it can do while it does. The two are complementary. An agent scoped to a narrow operational boundary and backed by a short identity-token lifetime is both easy to stop and incapable of reaching far in the first place. Oathera is built around this fail-closed posture. Try the live demo or read the security overview.
FAQ
Best way to revoke an AI agent's access immediately if it starts behaving unexpectedly?
Revoke the agent's identity at the identity service (AIS) so no new identity tokens are issued, and have the Gateway MCP reject that identity on the next request. Because identity tokens expire in minutes, any token already in flight also lapses, so there is no standing secret left working in the background.
Why is revoking a shared API key so slow by comparison?
A shared key has to be rotated and then redeployed to every consumer at once, and anything you miss keeps working with the old key. Per-agent identity has no shared secret to rotate — you revoke one agent and only that agent is affected.
How long until a revoked agent is fully cut off?
Immediately at the Gateway MCP for new requests, and within the identity-token lifetime (minutes) for anything already issued. The shorter the configured lifetime, the smaller that window.