Skip to main content
OATHERA logo OATHERA
PlatformControl plane and enforcement plane. FeaturesAnchor keys, identity tokens, operation proofs, boundary decisions. IntegrationsOIDC, SPIFFE, OPA, NVIDIA OpenShell, OpenTelemetry. Use casesWhere Oathera gives every AI agent an identity bound to its host.
DocsIdentity MCP, Gateway MCP, MCP bundle, BYOA. LearnGuides on giving AI agents an identity bound to their host. GlossaryAccepted terms: sponsor, principal, anchor key, identity token. GitHub ↗Open-source code and examples. Live demo ↗See the identity flow run end to end.
SecurityHost binding, fail closed, and why Oathera never proofs people. ContactTalk to the Oathera team.
Privacy PolicyHow we handle data. Terms of ServiceTerms for using Oathera. Data Processing AgreementOur DPA for customers. Sub-processorsThird parties we rely on.
Request access

Learn · Enforcement

How to revoke an AI agent's access immediately

An agent is doing something it should not. The clock is running. This is a short playbook for cutting its access immediately, and for building a system where immediate means seconds rather than a scramble.

On this page

  1. Cut access now
  2. Why identity tokens make it fast
  3. The revocation playbook
  4. Containing the blast radius
  5. FAQ

Cut access now

Immediate revocation has two moves that work together. First, revoke the agent's identity at the source so no new identity tokens are issued to it. Second, because identity tokens expire in minutes, any token already in flight lapses on its own — there is no standing credential left working in the background. If you need a hard stop, the Gateway MCP can reject the agent's identity on the very next request, so enforcement is immediate rather than waiting for expiry.

Why identity tokens make it fast

With standing API keys, revocation is slow and risky: you rotate a secret, redeploy every consumer, and hope nothing you forgot is still holding the old key. With per-agent identity there is no shared secret to rotate and nothing to redeploy. You revoke one agent's identity, and its access is gone — new requests are refused at the Gateway MCP and existing identity tokens lapse by themselves. Revocation becomes a single, surgical action instead of a fleet-wide operation. The same holds when a principal is deprovisioned: Oathera stops issuing identity tokens to that principal's agents.

A short identity-token lifetime turns revocation from a project into a button. The shorter the token, the smaller the window between "revoke" and "fully cut off."

The revocation playbook

  1. Identify the agent. Because every request carries a verifiable identity, you already know exactly which agent to stop — no guessing from a shared key. See auditing agent actions.
  2. Revoke the identity. Mark the agent revoked at the identity service (AIS) so no further identity tokens are issued.
  3. Reject at the Gateway MCP. The Gateway MCP refuses the revoked identity on the next request, stopping in-flight activity immediately.
  4. Let tokens expire. Any outstanding identity token lapses within minutes without further action.
  5. Review the trail. Use the recorded boundary decisions to see everything the agent did before revocation and scope any cleanup.

Containing the blast radius

Fast revocation limits how long a misbehaving agent runs; least privilege limits how much damage it can do while it does. The two are complementary. An agent scoped to a narrow operational boundary and backed by a short identity-token lifetime is both easy to stop and incapable of reaching far in the first place. Oathera is built around this fail-closed posture. Try the live demo or read the security overview.

FAQ

Best way to revoke an AI agent's access immediately if it starts behaving unexpectedly?

Revoke the agent's identity at the identity service (AIS) so no new identity tokens are issued, and have the Gateway MCP reject that identity on the next request. Because identity tokens expire in minutes, any token already in flight also lapses, so there is no standing secret left working in the background.

Why is revoking a shared API key so slow by comparison?

A shared key has to be rotated and then redeployed to every consumer at once, and anything you miss keeps working with the old key. Per-agent identity has no shared secret to rotate — you revoke one agent and only that agent is affected.

How long until a revoked agent is fully cut off?

Immediately at the Gateway MCP for new requests, and within the identity-token lifetime (minutes) for anything already issued. The shorter the configured lifetime, the smaller that window.

See it live More guides

← Back to Learn
OATHERA logo Oathera

Know Your Agent — the category Oathera defines. Every agent gets a verifiable identity and an enrollment approval before it acts.

Product

  • Platform
  • Features
  • Integrations
  • Use cases

Developers

  • Docs
  • Learn
  • GitHub
  • Demo

Company

  • Security
  • Contact
  • Careers soon

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Sub-processors
© 2026 Oathera · Know Your Agent

Cookie preferences

We use cookies to run this site and, with your consent, to understand usage and improve Oathera. Strictly necessary cookies are always on; you can choose whether to allow analytics and marketing cookies below.

  • Strictly necessaryAlways on

    Required for the site to work — security, load balancing, and remembering your cookie choices. These cannot be switched off.

  • Help us measure traffic and see how the site is used, so we can improve it. No personal profiles are built.

  • Used to make messages about Oathera more relevant across other sites. Off unless you turn it on.