Platform
One identity model for every agent you run.
OATHERA treats an AI agent as a first class principal. Before it can touch anything, it must have an identity it can prove, an owner who answers for it, and a boundary that limits it. The control plane issues, enforces, observes and revokes all three.
Why agent authentication breaks
Every AI application starts with a key. As agents move from a proof of concept into production, those keys and secrets multiply across repos, config files and environments, usually with no plan for rotation, revocation or ownership. The result is a fragile foundation: hardcoded credentials scattered everywhere, powering software that reads confidential data and acts across your own systems and third-party services.
The deeper issue is that a static key is a bearer credential, built on an authentication model that predates autonomous software entirely — whoever holds it gets whatever it can reach, and the system has no way to tell a legitimate caller from someone who copied the key. That single assumption is what turns a leaked token into a breach, and it is the assumption OATHERA removes.
OATHERA treats an AI agent as a first-class principal. Before it can touch anything, it must have an identity it can prove, an owner who answers for it, and a boundary that limits it. The control plane issues, enforces, observes and revokes all three.
1. Agent identity
A credential that cannot be borrowed.
Each agent generates its own Ed25519 key pair inside your environment. OATHERA issues short lived identity tokens bound to that key and to the attested machine, and requires a fresh RFC 9421 signature over every request. Steal the token and it fails: the thief has neither the key nor the machine. Identities interoperate with OIDC and SPIFFE, so agents fit the workload identity fabric you already run.
2. Accountable ownership
No orphan agents.
Every agent is enrolled against a named human or organizational owner. The owner approves the agent once, and that approval is sealed into a tamper evident audit certificate. Ownership travels with the identity, so every log line, policy decision and alert answers the question "whose agent is this?" When an owner leaves or a team changes, OATHERA flags the agents that need a new owner or a shutdown.
3. Operational boundary
A perimeter drawn around each agent.
The operational boundary is the high level envelope of what an agent may do: which tenants, systems, data classes and operations are in scope, and which are never in scope. It is set at approval and travels inside the agent's identity. Two layers enforce it:
- Fine grained authorization with OPA. Open Policy Agent evaluates every request against the boundary and your Rego policies, down to the tenant, agent, task, capability, operation and resource.
- Runtime confinement with NVIDIA OpenShell. OpenShell sandboxes confine what the agent's process can reach on the host: files, network destinations and privileges, enforced outside the agent where it cannot override them.
Architecture at a glance
OATHERA splits cleanly into seven parts. Four run entirely on your side; three are OATHERA services. The agent's private key is created in your environment and never leaves it, and your data never crosses to OATHERA — the service verifies and decides, but is never given a route into your systems.
4. Control plane
The system of record for your agents.
The OATHERA control plane is where agents are enrolled, approved, scoped, monitored and revoked. It holds the inventory of every agent, its owner and its boundary, distributes policy to gateways and sandboxes, and collects telemetry from every enforcement point into one trace.
Defense in depth
| Layer | Question it answers | Enforced by |
|---|---|---|
| Request | Is this really the agent it claims to be, on the machine it was issued for? | OATHERA gateway, sender constrained tokens, RFC 9421 signatures |
| Policy | Is this exact action allowed for this agent, owner and task? | Open Policy Agent |
| Runtime | Can the agent's process physically reach this file, host or privilege? | NVIDIA OpenShell |
| Record | Can we prove what happened afterward? | OATHERA control plane, audit certificates |