Skip to main content

Arkodomo — Identity Broker for the Agentic Era

Arkodomo solves a problem that existing IAM tools don't: how does an AI agent prove its identity to an MCP server without holding long-lived secrets?

The problem​

AI agents cannot complete browser-based OAuth flows. They run unattended, at scale, across multi-agent pipelines — and if they hold long-lived credentials, a single compromised agent means those credentials are exposed until someone notices and rotates them.

The common workaround — embedding API keys or service-account tokens in agent configuration — creates unacceptable blast radius. Every agent becomes a potential credential leak.

How Arkodomo works​

Arkodomo acts as a standards-based intermediary between your agents and your MCP servers:

  1. Register your MCP servers and agents in the Arkodomo console.
  2. Agents authenticate using a cryptographic workload identity — a SPIFFE SVID, an AWS/GCP/Azure OIDC token, or a Kubernetes service account token. No passwords, no secrets embedded in code.
  3. Arkodomo evaluates your authorization policy (OPA Rego) and issues a short-lived, audience-restricted JWT scoped to the target MCP server.
  4. The agent presents that JWT as a standard Bearer token. The MCP server validates it against Arkodomo's JWKS endpoint — no Arkodomo SDK required.
Agent runtime Arkodomo MCP Server
│ │ │
│ POST /oauth2/token │ │
│ (workload credential) ───▶ │ │
│ │ evaluate OPA policy │
│ ◀─── short-lived JWT ───── │ │
│ │ │
│ Bearer: <jwt> ─────────────────────────────────────▶ │
│ │ GET /oauth2/jwks ◀─── │
│ │ (cached, ~5 min) │
│ │ ────────────────────▶ │

Tokens expire in minutes. If a token is compromised, it's worthless before you've even noticed.

Key properties​

PropertyDetail
Token TTL5 minutes default, 1–60 min configurable per agent
Signing algorithmRS256 / ES256 via AWS KMS — private key never leaves KMS
AttestationSPIFFE JWT-SVID, AWS OIDC, GCP OIDC, Azure OIDC, Kubernetes SA
AuthorizationOPA Rego policies — version-controlled, testable, auditable
StandardsOAuth 2.1, RFC 8693 Token Exchange, RFC 8707 Resource Indicators, JWKS
AuditEvery issuance, rejection, and revocation is a tamper-evident audit event

What you need Arkodomo for​

  • Your AI agents need to call MCP servers without holding API keys
  • You want to enforce policy on which agents can call which tools with which scopes
  • You need an audit trail of every token issuance across your agent fleet
  • You're running multi-agent pipelines and need a consistent identity layer

What you don't need Arkodomo for​

  • Simple API key auth for a human-operated service (just use an API key)
  • Single-user scripts running under your own identity

Ready to get started? Head to the Quickstart →