Arkodomo — Identity Broker for the Agentic Era
Arkodomo solves a problem that existing IAM tools don't: how does an AI agent prove its identity to an MCP server without holding long-lived secrets?
The problem
AI agents cannot complete browser-based OAuth flows. They run unattended, at scale, across multi-agent pipelines — and if they hold long-lived credentials, a single compromised agent means those credentials are exposed until someone notices and rotates them.
The common workaround — embedding API keys or service-account tokens in agent configuration — creates unacceptable blast radius. Every agent becomes a potential credential leak.
How Arkodomo works
Arkodomo acts as a standards-based intermediary between your agents and your MCP servers:
- Register your MCP servers and agents in the Arkodomo console.
- Agents authenticate using a cryptographic workload identity — a SPIFFE SVID, an AWS/GCP/Azure OIDC token, or a Kubernetes service account token. No passwords, no secrets embedded in code.
- Arkodomo evaluates your authorization policy (OPA Rego) and issues a short-lived, audience-restricted JWT scoped to the target MCP server.
- The agent presents that JWT as a standard Bearer token. The MCP server validates it against Arkodomo's JWKS endpoint — no Arkodomo SDK required.
Agent runtime Arkodomo MCP Server
│ │ │
│ POST /oauth2/token │ │
│ (workload credential) ───▶ │ │
│ │ evaluate OPA policy │
│ ◀─── short-lived JWT ───── │ │
│ │ │
│ Bearer: <jwt> ─────────────────────────────────────▶ │
│ │ GET /oauth2/jwks ◀─── │
│ │ (cached, ~5 min) │
│ │ ────────────────────▶ │
Tokens expire in minutes. If a token is compromised, it's worthless before you've even noticed.
Key properties
| Property | Detail |
|---|---|
| Token TTL | 5 minutes default, 1–60 min configurable per agent |
| Signing algorithm | RS256 / ES256 via AWS KMS — private key never leaves KMS |
| Attestation | SPIFFE JWT-SVID, AWS OIDC, GCP OIDC, Azure OIDC, Kubernetes SA |
| Authorization | OPA Rego policies — version-controlled, testable, auditable |
| Standards | OAuth 2.1, RFC 8693 Token Exchange, RFC 8707 Resource Indicators, JWKS |
| Audit | Every issuance, rejection, and revocation is a tamper-evident audit event |
What you need Arkodomo for
- Your AI agents need to call MCP servers without holding API keys
- You want to enforce policy on which agents can call which tools with which scopes
- You need an audit trail of every token issuance across your agent fleet
- You're running multi-agent pipelines and need a consistent identity layer
What you don't need Arkodomo for
- Simple API key auth for a human-operated service (just use an API key)
- Single-user scripts running under your own identity
Ready to get started? Head to the Quickstart →