AI Agent Authentication and Authorization (IETF Internet-Draft)
datatracker.ietf.org
AI Agent Authentication and Authorization (IETF Internet-Draft)
1–7 of 7 posts
Re: AI Agent Authentication and Authorization (IETF Internet-Draft)
#2> The Large Language Model MUST NOT have access to an agent's credentials or to credentials that may be needed to access tools and services. This prevents the Large Language Model from using, exposing, or being manipulated via prompt injection into disclosing the credentials.
I knew this but I just went ahead doing it wrong anyway. As a stop gap I gave all my secrets handles so the LLM and I could discuss them but I am just pretending that my agent is trustworthy. We have some big names here so hopefully there is better tooling in our future.
Re: AI Agent Authentication and Authorization (IETF Internet-Draft)
#3This is at the bottom of section 8 > The Large Language Model MUST NOT have access to an agent's credentials or to credentials that may be needed to access tools and services. This prevents the Large Language Model from using, exposing, or being manipulated via prompt injection into disclosing the credentials. I knew this but I just went ahead doing it wrong anyway. As a stop gap I gave all my secrets handles so the…
Re: AI Agent Authentication and Authorization (IETF Internet-Draft)
#4Re: AI Agent Authentication and Authorization (IETF Internet-Draft)
#5This is at the bottom of section 8 > The Large Language Model MUST NOT have access to an agent's credentials or to credentials that may be needed to access tools and services. This prevents the Large Language Model from using, exposing, or being manipulated via prompt injection into disclosing the credentials. I knew this but I just went ahead doing it wrong anyway. As a stop gap I gave all my secrets handles so the…