Skip to main content
OATHERA logo OATHERA
PlatformControl plane and enforcement plane. FeaturesAnchor keys, identity tokens, operation proofs, boundary decisions. IntegrationsOIDC, SPIFFE, OPA, NVIDIA OpenShell, OpenTelemetry. Use casesWhere Oathera gives every AI agent an identity bound to its host.
DocsIdentity MCP, Gateway MCP, MCP bundle, BYOA. LearnGuides on giving AI agents an identity bound to their host. GlossaryAccepted terms: sponsor, principal, anchor key, identity token. GitHub ↗Open-source code and examples. Live demo ↗See the identity flow run end to end.
SecurityHost binding, fail closed, and why Oathera never proofs people. ContactTalk to the Oathera team.
Privacy PolicyHow we handle data. Terms of ServiceTerms for using Oathera. Data Processing AgreementOur DPA for customers. Sub-processorsThird parties we rely on.
Request access

Glossary

The Know Your Agent vocabulary, defined precisely.

Oathera draws lines that others blur. This glossary defines every term in one place and groups it by maturity, so what runs today is never confused with what is coming or what is on the roadmap. Each term has its own anchor, so a definition anywhere on the site can link straight to it.

On this page

  1. Running — available today
  2. Coming — not yet available
  3. On the roadmap

Running Available today

Every term in this group describes something Oathera runs today. You can rely on these as current capabilities.

Know Your Agent

The category Oathera defines: giving every AI agent a provable identity, an accountable sponsor, and an operational boundary enforced on every request. Know Your Agent is the category, not a product name.

Sponsor

The person or organizational unit that is accountable for an agent and answers for what it does. The sponsor travels with the identity and is visible on every log line and boundary decision.

Oathera says sponsor, not the generic “owner.” A sponsor is accountable for the agent; it is a distinct idea from the principal who signs in to approve it.

Principal

The person who signed in through the IdP and completed the enrollment approval for an agent. A principal is not the same as a sponsor: the principal performs the approval, while the sponsor is who the agent answers to.

Anchor key

The one Ed25519 key an agent holds, generated inside your environment and never exported. One agent has exactly one anchor key.

Oathera says anchor key rather than the generic cryptographic term, because the key is the stable root of the agent's identity, not a secret to be passed around.

Thumbprint

The compact, verifiable value derived from an agent's anchor key. The thumbprint is the agent's identity: present the thumbprint and prove possession of the matching anchor key, and you have proven which agent you are.

Identity token

A short-lifetime credential — measured in minutes — issued by the identity service and bound to an agent's anchor key and its host. On its own it is useless to a thief, who has neither the anchor key nor the host.

Oathera says identity token rather than naming it by its transport or lifetime; the point is what it is bound to, not how long it lasts.

Session key

The signing key an agent uses for a working session, held alongside the identity token. Where a definition needs to name the thing doing the signing during a session, it is the session key.

Operation proof / Proof of possession

A single-use RFC 9421 HTTP Message Signature carried on each call, over that exact method, path and body. Because it proves possession of the signing key for that one request, a request cannot be replayed or altered.

Host binding

The tie between an agent's identity and the host it was enrolled on. An agent that appears on a new host is revoked; that new host enrolls a new agent.

Oathera says host throughout, not a forced synonym; incidental technical phrases such as “virtual machine” are left as they are.

Host digest

The compact record of the host that the Identity MCP captures at enrollment, so the identity can be tied to that host. It is a digest of the host, not a claim that the host has been independently attested.

Enrollment

The process by which an agent gets its identity: the Identity MCP creates the anchor key, records a host digest, and the agent is registered against a sponsor.

Enrollment approval

The step where a principal signs in and approves an agent's enrollment once. Nothing runs on an unapproved identity. The credential service issues a verifiable credential recording who approved what.

Operational boundary

The envelope that defines what an agent may do: which tenants, systems, data classes and operations are in scope, and which are explicitly never in scope. The boundary travels inside the identity, so it follows the agent everywhere it acts.

Boundary decision

The signed allow or deny returned when the Gateway MCP evaluates a request against the operational boundary, using Open Policy Agent (OPA) as policy input. The operational boundary is the envelope; the boundary decision is the signed outcome for one request.

Control plane

The Oathera services that handle enrollment, policy, revocation and telemetry. The control plane is where identities are managed; it is distinct from the enforcement plane that acts beside your agent.

Enforcement plane

The two MCPs — the Identity MCP and the Gateway MCP — that run beside your agent and enforce identity and the operational boundary on every request.

Oathera pairs the control plane with the enforcement plane; it does not use the term some vendors use for the layer that carries traffic.

Identity MCP

The component that runs beside an agent, creates and holds its anchor key, records a host digest at enrollment, and signs on the agent's behalf.

Oathera says Identity MCP — one name for this component everywhere — not a generic “helper.”

Gateway MCP

The component that verifies an agent's identity token and operation proof, requests the boundary decision, and lets a request through only when it is allowed.

Oathera says Gateway MCP — one name everywhere — not a generic “gateway” label.

Identity service

The control-plane service that issues identity tokens bound to an agent's anchor key and host, and maintains the agent register.

Technical name: AIS.

Credential service

The control-plane service that issues verifiable credentials recording who approved what, so an approval can be verified later.

Technical name: VCI.

Runtime check-in

The regular contact between an agent's enforcement plane and the control plane that keeps a short-lifetime identity token renewed. When renewal stops, access ends within one token lifetime.

Revocation on deprovision

When a sponsoring principal is deprovisioned, the identity service stops issuing identity tokens to that principal's agents and bumps the revocation epoch, so access ends within one short token lifetime — without a redeploy.

Content trust

Labels on the trust of content flowing through an agent's tools, so an agent can tell what came from a trusted source and what did not before it acts on it.

Federation

Issuing identity in a form another system already accepts, so agents join trust domains you already run. Today Oathera federates with Microsoft Entra.

NHI attributes

The non-human-identity attributes an agent reports about itself, which feed its risk tier. Oathera is explicit that these are self-reported, not independently proofed.

Risk tier

A rating from 1 to 4 for how dangerous an agent's reach is, where 1 is the most dangerous and 4 the least. Risk tier is the only Oathera term that uses that word.

Resource server

A system an agent calls — an API or service that holds the data or performs the operation the agent is reaching for.

Protected core

The signed native library at the heart of the enforcement plane, used where the specific signed component is meant rather than a resource server in general.

IdP

Your own identity provider — the OIDC provider where a principal signs in. Oathera relies on your IdP for human identity. The IdP that ships with Oathera is a demo IdP, for demonstration only.

Capability

A specific action an agent is permitted to take within its operational boundary.

Privileged capability

A capability with higher reach or risk. Identity tokens for privileged capabilities are issued with a shorter lifetime.

Audience

The intended recipient an identity token is issued for, so a token meant for one resource server is not accepted by another.

Anchor rotation

Replacing an agent's anchor key with a new one while preserving a verifiable link to the identity, so a key can be refreshed without re-establishing who the agent is.

Gateway assertion

The signed statement the Gateway MCP emits about a verified request and its boundary decision, forming part of the audit record.

Evidence source

Who vouches for something — the party supplying a signal about an agent or identity. Kept distinct from the assurance level, which is how far that evidence lets you trust it.

Assurance level

How far a piece of evidence lets you trust an identity. Kept distinct from the evidence source: one names who vouches, the other names how far to trust.

Tenant

An isolated customer space within Oathera. An agent's operational boundary names which tenants are in scope.

MCP bundle

The package you install beside your own agent: the Identity MCP and the Gateway MCP together.

Bring your own agent (BYOA)

Running your existing agent with Oathera by installing the MCP bundle next to it, rather than rebuilding the agent on a new framework.

Admin API

The programmatic interface for managing identities, boundaries and revocation in the control plane.

Clearance 0 (Basic)

The baseline clearance every enrolled agent has today. Higher clearances (Verified, High) are on the roadmap and are not available now.

Sovereign (deployment)

Used only to describe a deployment: self-hosted or in-country. Sovereign refers to where Oathera runs, never to a clearance and never as a tagline.

Coming Not yet available

These capabilities are being built and are not available today. They are defined here so the vocabulary is clear; nothing in this group is live yet.

Enrollment review

An additional admin sign-off on top of enrollment approval, so a second administrator reviews an agent before it is activated.

Task context

Scoping an agent's authority to the specific task it was handed, so a boundary decision can take that task into account.

Delegation

One agent passing a scoped slice of its authority to another, with the chain recorded and verifiable.

Operation approval

A human-in-the-loop checkpoint on an individual operation before it is allowed to run. Distinct from enrollment approval, which happens once at enrollment.

Signed revocation snapshots (risk tier boundary-decision optimization)

Signed revocation snapshots and a risk tier optimization that let the Gateway MCP reach a boundary decision faster. The boundary decision itself runs today; this optimization does not.

On the roadmap Roadmap

Longer-term directions, named here only so the vocabulary is clear. These are not available and not committed to a release, and Oathera does not present them as capabilities you can use. Consistent with ADR 0001, Oathera does not proof humans; any identity assurance would rely on your own IdP and proofing sources.

Verified sponsor

A sponsor whose identity has been established to stronger assurance through your IdP and proofing sources. Per ADR 0001, Oathera does not proof people itself, so this stays on the roadmap.

Proofing source

An external party that establishes a human's identity. Oathera would rely on your proofing sources rather than proof people itself (ADR 0001).

Clearance 1 (Verified) and Clearance 2 (High)

Clearances above Basic, computed from evidence through your IdP and proofing sources. Both are on the roadmap; today every agent is Clearance 0 (Basic).

Known organization

An organization recognized with baseline assurance. A roadmap label, not an available capability.

Verified organization

An organization established to stronger assurance through proofing sources. A roadmap label, not an available capability.

Handover

Transferring responsibility for an agent from one sponsor to another, with the change recorded. On the roadmap.

Departure detection

Surfacing agents whose sponsor has left, so they can be reassigned or retired. On the roadmap.

Agent class

Grouping agents into classes so a boundary and policy can be expressed once and applied across the class. On the roadmap.

Trust score

A computed score summarizing how far an agent can be trusted. On the roadmap.

Agent identity wallet

A wallet that carries an agent's credentials and presents them where needed. On the roadmap.

Attested host

A host whose integrity has been attested, used in the roadmap Clearance 2 context (ADR 0003). Today the Identity MCP records a host digest at enrollment; full host attestation is on the roadmap.

Plan

A packaging of Oathera for a customer, which may be measured in sponsor seats. Defined here for vocabulary only; Oathera does not publish pricing on the site.

← Back to Oathera
OATHERA logo Oathera

Know Your Agent — the category Oathera defines. Every agent gets a verifiable identity and an enrollment approval before it acts.

Product

  • Platform
  • Features
  • Integrations
  • Use cases

Developers

  • Docs
  • Learn
  • GitHub
  • Demo

Company

  • Security
  • Contact
  • Careers soon

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Sub-processors
© 2026 Oathera · Know Your Agent

Cookie preferences

We use cookies to run this site and, with your consent, to understand usage and improve Oathera. Strictly necessary cookies are always on; you can choose whether to allow analytics and marketing cookies below.

  • Strictly necessaryAlways on

    Required for the site to work — security, load balancing, and remembering your cookie choices. These cannot be switched off.

  • Help us measure traffic and see how the site is used, so we can improve it. No personal profiles are built.

  • Used to make messages about Oathera more relevant across other sites. Off unless you turn it on.