Secure AI agent connectivity

AI agents are the new power users — with API keys, tool access, and no device screen. Give each one a scoped identity instead of the keys to the kingdom.

The agent access problem

Long-lived credentials

A .env file with production keys, baked into an agent container. The blast radius of one leak is everything.

Undefined blast radius

Nobody can answer "what can this agent touch?" — because the honest answer is "the whole VPC".

Prompt injection pivot

When an agent gets talked into fetching a URL it shouldn't, the network is the last line of defense. Make it a real one.

Agents on the tailnet

1 · Identity per agent

Each agent runs as its own tailnet node with its own short-lived auth key. No shared secrets.

2 · Scope with ACLs

This agent may reach the model gateway and the docs index. Nothing else — enforced at the network layer.

3 · Egress control

Approved model endpoints only. A prompt-injected fetch to an arbitrary domain fails closed.

4 · Full audit

Every connection logged: which agent, which destination, when, for how long. Incident response starts with facts.

Reference patterns

Model gateway

Agents reach models only through an internal gateway that adds auth, rate limits, and logging. Direct model egress is blocked.

Tool servers via MCP

MCP tool servers listen only on the tailnet. Agents discover and call them over AmneziaWG-encrypted connections.

Human-in-the-loop data access

Agents request sensitive datasets; the data plane checks a human-approved grant before the bytes move.

Let agents work. Keep the keys.