{"slug": "introducing-token-vault-agents-access-everything-hold-nothing", "title": "Introducing Token Vault: Agents Access Everything. Hold Nothing.", "summary": "Kong introduced Token Vault for Kong Identity, a credential-brokering service that lets AI agents authenticate to Kong and have downstream credentials applied during authorized requests rather than storing those credentials inside the agents themselves. Kong said the product combines agent authentication through its centralized Principals directory, centralized authorization policies covering APIs, MCP servers, models and event resources, and credential brokering for downstream systems that may use OAuth on behalf of a user, shared machine-to-machine identities, administrator-managed keys or their own OAuth providers. The company framed the launch as a way for platform and security teams to control both who an agent is and how that identity reaches enterprise systems.", "body_md": "# Introducing Token Vault: Agents Access Everything. Hold Nothing.\n\nAlex Drag\n\nHead of Product Marketing\n\n**Kong Identity can now securely broker downstream credentials for AI agents, giving them access to the systems they need without putting those credentials in the agents themselves.**\n\nAI agents are getting access to more of the enterprise.\n\nAn engineering agent might need GitHub and Jira. A support agent might need Salesforce, Slack, and an internal customer API. An analytics agent might need Snowflake and Databricks. And increasingly, those resources are exposed through a mix of APIs, MCP servers, models, and event infrastructure.\n\nEvery one of those systems has its own identity and authentication requirements.\n\nThe obvious solution is to give the agent credentials for each system it needs to access.\n\nIt’s also a dangerous one.\n\nThe more capable the agent becomes, the more credentials it accumulates. Those credentials end up in exactly the place you don’t want them: inside applications designed to reason and act autonomously.\n\nWe’re introducing **Token Vault for Kong Identity**, giving organizations a different approach.\n\n**Agents access everything. Hold nothing.**\n\n## The credential problem gets worse as agents get better\n\nTraditional applications generally have well-defined boundaries. They interact with a known set of services using credentials provisioned specifically for those connections.\n\nAgents are different.\n\nTheir value comes from their ability to work across systems. An agent may need intelligence from a model, tools exposed through APIs and MCP servers, and context from enterprise data and event streams.\n\nAs agents become more capable, their access surface expands.\n\nWithout an identity layer sitting between the agent and those resources, that can quickly become:\n\nNow consider what happens when that agent is compromised, manipulated, or simply behaves in a way you didn’t anticipate.\n\nThe problem is no longer just what the agent can do.\n\nIt’s **what credentials the agent possesses.**\n\n## One agent identity. Many downstream identities.\n\nToken Vault changes the architecture.\n\nInstead of giving an agent every downstream credential it might need, the agent authenticates to Kong.\n\nKong Identity establishes who the agent is. Kong’s policies determine what that identity is allowed to access. Token Vault manages the relationship between that principal and the credentials required by downstream systems.\n\nWhen the agent accesses an authorized resource, Kong can apply the appropriate downstream credential as part of the request flow.\n\nThe agent doesn’t need to understand how every downstream system authenticates. And downstream credentials don’t need to be exposed directly to the agent.\n\nThe result is a clean separation between **who the agent is** and **how it authenticates to everything it needs.**\n\n## Authenticate. Authorize. Broker.\n\nKong Identity brings three critical pieces of agent access together.\n\n**Authenticate the agent.** Establish a consistent identity for agents and other machine principals through Kong’s centralized Principals directory.\n\n**Authorize access.** Apply centralized policies that determine which APIs, MCP servers, models, event resources, and other enterprise capabilities an identity is permitted to access.\n\n**Broker the credential.** Token Vault manages the credentials needed by downstream systems and makes the appropriate credential available as part of authorized traffic.\n\nThat gives platform and security teams one place to control both **who an agent is** and **how that identity reaches the enterprise.**\n\n## Support the messy reality of enterprise identity\n\nThere isn’t one universal authentication scheme waiting on the other side of an agent request.\n\nOne resource might use OAuth on behalf of an individual user. Another might require a shared machine-to-machine identity. An internal API might use an administrator-managed key. Another system might have its own OAuth provider.\n\nToken Vault is designed for this heterogeneous environment.\n\nCredential providers can represent different downstream systems and credential models, including per-user and shared credentials. Those providers can then be associated with the resources that use them and the principals authorized to access them.\n\nThat means an agent can operate across systems such as GitHub, Slack, Atlassian, Snowflake, Google, Databricks, internal APIs, and other enterprise resources without every authentication mechanism becoming part of the agent itself.\n\n**One agent identity. Many downstream identities. One enforcement layer.**\n\n## Reduce the blast radius of agent compromise\n\nThis architecture has an important security consequence.\n\nIf downstream credentials are distributed across agents, compromising an agent can also expose the credentials it possesses. Security teams then have to determine which secrets were exposed, revoke them at their respective providers, provision replacements, and update affected applications.\n\nBrokered access changes that equation.\n\nAccess remains tied to the agent’s identity and centrally enforced policy. Security teams can change or revoke what an identity is allowed to access without relying on credentials scattered throughout agent implementations.\n\nAnd because access flows through Kong, organizations gain a centralized record of which identity accessed which resources.\n\n## Identity across intelligence, tools, and context\n\nAgents ultimately need three things to do useful work:\n\n- **Intelligence** — the models they reason with.\n\n- **Tools** — the APIs and MCP servers they use to take action.\n\n- **Context** — the enterprise data and events they use to understand what’s happening.\n\nIn a real enterprise, those resources are scattered across providers, clouds, SaaS platforms, data systems, and internal infrastructure.\n\nKong Identity provides a common identity and access layer across that heterogeneous environment, while Token Vault helps bridge the different credential systems agents encounter as they move through it.\n\nAgents don’t need an identity strategy for every new system they access.\n\nThey need **one identity layer that can span all of them.**\n\n## A source of truth for agent identity\n\nToken Vault expands the role of Kong Identity.\n\nKong’s centralized Principals directory already provides a common source of truth for human and machine identities across APIs, AI, and events, with support for multiple authentication mechanisms, metadata-driven policy, credential lifecycle management, analytics, and audit logging.\n\nToken Vault extends that model downstream.\n\nKong can now help organizations establish the agent’s identity, govern what it is allowed to reach, and broker the credentials required to authenticate to those resources.\n\nBecause giving agents access to the enterprise shouldn’t mean giving them the keys to the enterprise.\n\n## Agents access everything. Hold nothing.\n\nThe future of agent security isn’t creating and distributing more credentials every time an agent gains another capability.\n\nIt’s separating **access from possession**.\n\nGive agents the identity they need to operate. Give security teams centralized control over what those identities can access. Let Kong handle the credentials required to make those connections work.\n\n**Kong Token Vault is available as part of Kong Identity.**\n\nModern enterprise APIs don't live in one place. They're spread across multiple gateways, deployed across regions and clouds, and accessed by a growing mix of consumers, internal developers, external partners, machine-to-machine services, and increas\n\nAmit Shah\n\n# Expanded Observability, Orchestration, and Security with Kong Gateway 3.13\n\nAs API ecosystems grow more complex, maintaining visibility and security shouldn't be a hurdle. Kong Gateway 3.13 simplifies these challenges with expanded OpenTelemetry support and more flexible orchestration. These new capabilities not only make y\n\nAmit Shah\n\n# Introducing Kong AI Registry: Self-Service Discovery for Agents\n\nAPI management solved a similar problem for developers. Instead of asking a platform team every time they needed an API, developers could go to a Developer Portal, discover what was available to them, and start building — within the governance bound\n\nAlex Drag\n\n# Kong Gateway 3.9: Extended AI Support and Enhanced Security\n\nToday we're excited to announce Kong Gateway 3.9! Since unveiling Kong Gateway 3.8 at API Summit 2024 just a few months ago, we’ve been busy making important updates and improvements to Kong Gateway. This release introduces new functionality arou\n\nAlex Drag\n\n# Protect APIs Against Injection Attacks with Content Inspection\n\nAPIs facilitate effortless communication and data exchange between applications and services. However, their inherent design, which codifies service capabilities within the API definition, makes them easily exploitable by malicious actors. API attac\n\nBrent Yarger\n\n# Kong Introduces the Portal MCP Server for Developer Portal\n\nYour developer portal was built for a developer scanning docs in a browser: reading a page, copying a curl command, moving on. Increasingly, the thing reading those docs isn't a person. It's an agent, working through an API integration on someone's\n\nModern enterprise APIs don't live in one place. They're spread across multiple gateways, deployed across regions and clouds, and accessed by a growing mix of consumers, internal developers, external partners, machine-to-machine services, and increas\n\nAmit Shah\n\n# Expanded Observability, Orchestration, and Security with Kong Gateway 3.13\n\nAs API ecosystems grow more complex, maintaining visibility and security shouldn't be a hurdle. Kong Gateway 3.13 simplifies these challenges with expanded OpenTelemetry support and more flexible orchestration. These new capabilities not only make y\n\nAmit Shah\n\n# Introducing Kong AI Registry: Self-Service Discovery for Agents\n\nAPI management solved a similar problem for developers. Instead of asking a platform team every time they needed an API, developers could go to a Developer Portal, discover what was available to them, and start building — within the governance bound\n\nAlex Drag\n\n# Kong Gateway 3.9: Extended AI Support and Enhanced Security\n\nToday we're excited to announce Kong Gateway 3.9! Since unveiling Kong Gateway 3.8 at API Summit 2024 just a few months ago, we’ve been busy making important updates and improvements to Kong Gateway. This release introduces new functionality arou\n\nAlex Drag\n\n# Protect APIs Against Injection Attacks with Content Inspection\n\nAPIs facilitate effortless communication and data exchange between applications and services. However, their inherent design, which codifies service capabilities within the API definition, makes them easily exploitable by malicious actors. API attac\n\nBrent Yarger\n\n# Kong Introduces the Portal MCP Server for Developer Portal\n\nYour developer portal was built for a developer scanning docs in a browser: reading a page, copying a curl command, moving on. Increasingly, the thing reading those docs isn't a person. It's an agent, working through an API integration on someone's\n\nModern enterprise APIs don't live in one place. They're spread across multiple gateways, deployed across regions and clouds, and accessed by a growing mix of consumers, internal developers, external partners, machine-to-machine services, and increas\n\nAmit Shah\n\n# Expanded Observability, Orchestration, and Security with Kong Gateway 3.13\n\nAs API ecosystems grow more complex, maintaining visibility and security shouldn't be a hurdle. Kong Gateway 3.13 simplifies these challenges with expanded OpenTelemetry support and more flexible orchestration. These new capabilities not only make y\n\nAmit Shah\n\n# Introducing Kong AI Registry: Self-Service Discovery for Agents\n\nAPI management solved a similar problem for developers. Instead of asking a platform team every time they needed an API, developers could go to a Developer Portal, discover what was available to them, and start building — within the governance bound\n\nAlex Drag\n\n# Kong Gateway 3.9: Extended AI Support and Enhanced Security\n\nToday we're excited to announce Kong Gateway 3.9! Since unveiling Kong Gateway 3.8 at API Summit 2024 just a few months ago, we’ve been busy making important updates and improvements to Kong Gateway. This release introduces new functionality arou\n\nAlex Drag\n\n# Protect APIs Against Injection Attacks with Content Inspection\n\nAPIs facilitate effortless communication and data exchange between applications and services. However, their inherent design, which codifies service capabilities within the API definition, makes them easily exploitable by malicious actors. API attac\n\nBrent Yarger\n\n# Kong Introduces the Portal MCP Server for Developer Portal\n\nYour developer portal was built for a developer scanning docs in a browser: reading a page, copying a curl command, moving on. Increasingly, the thing reading those docs isn't a person. It's an agent, working through an API integration on someone's", "url": "https://wpnews.pro/news/introducing-token-vault-agents-access-everything-hold-nothing", "canonical_source": "https://konghq.com/blog/product-releases/token-vault", "published_at": "2026-09-30 16:00:00+00:00", "updated_at": "2026-09-30 16:22:42.492808+00:00", "lang": "en", "topics": ["ai-agents", "ai-infrastructure", "agent-protocols", "ai-products"], "entities": ["Kong", "Token Vault", "Kong Identity", "Alex Drag", "GitHub", "Jira", "Salesforce", "Snowflake"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/introducing-token-vault-agents-access-everything-hold-nothing", "markdown": "https://wpnews.pro/news/introducing-token-vault-agents-access-everything-hold-nothing.md", "text": "https://wpnews.pro/news/introducing-token-vault-agents-access-everything-hold-nothing.txt", "jsonld": "https://wpnews.pro/news/introducing-token-vault-agents-access-everything-hold-nothing.jsonld"}}