Keydris has launched an authorization layer that sits between AI agents and the external tools they call, issuing agents signed tokens that prove what they are permitted to do. The system verifies each action in milliseconds before it reaches the target server, and revocation takes effect immediately—with every decision automatically recorded and auditable. This addresses the problem that AI agents act too fast for human review and against systems that cannot tolerate unauthorized mistakes.
Summaries like this, in your inbox every morning.
Sign up free →What happened
Keydris has released a system that issues AI agents signed authorization tokens (called kits) before they can call external tools or services. A lightweight component called the Kit Reader sits on each tool server, verifies the token with Keydris's central Gateway, and blocks any action that lacks valid authorization.
Why it matters
AI agents now act faster than humans can review and against systems that do not tolerate mistakes. Unlike software built for human users, agents need verifiable proof of what they are permitted to do at the moment of action. Keydris lets institutions answer critical questions—which actions were actually authorized, who authorized them, and what proof exists—before harm occurs rather than after.
What to watch
Keydris is designed to work across any AI model, vendor, or platform, positioning itself as neutral infrastructure between institutions. The system issues tokens with minimum privilege by default, syncs revocation instantly across boundaries, and produces signed audit records automatically as part of normal operation—not assembled after the fact for compliance review.
Keydris has created a middleware layer designed to intercept and validate AI agent actions before they reach external tools or services. The system works in four stages: the Keydris Gateway issues each agent a signed token called a KIT that specifies what actions the agent is permitted to perform and for how long, based on policies set by the institution. That token is bound to an append-only, hash-chained log to create an immutable record. When the agent attempts to call an external tool or MCP (Model Context Protocol) server, a lightweight component called the Kit Reader—installed on the receiving service—intercepts the call, verifies the token with the Gateway, and either allows or denies the action before it reaches the actual server.
The authorization model is built on minimum privilege by default, meaning agents receive only the specific permissions they need. Revocation operates at machine speed: when an institution revokes an agent's authority at 09:00, any action attempted after that timestamp fails verification, and the system records the exact timing of the revocation, when it propagated, and when the blocked action occurred. Every verification produces a signed record that names the request, the policy in force, the checks performed, and the outcome—creating an audit trail that is the system's native output rather than a report assembled after the fact.
Keydris emphasizes that it operates as neutral infrastructure independent of any AI model, vendor, or platform. The system does not hold money, private keys, or other sensitive data—it sits between institutions as an authorization and audit layer. This design allows different organizations and systems to interoperate around a common proof of authority, addressing what security officers, platform engineers, and compliance leads need: verifiable proof that every action carried an authorization at the moment it occurred, who issued that authorization, whether it had been revoked, and a complete record for audit.
AI agents present a novel liability that traditional software authorization frameworks do not address. While every previous category of software was built for humans clicking buttons and reviewing actions, agents act at machine speed—faster than any human can validate, against systems that do not forgive mistakes. The core problem Keydris addresses is that trust by assumption is no longer sufficient when an agent can cause damage in milliseconds.
Keydris positions itself as infrastructure that sits at the boundary between the agent and the tool it calls, creating a verifiable chain of proof around every action. Each authorization decision is cryptographically signed and immutable, with revocation built into the verification process itself rather than as a separate administrative function. This approach answers the questions that security and compliance leaders already ask: which actions were actually authorized and by whom, what happens when authority is revoked, and what record would be handed to an auditor. The system's output—signed records of every decision—is generated automatically as the system operates, not assembled after the fact for compliance review.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
No comments yet. Be the first to share your thoughts!
Log in to join the discussion



Get curated AI news from 200+ sources delivered daily to your inbox. Free to use.
Get Started FreeFree · takes 30 seconds · unsubscribe anytime