AIToday
Large Language ModelsAI Safety & AlignmentHacker NewsPublished: Jul 26, 2026, 06:00 JST2 min read

Keydris adds authorization layer for AI agents calling external tools

Keydris adds authorization layer for AI agents calling external tools

3 Key Points

  1. What happened

    Keydris has released a system that issues AI agents signed authorization tokens (called kits) before they can call external tools or services. A lightweight component called the Kit Reader sits on each tool server, verifies the token with Keydris's central Gateway, and blocks any action that lacks valid authorization.

  2. Why it matters

    AI agents now act faster than humans can review and against systems that do not tolerate mistakes. Unlike software built for human users, agents need verifiable proof of what they are permitted to do at the moment of action. Keydris lets institutions answer critical questions—which actions were actually authorized, who authorized them, and what proof exists—before harm occurs rather than after.

  3. What to watch

    Keydris is designed to work across any AI model, vendor, or platform, positioning itself as neutral infrastructure between institutions. The system issues tokens with minimum privilege by default, syncs revocation instantly across boundaries, and produces signed audit records automatically as part of normal operation—not assembled after the fact for compliance review.

Ask the AI about this article →

Summaries like this, in your inbox every morning.

Context & Analysis

AI agents present a novel liability that traditional software authorization frameworks do not address. While every previous category of software was built for humans clicking buttons and reviewing actions, agents act at machine speed—faster than any human can validate, against systems that do not forgive mistakes. The core problem Keydris addresses is that trust by assumption is no longer sufficient when an agent can cause damage in milliseconds.

Keydris positions itself as infrastructure that sits at the boundary between the agent and the tool it calls, creating a verifiable chain of proof around every action. Each authorization decision is cryptographically signed and immutable, with revocation built into the verification process itself rather than as a separate administrative function. This approach answers the questions that security and compliance leaders already ask: which actions were actually authorized and by whom, what happens when authority is revoked, and what record would be handed to an auditor. The system's output—signed records of every decision—is generated automatically as the system operates, not assembled after the fact for compliance review.

FAQ
How does Keydris prevent unauthorized actions by AI agents?
Keydris issues each agent a signed token called a KIT that states what the agent may do and for how long. When the agent calls a tool, a lightweight component called the Kit Reader—installed on the receiving server—verifies the token with Keydris's central Gateway and blocks the call if authorization is invalid or has been revoked.
What happens if an agent's authority is revoked?
Revocation takes effect at machine speed across every boundary. The next verification check fails immediately, and the audit trail records exactly when the revocation was issued, when it synced, and when any subsequent action attempt was refused.
Does Keydris tie me to a specific AI model or platform?
No. Keydris is designed to be independent of any model, vendor, platform, or rail—it functions as neutral infrastructure that can sit between different institutions rather than being locked into one vendor's ecosystem.

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • Meta's Muse AI agent prices in at $20 and $100 a monthYahoo Finance AI · 24m ago
  • OpenAI agents hit RubyGems with 2,000+ malicious packagesTHE DECODER · 24m ago
  • AI hangover hits firms; cure isn't more GenAI useFortune AI · 24m ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleTSMC pledges $100B more US investment; SK Hynix eyes US manufacturing