Works with your favorite agent harnesses and SDKs
Authenticated
Every agent and sub-agent authenticates with its own credentials before acting. The delegation chain back to the user or upstream agent is recorded before any tool runs.
Authorized
Ory applies fine-grained authorization to shell commands, file writes, MCP tools, and API calls — the same policy model that governs human access.
Accountable
Every action is recorded and exported through OpenTelemetry to your SIEM. The delegation chain outlives the token, so the trail holds even after credentials expire.
How Ory's agent security works
Get started with your preferred AI tool
Anthropic Claude Agent SDK
The Anthropic Claude Agent SDK is a developer framework by Anthropic that enables the programmatic creation and deployment of autonomous AI agents capable of multi-turn reasoning, executing code, and interacting with file systems and external tools.
Gemini CLI
Gemini CLI is an open-source AI agent developed by Google that brings the power of Gemini models directly into your terminal, enabling developers to understand code, automate complex workflows, and execute tasks using natural language prompts.
OpenAI Codex
OpenAI Codex is an AI-powered coding agent designed to automate software development tasks by navigating codebases, generating features, debugging issues, and executing tests directly in an isolated terminal or cloud environment.
Microsoft Agent Framework
Microsoft Agent Framework is an open-source SDK and runtime by Microsoft for building, orchestrating, and deploying enterprise-grade AI agents and multi-agent workflows in Python and .NET.
Frequently asked questions
More on agent security
Ory DX: Build secure apps at the speed of thought, the right way.
Ory DX is the ultimate developer toolkit that unifies AI automation with Ory’s hardened security ecosystem. By seamlessly blending Model Context Protocol (MCP) servers, plugins, CLI, and Ory Elements, it gives developers a conversational, agent-led workflow to develop enterprise-ready identity, access management, and fine-grained permissions.







