Works with your favorite agent harnesses and SDKs
Authenticated
Every agent and sub-agent authenticates with its own credentials before acting. The delegation chain back to the user or upstream agent is recorded before any tool runs.
Authorized
Ory applies fine-grained authorization to shell commands, file writes, MCP tools, and API calls — the same policy model that governs human access.
Accountable
Every action is recorded and exported through OpenTelemetry to your SIEM. The delegation chain outlives the token, so the trail holds even after credentials expire.
How Ory's agent security works
Get started with your preferred AI tool
Amp
Amp is an agentic AI coding tool developed by Sourcegraph that operates in your terminal and editor extensions, enabling developers to execute complex multi-file edits, plan architecture, and automate development workflows using frontier AI models.
Anthropic Claude Agent SDK
The Anthropic Claude Agent SDK is a developer framework by Anthropic that enables the programmatic creation and deployment of autonomous AI agents capable of multi-turn reasoning, executing code, and interacting with file systems and external tools.
Claude Code
Claude Code is an agentic AI coding tool developed by Anthropic that operates directly in your terminal, enabling developers to navigate codebases, build features, debug issues, and automate routine tasks using natural language commands.
Cline
Cline is an open-source AI coding agent that operates in your IDE and terminal, enabling developers to edit multiple files, execute commands, run tests, and automate complex tasks with full human approval.
Frequently asked questions
More on agent security
Ory DX: Build secure apps at the speed of thought, the right way.
Ory DX is the ultimate developer toolkit that unifies AI automation with Ory’s hardened security ecosystem. By seamlessly blending Model Context Protocol (MCP) servers, plugins, CLI, and Ory Elements, it gives developers a conversational, agent-led workflow to develop enterprise-ready identity, access management, and fine-grained permissions.







