---
type: "article"
title: "API Evangelist Weekly — Agents Got an Identity, and Everyone Said an Identity Is Not Enough"
summary: "8,601 unique posts across 1,971 provider blogs between August 30th and September 6th. Four identity vendors shipped agent-identity product inside a seventy-two hour window, and in the same seven days at least four other companies published the argument that identity is the wrong layer to solve this at. MCP finished its migration from the engineering blog to the support desk and started a second one, to the security desk. And OpenAPI was named in exactly one third-party post title all week."
newsletter: "API Evangelist"
newsletter_handle: "apievangelist"
newsletter_url: "https://usecommune.com/n/apievangelist"
author: "Kin Lane (@kinlane)"
published: "2026-09-07T13:58:48.613Z"
canonical_url: "https://usecommune.com/n/apievangelist/a/dDnzyEWE"
markdown_url: "https://usecommune.com/n/apievangelist/a/dDnzyEWE.md"
chat_url: "https://usecommune.com/n/apievangelist/a/dDnzyEWE/chat"
body_source: "native"
likes: 0
replies: 0
body_words: 3104
---

# API Evangelist Weekly — Agents Got an Identity, and Everyone Said an Identity Is Not Enough

Last week I ended on a button. The agent can hold a credential, I wrote, it just cannot obtain one — every door in the network still needs a human hand on it, and everything upstream of that button is governed while the button is not governed at all.

This week the industry answered a question I had not asked. It gave the agent an identity.

Four vendors shipped it inside seventy-two hours. HashiCorp took agentic IAM to GA, CrowdStrike announced an agentic identity provider, AWS gave Bedrock AgentCore a managed consent portal, and Auth0 shipped enterprise-managed authorization for client apps. That is a category forming in real time, and if you had asked me in June what the agent-access problem needed, I would have said roughly this.

And then, in the same seven days, at least four other companies published the argument that it does not work.

Not that the products are bad. That the layer is wrong. VentureBeat ran it twice. Cequence ran it. SpruceID ran it. Arcade ran it. The sentence they are all circling is that an agent which passes authentication is still an agent — it can drift, it can be prompt-poisoned, it can be handed a perfectly valid credential and do something nobody authorized with it. HackerNoon put the cleanest title on it: the impostor in your environment is the AI agent holding a valid credential.

I want to be careful here, because there is a lazy version of this observation and I do not want to write it. The lazy version is "identity is dead, behavior is the new perimeter," which is a vendor sentence wearing an analyst costume. The honest version is smaller and more useful: we spent the year narrowing the grant, and narrowing the grant turns out to answer *who is calling* without answering *what this call is for*. Those were the same question when a human sat behind every token. They are not the same question anymore.

![A vast dark neon grid at night where hundreds of small angular light-vessels each carry a bright glowing badge, passing unchallenged through a tall gleaming gateway arch, while beyond the arch the vessels scatter in every direction across an unlit plain with no structures, no paths and nothing watching them.](https://kinlane-images.s3.amazonaws.com/apievangelist/api-evangelist-images/newsletter/2026-09-07-identity-is-not-enough.png)

## Identity Arrived for Agents, and Everyone Immediately Said It Was Not Enough

The products, first, because they are real and they shipped:

- [HashiCorp Vault agentic IAM went generally available](https://www.hashicorp.com/blog/hashicorp-vault-agentic-iam-is-now-generally-available), [CrowdStrike announced an Agentic Identity Provider](https://www.crowdstrike.com/en-us/blog/crowdstrike-announces-agentic-identity-provider/), [Amazon Bedrock AgentCore Identity added a managed consent portal](https://aws.amazon.com/about-aws/whats-new/2026/09/amazon-bedrock-agentcore/), and [Auth0 shipped enterprise-managed authorization for client apps](https://auth0.com/blog/enabling-enterprise-managed-authorization-for-client-apps/). September 1st and 2nd, all four.
- WorkOS noticed the same convergence from inside it and counted it themselves: [three identity vendors shipped the same agent access pattern in eight days](https://workos.com/blog/cross-app-access-converged-in-eight-days). When competitors ship the same shape in the same fortnight without coordinating, the shape is not a product decision. It is the only thing the constraints allow.

Then the counter-argument, from companies with no shared incentive to make it:

- [VentureBeat, twice](https://venturebeat.com/security/identity-and-permissions-arent-enough-to-govern-ai-agent-behavior): identity and permissions are not enough to govern agent behavior, and separately, [agents that pass authentication can still drift, expose data, or get memory-poisoned](https://venturebeat.com/security/ai-agents-that-pass-authentication-can-still-drift-expose-data-or-get-memory-poisoned).
- [Cequence: agentic governance must focus on behavior, not just identity](https://www.cequence.ai/blog/ai/agents-without-guardrails/). [SpruceID: agents have an authorization problem, not just an identity problem](https://blog.spruceid.com/ai-agents-have-an-authorization-problem-not-just-an-identity-problem/). [Arcade: AI agent governance is not governing people](https://www.arcade.dev/blog/ai-agent-governance-is-not-governing-people/) — which is the one I would read first, because it is the only one that says out loud why the analogy breaks. Our entire access-control vocabulary was built for a principal that gets tired, gets bored, and does one thing at a time.
- [Akeyless walked through the Hugging Face breach](https://www.akeyless.io/blog/hugging-face-breach-ai-agent-identity-security/), where the rogue agents needed exposed credentials to get in — a reminder that the boring failure is still the common one. And [JumpCloud published the operational sequel nobody had written yet: what to actually do when you find your first shadow agent](https://jumpcloud.com/blog/turning-discovery-into-action-what-to-do-when-you-find-your-first-shadow-agent). Shadow IT took fifteen years to get a playbook. Shadow agents got one this week.
- The plumbing kept improving underneath the argument. [WorkOS published refresh token behavior across fourteen providers](https://workos.com/blog/refresh-token-behavior-across-fourteen-providers) — genuinely useful empirical work of the kind almost nobody does — plus [a race condition in token refresh and why a conditional write beats a distributed lock](https://workos.com/blog/oauth-refresh-token-race-condition), [keeping credentials out of an agent's context entirely with Relay](https://workos.com/blog/credentials-out-of-agent-context), and [an argument that identity, authorization and audit belong in the same place](https://workos.com/blog/agent-identity-authorization-audit). [Arcade made the operationally sane suggestion of pre-authorizing all of an agent's tools up front](https://www.arcade.dev/blog/pre-authorize-agent-tools/). [BigID wrote up delegated authority](https://bigid.com/blog/ai-agent-delegation/), and [Nudge Security wrote the best-titled post of the week about OAuth grants as the new perimeter](https://www.nudgesecurity.com/post/the-traffic-cop-is-directing-traffic-on-a-road-nobody-drives-anymore) — the traffic cop is directing traffic on a road nobody drives anymore.

Here is what I think is actually happening, and it is not a failure. Identity had to ship first. You cannot reason about what a call is *for* until you can say reliably who is making it, and until this month you could not. The four products above are the floor, not the ceiling, and the four critiques are early rather than wrong. What worries me is the gap between them — a floor that shipped as a finished product, sold to enterprises this quarter, against a ceiling that exists only as blog posts. That gap is where the incidents live.

![An immense dark neon grid where a long low counter of small warmly lit openings runs across the foreground, and rising directly behind it a tall smooth featureless barrier wall pierced by a row of round glowing scanning apertures, with small angular light-vessels queuing first at the low openings and then again at the apertures above.](https://kinlane-images.s3.amazonaws.com/apievangelist/api-evangelist-images/newsletter/2026-09-07-mcp-security-desk.png)

## MCP Moved From the Support Desk to the Security Desk

Last week I counted fourteen MCP posts published on help desks and called it the tell that adoption had become real. This week the count of third-party MCP-titled posts went from 66 to **77**, and the centre of gravity moved again — not away from support, but on to a second desk beside it.

- The sharpest item of the week: [MCP's new spec turns a planted prompt into a stolen credential](https://venturebeat.com/security/mcps-new-spec-turns-a-planted-prompt-into-a-stolen-credential). Read that next to the section above. The protocol added capability, the capability added an authorization surface, and the authorization surface is reachable by anything that can get text in front of the model.
- I wrote [the MCP authentication and authorization gap](https://apievangelist.com/2026/09/03/the-mcp-authentication-and-authorization-gap/) on Wednesday, and [WorkOS published a genuinely good explainer of what MCP authorization is and how OAuth works for agents](https://workos.com/blog/what-is-mcp-authorization) the same day — and, earlier in the week, the distinction that most implementations are getting wrong: [scope step-up is not authentication step-up](https://workos.com/blog/mcp-scope-step-up-vs-authentication-step-up).
- Trust is becoming a product category. [ObservePoint published a security-and-trust page for its own MCP server](https://help.observepoint.com/en/articles/16313176-observepoint-mcp-server-security-trust) — a vendor documenting its server's threat posture as a customer-facing artifact, which did not exist as a genre six months ago. [MCPVault launched to grade and verify MCP servers](https://betalist.com/startups/mcpvault), and [Activepieces published safe tool-calling practice](https://www.activepieces.com/blog/enterprise-ai-security-framework-for-automation-2026). OWASP is drafting a common taxonomy for MCP security risks, which is the signal I would weight highest — a risk taxonomy is what a field produces after it has enough incidents to sort.
- The engineering work continued in parallel and got more specific, which is its own maturity signal. [LangChain shipped stateless protocol support and elicitation](https://www.langchain.com/blog/mcp-in-langchain-stateless-protocol-elicitation-and-more), and [RunPod wrote about designing MCP tools that do not blow up your agent's context window](https://www.runpod.io/blog/designing-mcp-tools). Elicitation is the interesting one — it is the spec's answer to a server needing something from the human mid-call, which is the multi-hop consent problem I flagged last week arriving as an actual protocol feature rather than a think-piece.
- And the long tail kept shipping regardless: Crossbeam, Zoho, Jitterbit, Scrapingdog, CloudConvert, Ahrefs, Knack, Okendo, CloudZero, ToolJet, Appwrite, RemNote, Solve Intelligence, plus [Everlaw's second MCP integration in seven days, this time with Microsoft Copilot](https://www.everlaw.com/blog/ai-and-law/everlaw-microsoft-copilot-mcp-integration/). HackerNoon's newsletter opened the week with the headline "MCP Was Declared Dead." Seventy-seven posts later, it is not.

***

**📄 **[**Conversational API Governance**](https://papers.apievangelist.com/papers/conversational-api-governance/?utm_source=apievangelist&utm_medium=email&utm_campaign=conversational-api-governance&utm_content=midpoint) — Everything above is an argument that our governance reaches the wrong place. Your Spectral ruleset reaches the IDE and it reaches the pipeline. It does not reach the conversation, which is now where APIs actually get designed — and it does not reach the agent, which is now what calls them. This paper is the practical version: wrapping the governance engine in a small MCP server so your rules are reachable by the copilot and the agent, not just by CI. It is also the thinking behind why I spent this week forking Spectral. **$25**

![A dark neon plain where an ornate old toll arch stands stranded and dark beside an empty road, while a short distance away a new low broad arch hums with light and a dense braided stream of small angular light-vessels pours through it, the new arch's outline echoing the old one exactly.](https://kinlane-images.s3.amazonaws.com/apievangelist/api-evangelist-images/newsletter/2026-09-07-gateway-word-changed-hands.png)

## The Gateway Word Changed Hands

I have been watching this one for a few weeks and it tipped this week. "Gateway" now means AI gateway by default in this corpus, and the API gateway has become the thing you say the long name for.

- [Kong AI Gateway 2.0 went GA](https://konghq.com/blog/product-releases/kong-ai-gateway-2-0-ga) — Kong, of all companies, shipping the 2.0 of a product whose name is a modifier on its own original category. [Cloudflare consolidated AI Gateway billing and standardized model names](https://developers.cloudflare.com/changelog/post/2026-09-01-billing-and-model-names/), which is the least glamorous and most telling item here: you do not consolidate invoice line items for a product nobody is spending real money on.
- Vercel shipped models to its AI Gateway on five separate days this week. cData spent the week defining the category from three directions — [what an LLM gateway is and where it sits in the stack](https://www.cdata.com/blog/what-is-an-llm-gateway), [what an MCP gateway does that an API gateway cannot](https://www.cdata.com/blog/mcp-gateway-vs-api-gateway), and an enterprise deployment guide. [DigitalOcean shipped an Action Gateway for connecting agents to SaaS tools without sharing credentials](https://www.digitalocean.com/community/tutorials/connect-tools-ai-agent-action-gateway) — note that the pitch is a credential-isolation pitch, which puts it squarely in the first section of this issue.
- I wrote [a gateway nobody owns is just a load balancer with a deploy pipeline](https://apievangelist.com/2026/09/01/a-gateway-nobody-owns-is-just-a-load-balancer/) on Monday, before most of this landed, and I would say it harder now. Three gateway categories are being sold into the same rack — API, LLM, MCP — and in most orgs no single person owns all three. That is not an architecture. That is three teams each holding a chokepoint and nobody holding the policy.

The thing I would watch: none of this is standardizing. Every gateway above is a product with a proprietary policy model, arriving at the exact moment the industry decided that policy — not identity — is where the agent problem gets solved. We are about to encode the most important control layer of the agentic era in five incompatible configuration formats.

![A dark neon expanse where five small angular light-vessels attempt to pass a chain of glowing waypoints by leaping between them through empty air, each leap dimmer and more crooked than the last, while alongside them a single vessel instead lays a continuous solid glowing rail ahead of itself and travels it smoothly past all five.](https://kinlane-images.s3.amazonaws.com/apievangelist/api-evangelist-images/newsletter/2026-09-07-five-tool-calls.png)

## Moving Past About Five Tool Calls, You Are Gluing With Inference

This was the week's convergence, and it came from four unrelated directions.

- [Red Hat wrote up the last-mile problem in agentic AI](https://www.redhat.com/en/blog/last-mile-problem-agentic-ai-why-tool-calling-reliability-harder-it-looks) — tool-calling reliability is harder than it looks, and it degrades with chain length. [RunPod approached the same wall from the context side](https://www.runpod.io/blog/designing-mcp-tools). [Postman published how agents actually discover and integrate public APIs](https://blog.postman.com/how-ai-agents-discover-and-integrate-public-apis/).
- And Jens Neuse said it plainly on the podcast: past about five MCP tool calls, you are gluing them together with inference — and inference is slow, expensive and unpredictable, so the architecture is simply wrong. Models are good at writing code. Let them write a program and run it.
- I had written [agents should write code to integrate, not infer it at runtime](https://apievangelist.com/2026/09/01/agents-should-write-code-to-integrate-not-infer/) two days before that conversation, and [the deterministic integration layer is being built from both ends](https://apievangelist.com/2026/09/02/the-deterministic-integration-layer-is-being-built-from-both-ends/) the day after. Arriving at the same place independently is worth more than agreeing in a room.

If that read is right, it reframes the whole MCP tooling conversation. The valuable MCP server is not the one with the most tools. It is the one whose tools compose into a program the model can write once and execute deterministically — which is an API design problem, and an old one, wearing a new protocol.

![A long dark neon avenue lined with tall unmarked doorways, each with a small glowing hand-crank and no automatic mechanism, small angular light-vessels stalled at four of them, while at the avenue's far end a single vast blank hall stands open and empty, its floor unmarked, with several faint competing boundary lines drawn across it that do not meet.](https://kinlane-images.s3.amazonaws.com/apievangelist/api-evangelist-images/newsletter/2026-09-07-from-my-desk-where-specs-live.png)

## From My Desk: Where a Specification Lives, and Who Registers What

One number before the links. Across 8,601 unique posts this week, **OpenAPI was named in exactly one third-party post title** — [Redocly's, on generating agent-friendly SDKs and tooling from an OpenAPI description](https://redocly.com/blog/agent-friendly-sdks). One. The description layer everything above depends on is invisible in the discourse again, two weeks after it briefly reappeared as a malware vector. That is the whole reason I spent this week on the registry.

- **The extension-registration thread.** [Redocly already knows how to register an OpenAPI extension](https://apievangelist.com/2026/09/03/redocly-already-knows-how-to-register-an-openapi-extension/) — they do it correctly and almost nobody noticed. [Speakeasy has thirty-six OpenAPI extensions and zero registered](https://apievangelist.com/2026/09/04/speakeasy-has-thirty-six-openapi-extensions-and-zero-registered/). [RFC 10008 left a slot open and somebody is standing in it](https://apievangelist.com/2026/09/03/rfc-10008-left-a-slot-open-and-somebody-is-standing-in-it/). And the frame underneath all three: [every specification is a land grab](https://apievangelist.com/2026/09/02/every-specification-is-a-land-grab/). Registration is the cheapest governance act in our entire stack and the least performed.
- [**A conversation with Lukasz Gornicki on what the Linux Foundation actually gave AsyncAPI, why a sponsor walked away because of it, and Open Source Europe as a home for a specification**](https://conversations.apievangelist.com/store/2026-09-01-lukasz-gornicki/)**.** Lukasz ran AsyncAPI as executive director, which means he has already run the experiment everyone else is theorizing about. I brought him the question I have been carrying since I forked Spectral: where should a rule-set specification live? What I got back was not a recommendation, it was a set of distinctions — the Linux Foundation gave AsyncAPI intellectual property and trademark protection and very little else, protection that turns out to mean a free letter from a lawyer after which you need a litigation budget you do not have. It funds no engineering. And one sponsor declined to renew *specifically because* AsyncAPI joined. If you are about to put your specification in a foundation, listen to this before you sign anything. Related: [what matters most in forking Spectral](https://apievangelist.com/2026/09/01/what-matters-most-in-forking-spectral/).
- [**A conversation with Jens Neuse on GraphQL federation, deterministic joins, and why MCP has very little to do with agents calling APIs**](https://conversations.apievangelist.com/store/2026-09-03-jens-neuse/)**.** Jens is co-founder and CEO of WunderGraph, whose Cosmo federation stack runs inside Mercedes, Rivian and eBay. Two halves: what federation actually buys you — fragments so a UI can evolve without leaving dead fields in a REST API forever, entities so separate teams can join data deterministically rather than hopefully — and then the five-tool-call claim in the section above. He also points out, correctly and a little witheringly, that we invented Web MCP while the user agent has been sitting in the HTTP header the entire time.
- **The onboarding series kept grading doors,** and the doors kept failing in new and specific ways. [Zoom gets the headless half right](https://apievangelist.com/2026/08/31/zoom-server-to-server-oauth-is-headless/). [Mintlify put signup in the CLI when it was already in the protocol](https://apievangelist.com/2026/08/31/mintlify-put-signup-in-the-cli-when-it-was-already-in-the-protocol/). [Salesforce actually has a create-an-app API and still makes you work for it](https://apievangelist.com/2026/09/02/salesforce-connected-apps-via-metadata/). [Square made the OAuth dance scriptable but left onboarding at the dashboard door](https://apievangelist.com/2026/09/04/square-oauth-dance-dashboard-app/). [PayPal lets you mint a token, but not register the app](https://apievangelist.com/2026/09/06/paypal-client-credentials-dashboard-app/). Then I turned the grader on myself: [I graded everyone else's onboarding, here is mine](https://apievangelist.com/2026/09/02/i-graded-everyone-elses-onboarding-here-is-mine/).
- **Also this week:** [the four plans I landed on for APIs.io](https://apievangelist.com/2026/09/01/the-four-plans-i-landed-on-for-apis-io/) and [inside the agent-readiness score](https://apievangelist.com/2026/08/30/inside-the-agent-readiness-score/). [I want you to own the integration](https://apievangelist.com/2026/09/03/i-want-you-to-own-the-integration/). [The blog was the retrieval layer all along](https://apievangelist.com/2026/09/04/the-blog-was-the-retrieval-layer-all-along/) — which, after a week of reading 8,601 of them, I believe more than when I wrote it. [Agents will make everything you left undone visible](https://apievangelist.com/2026/08/31/agents-will-make-everything-you-left-undone-visible/). And [I am leaving Naftiko behind to focus on API Evangelist and APIs.io](https://apievangelist.com/2026/09/01/leaving-naftiko-behind-to-focus-on-api-evangelist-and-apis-io/).

Two things worth putting next to each other on the way out.

Agent payments, which had four competing protocols and a volume fight two weeks running, produced **five posts this week**. Not a collapse — a pause. But if you were told in August that agentic commerce was the story of the autumn, note that it went quiet the same week identity got loud, and draw whatever conclusion you like about how many things this industry can pay attention to at once.

And the number I keep coming back to: 435 of this week's 8,601 posts carried an API signal in the title. Five percent. We have built an entire agentic apparatus — identity providers, gateways, protocols, taxonomies — on top of a description layer that ninety-five percent of the people writing about it never mention. Every argument in this issue eventually terminates in a question about what an API actually does and who said so. That answer lives in a document almost nobody is talking about, and which one company registered its extensions for.

See you next week.

***

**🔌 **[**APIs.io Understanding — the security and scopes collections**](https://apis.io/developer/plans/?utm_source=apievangelist&utm_medium=email&utm_campaign=apisio-pro&utm_content=footer) — This entire issue argues that authorization, not identity, is where the agent problem gets decided. The part I can actually hand you is the evidence: every OAuth scope and every security definition extracted from every API in the catalog, as collections you can query.

Eighteen of the twenty per-artifact endpoints on APIs.io are free. `security` and `scopes` are the two that are not, and they are the two people push on hardest — a keyless call to either returns a `402` naming the tier, which is the honest version of a paywall.

**The operation worth your week:** before you write another scope string, go read how a few hundred other providers named and split theirs, then check which auth schemes those same providers actually declare.

```javascript
curl -H "X-API-Key: $KEY" "https://apis.io/api/v1/scopes?limit=50"
curl -H "X-API-Key: $KEY" "https://apis.io/api/v1/security?limit=50"
```

Same data as the `find_scopes` and `find_security` MCP tools, if you would rather ask an agent than write a loop. **Understanding is $199/mo, or $1,990/yr** — [log in with GitHub](https://apis.io/api/v1/auth/login) for a free Learn key first and see how far the free tier carries you.

***

## Discussion

No replies yet.
