One identity provider for every AI agent.

The agents you run, and the agents your customers send.

The agents you run

Your workforce signs in with your IdP. Now your agents do too.

Operators delegate their live entitlements. Agents get 10-minute tokens scoped to exactly those. Deactivate the human, and their agents suspend with them.

See how the platform works →
Issued by Eniyan
support-agent-v2
Operated by Acme Marketplace
scopes from IdP group support-l2: live while members hold it
Active · expires in 10 minutes
The agents your customers send

Willa's grocery agent shops with her money: under her rules.

Consent-scored delegations with per-transaction caps, budgets, and approved counterparties baked into every 5-minute token. Revoke it, and the very next check says inactive.

Explore Transaction Governance →
Delegation · grocery agent
$200
per order
$600
per month
3
merchants
CAL 3
consent
Live · revocable in one call
OIDCSAML 2.0SCIM 2.0OAuth 2.0RFC 9396RFC 7662W3C VCES256 · ML-DSA-65EU AI Act
Live

Both directions, on the record.

Every mint, refusal, revocation, and attestation, workforce and consumer alike, lands in one tamper-evident audit chain, delivered by webhook in real time.

Control plane: live
09:41:02Workforcetoken minted · support-agent-v2 · scopes from support-l2 · 10 min
09:41:19Consumerintrospection · delegation active · CAL 3
09:42:04Consumerrefused · $260 order exceeds the $200 per-order cap
09:42:37Workforcetoken minted · billing-agent · scopes from finance-ops · 10 min
09:43:10Workforcerevoked · operator offboarded via SCIM · agents suspended
09:43:41Workforceattested · task complete · audit entry sealed
Illustrative stream. Every event lands in your org's audit log: filter by event type, export it, and subscribe via webhooks.

The platform

One control plane. Identity and risk.

Federate your agents to the identity provider you already run, delegate live entitlements instead of secrets, and govern every action at runtime: one auditable chain from an accountable human to the agents acting for them.

01

Federate

Connect your identity provider

OIDC/SAML SSO and SCIM 2.0 sync your people and groups, and when someone is deactivated, their agents suspend with them. Your joiner–mover–leaver process, extended to agents.

Included in every planLearn more →
02

Delegate

Entitlements, not secrets

Operators delegate their live IdP entitlements to agents. Each agent trades a verifiable credential for a 10-minute OAuth token scoped to exactly those entitlements. No static secrets, no standing access.

Included in every planLearn more →
03

Govern

Risk Management

Control what agents actually do at runtime. Enforce scope, grant access just-in-time with zero standing privileges, attest tasks after the fact, and detect operator and insider risk.

Included in every planLearn more →

Capabilities

Everything an identity team expects, and the risk controls agents demand.

01

IdP Federation

Connect your identity provider

OIDC + SAML single sign-on
Your people sign in with the identity provider you already run. No second directory to maintain.
SCIM 2.0 provisioning + offboarding cascade
Users and groups sync automatically. Deactivate someone and every agent anchored to them suspends.
Entitlement delegation + multi-operator certs
Delegations lapse the moment the human loses the group. Multi-operator certificates stay valid only while every member delegates.
Agent OAuth token service
A verifiable credential trades for a 10-minute OAuth token. PKCE issuance and RFC 7662 introspection: standard tooling works unchanged.
02

Risk Management

Govern what agents do

Just-in-time access
Agent credentials are suspended between tasks. One call opens a named, scoped, time-bounded window.
Scope enforcement
Advisory flag or hard block, org-wide or per agent. Every violation audited and delivered by webhook.
Post-task operator attestation
Operators attest to what an agent did. Revoke the human and their agents cascade-suspend automatically.
Operator & insider-risk detection
Surface anomalous behaviour across your fleet before it becomes an incident.
03

Consumer Delegation

Agentic transaction governance

Consent ceremonies scored by CAL
Every grant is scored for consent quality, with hard caps for duress and coercion.
Caps, budgets & counterparty allow-lists
Limits live on the delegation itself: checked before any token exists, not after the money moves.
5-minute transaction-constrained tokens
The exact transaction rides inside the token; the customer is the subject, the agent the actor.
Verified step-up + live revocation
Sensitive transactions can demand an identity check or MFA. Revocation lands on the very next introspection call.
04

Verification & Transparency

Public agent verification

Public verification seals
A public verification page with a structured scope checklist your customers can check before they engage.
EU AI Act Article 50 disclosure
A reviewed, third-party-verified artifact anyone can open. No account required.

What your customers see

Verification anyone can check. No account required.

Consumer-facing agents get a public verification page with a structured scope checklist and the Eniyan seal, supporting EU AI Act Article 50 disclosure. And a signed view link shows each customer exactly what they delegated: scopes, caps, remaining budget, and the step-up rules protecting them.

EniyanIdentity verified by Eniyan
grocery-agent
Operated by FreshCart
Verified
Groceries and household staples onlyUp to $200 per order · $600 per monthThree approved merchantsLarger orders need Willa's approval

public verification page · pairwise · no PII

Compatibility

Works with the identity provider you already run.

Federate over standard OIDC, SAML 2.0, and SCIM. No rip-and-replace, no proprietary connectors. If it speaks OIDC or SAML, it works.

Identity providerOIDC SSOSAML 2.0SCIM provisioningGroup Push
OktaSupportedSupportedSupportedSupported
Microsoft Entra IDSupportedSupportedSupportedSupported
Auth0SupportedSupportedSupportedSupported
OneLoginSupportedSupportedSupportedSupported
Ping IdentitySupportedSupportedSupportedSupported
JumpCloudSupportedSupportedSupportedSupported
Google WorkspaceSupportedSupportedUsers onlyNot supported
Any OIDC / SAML IdPSupportedSupportedSupportedSupported

Google Workspace supports SSO today; group-based delegation needs an IdP with SCIM group push. Don't see yours? If it speaks OIDC or SAML, it works.

Why Eniyan

Not another secret to rotate.

Service accounts and secrets managers still leave you with standing credentials no one owns. Eniyan ties every agent to a live human identity, and takes the access away the moment that human loses it.

DIY service accountsSecrets managerEniyan
Agent credentialsLong-lived static secretsRotated, still standing10-minute tokens, none at rest
Tied to a human's live accessNoNoLapses when they lose the group
OffboardingManual, easily missedManual revokeAutomatic SCIM cascade
Who approved this agentUnknownUnknownAccountable operator on record
Runtime scope enforcementNoneNoneAdvisory flag or hard block
Public verifiabilityNoneNoneVerification seals (EU AI Act)

Who it's for

Built for the teams accountable for what agents do.

Security & IAM teams
Extend your IdP's joiner–mover–leaver controls to every agent: zero standing privileges, an accountable human behind each one.
Platform & AI engineering
Ship agents that authenticate with short-lived, scoped OAuth tokens instead of static secrets. Your existing tooling works unchanged.
Risk & compliance
A tamper-evident accountability chain from an SSO-verified human to every agent action, with public seals for EU AI Act Article 50.
Commerce & payments
Accept the agents your customers send: consent-scored delegations with caps, budgets, and counterparties enforced before money moves.

Pricing

One platform. Identity and risk in every plan.

Federation, delegation, and runtime risk controls ship in every tier. No SSO tax, none of the security features gated behind the top plan. Simple per-agent pricing, the way your IdP prices people.

Book a demo

Pick a time that works for you. We'll walk you through Eniyan for your use case.

See full pricing

Bring every agent under governance: the ones you run, and the ones your customers send.

See your own IdP groups delegated to a live workforce agent, and a consumer delegation minted, capped, and revoked, live: in about 30 minutes.

Book a demo

Pick a time that works for you. We'll walk you through Eniyan for your use case.

Start free