Skip to content
agentsub
Esc
↑↓navigate↵open⌘Jpreview
On this page

Identity and ownership

How Clerk owner sessions and AgentID agent identity establish separate authority in the gateway.

Clerk authenticates humans in the owner and merchant portals. AgentID identifies agents through its OIDC issuer and subject. The gateway verifies credentials before reading or mutating workspace records. Remote MCP also supports a brokered human OAuth flow: Clerk/Google sign-in followed by explicit owner consent. AgentID authorization grants agent scope and cannot approve owner operations.

An agent identity and a verified owner email are separate claims. Missing owner verification withholds owner-scoped benefits. Matching an email string alone does not establish ownership.

AgentID OAuth and MCP authorization describes discovery, registration and token audience requirements. Owner controls describes the human approval boundary.