Story · WorkOS

Keeping credentials out of an AI agent's context with Relay (WorkOS)

blog post · Story page

WorkOS built Relay on a blunt premise: a credential the agent never holds can't leak. The proxy fields the agent's third-party API calls and injects the secret at the API boundary, so even a fully hijacked agent comes up empty-handed.

In plain words

  • WorkOS created Relay to keep login secrets away from an agent, an artificial intelligence (AI) system that takes actions independently.
  • Relay receives the agent's requests to outside services, then adds the needed secret only while forwarding each request.
  • Organizations using action-taking AI can limit theft of login secrets even when attackers manipulate the agent.

Appeared in

Subscribe

Get the brief in your inbox

Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.

  • Weekdays at 8:45am IST, one lead story and 6 to 9 items.
  • Sundays, an argued synthesis rather than a recap.
  • One click to leave, and quiet days say so in the subject line.
How often

Weekdays 8:45am IST + Sundays. Unsubscribe in one click.

You're asking for The Agentic Brief by email at the cadence you picked. You can unsubscribe in one click from any issue, and your address is never sold or shared.