Atlas works alongside your team in Slack to answer questions, automate tasks, and help everyone do their best work.
We are launching a remote MCP server that gives AI agents the same access to WorkOS as your dashboard login.
A managed gateway that handles API key verification, token decoding, and authorization so your backend does not have to.
Design and test AI agent policies that block unsafe actions and keep useful work moving. Learn to test intent, RBAC, and approvals, or try WorkOS Airlock.
An agent's task describes the work to do. Learn how to define useful intent while keeping identity, resource access, and company policy in force.
Airlock grew out of Atlas to give IT and security teams a shared way to govern agent actions. Aaron Tainter's Agent Night demo shows how it works.
Set GitHub permissions for AI code review, govern merges with Airlock, and prevent agents from merging code that changed after approval.
An agent can open a child session of itself for a sub-task. The chain re-derives authority at every hop and can never outlive its root.
Typed resources, structured errors, automatic retries, and AsyncSequence pagination for server-side Swift apps.
Codex, ChatGPT Work and Claude Code make five different choices about outbound network access. Here is what each one allows before you configure anything, what the docs publish, and where the boundary does not reach.
Every line has a literal answer and a real question behind it. Here is what the buyer is actually checking, which answers you can buy, and the three you cannot fake.
Envelope encryption, data keys, and why your sensitive data never has to leave your infrastructure
Both ship SSO, SCIM and audit logs now. The comparison that decides enterprise deals has moved to the long tail: provider coverage, where user lifecycle actually starts, and who is contractually on the hook.
The CLI gets you signed in. This is the session layer underneath it: what the sealed cookie holds, how to refresh it inside a before_action, and the three dashboard settings that break logout in production.
Sierra's MCP gateway iceberg is a field report on agent auth: identity, per-tool scopes, consent, and audit are the submerged mass, and they ship off the shelf.
The side effects nobody documents: analytics, lifecycle email, feature flags, webhooks, and the background job that runs as the wrong person an hour later.
How Neon used auth.md to let agents provision bounded database projects before a human signs up, then later transfer them to people who want to keep them.
Generic OIDC connections meet identity providers that read the same spec differently. Here are the per-connection compatibility settings we added, and why.
Please try a different search
Our global team is growing and we’re hiring all types of roles.
WorkOS builds developer tools for quickly adding enterprise features to applications.
We use cookies for analytics and advertising. See our cookie policy for details.