Between shadow AI and blind permissions: Navigating agent accountability
Ory Corp
Ory is pitching plugins that give coding agents real identities and permissions. It plugs into Claude Code, Codex, Gemini CLI and others, with local setup in one command.
Based on reporting by Ory Corp — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
Ory is trying to put a seatbelt on coding agents. Its new DX push bundles agent plugins, MCP tools, CLI access, and a security layer that gives each agent its own identity instead of letting everything run on shared credentials and wishful thinking.
The company says the setup works across several agent harnesses and SDKs, including Claude Code, Codex, Gemini CLI, OpenClaw, OpenCode, and Microsoft Agent Framework. The pitch is portability: one package per agent, the same skills and policies across tools, and no need to glue together a different auth story every time a team swaps runtimes.
A lot of the machinery is about identity and access. Ory talks about customer identity, OAuth, permissions, B2B SSO, and agent security built in with Ory best practices. It also says its Agent Security product gives every agent its own identity, scoped to what it actually needs and revocable, which is the part that matters when agents start doing more than autocomplete.
There is also a strong self-hosted angle. Ory says teams can run open-source Kratos, Hydra, and Keto locally with no cloud account and no config files from scratch, or use Ory Network to get started in minutes. Early adopters can run Agent Security on Ory Network at no cost for a limited time.
The rest of the package is meant to make setup less painful. Ory says one command can bring Kratos, Hydra, and Keto online locally, seeded and ready. Its CLI and REST API are exposed as MCP tools, so an agent can create identities, register OAuth clients, and manage relation tuples without someone copy-pasting commands. The company is clearly betting that agent security will not be a separate product forever; it will just be part of the workflow.
My take — AI-written commentary, not fact-checked reporting
The industry keeps building agents that can act, then acting surprised when they also need permissions. Ory is right to make identity the default, because blind access is how you turn automation into a cleanup job. The funny part is that security is only now being sold as a productivity feature, which tells you how much damage the hype cycle has already done.
Read more about this at: Ory Corp