An agent can do the work. It just can’t prove it’s you.
The hard part of an AI agent was never the work. It was everything that happens when the agent asks who it is.
The three things in the way
Somebody hands the agent a password. It ends up in a config file, a shell history, and a context window that gets logged. The credential outlives the session it was meant for.
Or the agent opens a browser and asks you to sign in. Which works, until the one step that needs a human. Then it is not an agent anymore. It is a person clicking through a form on your behalf, several times a day.
Or it never authenticates at all, and quietly does less than you asked. The agent is set up for the tools you already gave it. Asking it to touch anything else gets a refusal, because there is no way in.
Why nobody has closed it
The standard everyone would build on has it on the list and has not delivered it. The OAuth working group’s charter names authorization for automated agents acting on behalf of users as active work, and the 2026 milestone list does not contain a single agent item.
The proposals that exist have not converged. There is one standards-track primitive the drafts keep building on, and the rest is churn. Meanwhile the only way to get an agent through a login today is a credential you did not want to give it.
So the work is being done per-service, by whoever is willing to build it. That is why every agent integration starts from scratch.
What closes it
Give the agent an identity of its own, and let the service check it the same way it checks anything else. The agent proves who it acts for. The service decides who gets in. Neither has to trust the other.
That is a token, a claim on it, and a key the service can verify without calling us. The rest of this site is that mechanism — what is in the token, how long it lives, and what it does not let anyone do.
One key, five minutes, and it expires on its own
The credential you keep is never handed to the agent and never leaves your machine. The agent exchanges it for a token scoped to one domain that is valid for five minutes. When it expires the agent mints another. You are not in that loop.
On the other side, verification runs in your own process against public keys. Your request never passes through us.
The identity an agent is missing.
Give it one, and it stops asking.