Auth0 for AI Agents preview

The problem

Enterprises are deploying AI agents faster than they can secure them. An agent that acts on someone’s behalf has to log that person in, call APIs with their permission, and never quietly exceed what it was granted. None of that existed as a product yet.

This wasn’t a dashboard to tidy up. It was a net-new suite of capabilities, most of it living in code rather than screens: authenticating users into agents, a Token Vault for calling third-party APIs on a user’s behalf, asynchronous authorization for human approval of sensitive actions, and fine-grained authorization for RAG. The hard part wasn’t styling a UI. It was making a developer-first, mostly headless product legible, so the security model was obvious in a few lines of code and a couple of toggles instead of buried in docs.

What I did

I led design across every surface a developer touches, and the few an end user does.

A user request flows left to right through user authentication, an Auth0 engine that pulls scoped credentials from Token Vault, gates risky steps behind async authorization, and constrains retrieval with fine-grained authorization, ending in a completed agent response.
Authentication, Token Vault, Async approval, and Fine-grained Authorization for RAG.

The center of gravity was the developer experience, not a control panel. I shaped how onboarding gets someone from zero to an authenticated agent quickly, how the SDK reads, and how the docs and sample apps teach delegation instead of just listing endpoints. The guiding constraint, straight from the product promise, was “a few lines of code.”

Where the product did surface in the dashboard, I held it to the minimum that mattered: clear, low-friction toggles to turn on capabilities like Token Vault and connect an agent to a user’s third-party apps, without dragging admins into a sprawling new console.

The two moments an end user actually sees are signing in and granting consent, so those got the most care. When an agent attempts something sensitive, asynchronous authorization pauses it and asks a real person to confirm, out of band. I designed that consent moment to be unmistakable and fast, so the answer to “did an agent just move my money?” is always a deliberate yes, never a default.

An agent sign-in screen reading 'Log in to continue' with an email field, a Continue button, and options to continue with passkeys or Google.
Authentication
An async approval exchange where the agent says it has sent a request to approve a transfer, shows the Auth0 SDK call, and surfaces an 'Approve $10k transfer?' confirmation that is then approved.
Async authorization

The outcome

The work gave a sprawling, deeply technical initiative a single product story. That story became the primary vehicle for executive alignment and shaped the roadmap behind Auth0’s AI agent strategy.

It shipped, and it’s live: the landing page, the developer docs, and Auth for MCP.

It also earned outside recognition: Auth0 for AI Agents won theCUBE and SiliconANGLE’s Tech Innovation CUBEd Award for Most Innovative AI Infrastructure Security Solution.

Next project Guide with Okta AI

Let’s talk.

Tell me about the role and team, whether it’s a product design lead, IC, or something in between, and I’ll get back to you.

I typically respond within 48 hours during business days.