Session
From Human Login to Agent Identity: OAuth/OIDC Patterns for LLMs
LLMs are no longer just chat interfaces.
They’re autonomous agents that call APIs, trigger workflows, and act on behalf of users and organizations.
But OAuth and OpenID Connect were designed for secure API access and human‑centric logins, not for chains of sub‑agents, headless CLIs, and tool‑calling loops. In this session, we’ll bridge that gap.
We’ll map identity models for AI (user‑delegated, autonomous, and on‑behalf‑of) and focus on the OAuth/OIDC patterns that matter for LLMs: Authorization Code + PKCE, client credentials, and RFC 8693 token exchange for least‑privilege, task‑scoped tokens. You’ll learn how to design scopes around LLM tools, keep tokens out of prompts and agent memory, and enforce authorization in tool wrappers so policy is centralized and auditable.
We’ll also cover workload identity federation, treating AI agents as non‑human identities with dedicated credentials, tenant isolation, short lifetimes, and immediate revocation.
By the end, you’ll have a clear mental model and concrete patterns to secure LLM tool calling and agentic workflows with OAuth and OIDC—whether you’re building .NET backends, integrating with the cloud, or designing your own agent platform.
Roland Guijt
Microsoft MVP and MCT, Pluralsight author
Utrecht, The Netherlands
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top