How Ory Handles Identity and Access Management for AI Agents

Ory treats AI agents as first-class identities. Its Agent IAM (Agent Security) product gives every agent its own identity and permissions, then enforces those permissions at runtime with in-the-loop checks, so you get visibility and control over what agents do across tools like Claude Code, Codex, and Gemini. This is relevant if you run autonomous workflows or machine-to-machine systems and need authorization and audit controls, not just a login layer for humans.

What problem it solves

Traditional IAM assumes a human logs in once and acts within a session. Agents behave differently: they act on their own, call tools repeatedly, and may chain actions across systems. Ory's framing is "Every human. Every agent. Every tool call. One checkpoint." — meaning each agent, and each tool call it makes, passes through an identity and permission checkpoint rather than operating with inherited, unbounded access.

The three IAM tracks Ory offers

Ory splits its offering by who or what needs an identity:

Track Who it's for What it covers
Customer Identity (CIAM) People using your customer-facing apps Login, signup, privacy, scale
B2B Identity (B2B IAM) Your business customers and their teams SSO, SAML, SCIM, granular permissions
AI Agent Identity (Agent IAM) AI agents, autonomous workflows, machine-to-machine systems Auth, audit, and authorization for agentic systems

For agent use cases, the relevant track is Agent IAM. The other two matter when agents act on behalf of human users or enterprise tenants and need to inherit or be constrained by those identities.

How the agent controls work

Based on Ory's description, the mechanism has three parts:

  • Identity per agent — each agent gets its own identity rather than sharing a service account, so actions are attributable.
  • Permissions per agent — you define what each agent is allowed to do, giving granular rather than blanket access.
  • Runtime, in-the-loop enforcement — permission checks happen while the agent is running, at the point of each tool call, not only at setup time. This is what produces the "visibility and control" across supported tools.

Ory states Agent Security works across Claude Code, Codex, Gemini, and more, positioning it as a checkpoint layer that sits in front of agent tool calls rather than inside any single model provider.

Deployment options

Ory's agent capabilities sit within the same deployment model as its other IAM products, so you choose how much you manage:

  • Open Source — run Ory's open-source IAM components on your own infrastructure. Useful for testing agent use cases or building a proof of concept, with no vendor lock-in.
  • Self-Hosted (Ory Enterprise License) — an optimized codebase with premium support for mission-critical environments. Runs on-prem, in your private cloud, or in air-gapped infrastructure, with enterprise SLAs, security patches, and direct engineering support.
  • Fully-Managed Cloud (Ory Network) — SaaS identity infrastructure with built-in compliance, automatic scaling, and zero operational overhead. Ory describes this as the fastest path to production.

If your agents touch regulated or air-gapped systems, the self-hosted or open-source paths are the ones to evaluate. If you want to avoid running identity infrastructure yourself, Ory Network is the intended option.

What to check before deciding

  • Which tools your agents use — Ory names Claude Code, Codex, and Gemini as supported; confirm coverage for any other agent framework or tool in your stack.
  • Where enforcement needs to happen — runtime, in-the-loop checks are the core claim. Verify they fit your latency and architecture requirements.
  • Your compliance and hosting constraints — these determine whether open source, self-hosted, or Ory Network is viable.
  • Pricing and licensing terms — Ory publishes a pricing page, but the specific costs and license conditions for Agent IAM are not detailed in the material available here, so check the pricing page directly before committing.

For teams building agentic systems, the practical starting point is to map each agent to a distinct identity, define its allowed tool calls, and place Ory's checkpoint in the request path so every call is authorized and logged.

ory.com
Ory delivers identity and access management (IAM) for applications, enterprises, and AI agents. Cloud-native, API-first, and self-hostable.