Every builder who wires an agent to Gmail hits the same wall. Firecrawl’s Hiba Fathima describes it plainly in an October 2026 roundup of nine AI agent authentication platforms: her first Gmail-connected agent used a personal OAuth token in an environment variable, and it broke the moment a second user showed up. Token storage, refresh, scope limits, attribution — the identity plumbing took longer than the agent itself.
That plumbing is now a product category. Knowing how the nine platforms divide up the problem matters more than knowing which one “wins.”
Four problems, not one
The useful framing from the Firecrawl piece is that “agent authentication” is four distinct problems:
- Inbound auth — who can call your agent or MCP server, typically OAuth 2.1 with PKCE and dynamic client registration.
- Outbound delegated auth — how the agent reaches Gmail, Slack, or Salesforce as a specific user: consent, token vault, refresh, narrow scopes.
- Agent identity — whether the agent has an identity of its own, separate from its human.
- Authorization and approval — fine-grained access rules plus human sign-off for risky actions.
The common failure, per the article, is solving only one. Teams add OAuth to their MCP server and call it secure while the agent still hits downstream APIs with a shared admin key. And keeping credentials out of the model’s context is as important as obtaining them — a prompt injection that can read a token can use it.
How the nine platforms split the work
The roundup maps each platform to a layer. Composio is the fastest path to per-user access across 1,500+ toolkits, with a free tier of 100,000 tool calls a month and the largest repo (30,379 GitHub stars) of the group. Auth0 for AI Agents is the default if you already run on Auth0 or Okta — its token vault and CIBA-based asynchronous approval cover both inbound and outbound, which few platforms do. Arcade enforces authorization at the moment the tool call runs, with per-user and per-agent identity checked together and credentials never reaching the model. Nango is the open-source, code-owned option for teams who want to self-host and write their own tools and syncs.
The interesting outlier is AgentMail, which doesn’t manage OAuth at all. It gives the agent its own real email address and, through Sign in with AgentID, a sign-in identity apps can verify — with the app learning which human owns the agent. Most of the list answers “what can the agent access on a user’s behalf?” AgentMail answers “who is the agent, and who is accountable for it?”
If your concern is scoping what different audiences can reach behind an MCP gateway, that maps closely to what I wrote earlier about HEMA’s per-audience MCP split on Bedrock AgentCore — inbound authorization and delegated outbound auth fail in different ways, and it pays to separate them.
Practical tradeoffs worth noting
- Composio itself recommends bringing your own OAuth app before you scale past its shared managed apps; enterprise controls like SSO and SCIM sit behind the Enterprise plan.
- Arcade’s governance features (audit logs, out-of-band human approval) shorten security review conversations, but Team pricing of $25/month plus $0.10 per auth event adds up for chatty agents.
- Auth0’s agent features ship as SDKs for Vercel AI SDK, LangChain, LlamaIndex, and Genkit — verify your framework is covered before committing, and note that teams not already on Auth0 face a full CIAM migration.
One limitation: the source article was supplied only in truncated form, so the details of platforms five through nine (WorkOS, AWS AgentCore Identity, Stytch, Keycard, and part of Nango) come from the summary table rather than the full write-up. Start by naming which of the four layers your current agent actually lacks — that usually collapses the nine options to one or two.
Sources
AI-assisted summary compiled from the sources above, reviewed by a human before publishing.
