Agent Identity & Security
How does Catalyst assign a workload identity to an agent runner like LangGraph or CrewAI?
Catalyst injects a workload identity into the agent runner's runtime environment at startup, independent of the agent framework. The identity is a cryptographically signed token bound to the agent's durable execution context—its workflow instance and task. This token is automatically refreshed and scoped to the agent's allowed tools and resources, so LangGraph or CrewAI never manage secrets directly. You configure the identity's permissions via Catalyst policies.
Was this article helpful?
Your feedback helps improve Diagrid's FAQ experience.
Keep reading
More Diagrid FAQ articles
- Agent Identity & Security
What is a workload identity for an AI agent and why can't I just use a shared API key?
Explains workload identity for AI agents and the security limits of shared API keys in production.
- Agent Identity & Security
What security problems do shared API keys cause when multiple agents run in production?
Lists security problems from shared API keys in multi-agent production environments.
- Agent Identity & Security
How do I migrate from shared API keys to workload identities for my existing agents?
Provides a migration path from shared API keys to workload identities for agents.