Diagrid
Back to all questions
Agent Identity & Security

How do I migrate from shared API keys to workload identities for my existing agents?

First, identify all shared keys your agents use for external tool access. Then, define Catalyst policies that map each agent's workload identity to the minimal set of tools and resources it needs. Update your agent runner configuration to use Catalyst's identity injection instead of hardcoded keys—Catalyst handles token acquisition and rotation. Test with one agent, validate audit logs, then roll out across your fleet. No changes to your agent framework code are required.

Was this article helpful?

Your feedback helps improve Diagrid's FAQ experience.

Keep reading

More Diagrid FAQ articles

View all