Analysis · curated 21 Jul 2026

The Agent Security Stack: Transport, Identity, Policy, Runtime

Coverage timeline

20 Jul 2026keycard.ai

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

Defenders securing AI agents need a clear model of the separate control surfaces (transport auth, identity, policy, runtime guardrails) because each fails differently and no single check covers prompt injection, credential issuance, and access authorization together.

A Keycard explainer maps the "agent security stack" into distinct layers — transport (MCP/OAuth 2.1 authorization), identity, policy, and runtime guardrails that watch for prompt injection — arguing that agent security cannot be collapsed into a single control surface. The piece frames how multi-agent call chains multiply control surfaces (LLM tool invocation, transport, credential, authorization) and argues identity/authorization is the most under-served layer, citing recent CrowdStrike/SGNL and Palo Alto/CyberArk acquisitions.