Menu
What is AI agent authorization?
AI agent authorization decides whether a specific agent may perform a specific action on a specific resource before the consequential action executes.
Authentication is not authorization
Authentication establishes which agent is making a request. Authorization answers the separate question: is this agent allowed to perform this action on this resource right now?
Use explicit resource and action boundaries
Instead of giving an agent broad access, define authority such as a resource and action pair. This makes least privilege concrete and reviewable.
Enforce authorization before execution
The security decision should happen before the external API, tool, payment, database change or infrastructure action occurs. A deny decision should fail closed rather than execute first and audit later.
Human approval for high-impact actions
Some actions can be valid but still require a person. A require-approval decision lets policy pause execution until the configured approval requirement is satisfied.
Nodra runtime authorization
Nodra evaluates protected agent identity, explicit authority and policy, returns allow, deny or require-approval, and records security evidence around the decision and execution result.
See the JavaScript SDK