Artificial intelligence only reaches its full potential when it can access the right data. In practice, however, this is often hindered by fragmented IT landscapes, disparate Identity Providers (IdPs), and stringent security requirements. In their article published in IT Spektrum, Detlev Altendorf and Stefan Braun show how the OAuth mechanism Token Exchange helps companies deploy AI agents securely, flexibly and cost-effectively across system and security boundaries.
AI agents need an identity of their own
Companies today hold vast amounts of valuable data, spread across ERP systems, CRM solutions, file servers, collaboration platforms and cloud applications. For AI applications in particular, this information is highly valuable, as it enables well-founded analysis and faster decision-making. The challenge, however, lies in connecting these data sources securely and in a controlled manner.
In this context, AI agents act as so-called Non-Human Identities (NHIs). To be deployed safely, they need a clearly defined identity along with tightly controlled and traceable access rights. The article therefore highlights the importance of modern Machine Identity Management (MIM), which manages identities automatically, grants access rights based on the least-privilege principle, and makes all activity traceable.
When different Identity Providers need to work together
Most companies today rely on a wide range of identity sources – from Microsoft Entra ID to SAP environments, partner portals or specialised IAM systems. Each of these platforms uses its own authentication methodes, token formats and trust models. This creates significant complexity for AI applications that need to access information across systems.
This is where Token Exchange comes in. Specified under RFC 8693, this mechanism acts as an "interpreter" between different security domains. Existing tokens are validated and automatically "translated" into new tokens valid for the respective target system. This allows AI agents to securely access resources across different systems without requiring fundamental changes to existing applications or identity infrastructures. At the same time, security zones remain clearly separated, and authorisations can be verified individually for each access request.
Greater security and flexibility with less integration effort
The key advantage of Token Exchange lies in its combination of security, scalability and cost-effectiveness. Companies don't need to consolidate their existing system landscape onto a single Identity Provider in order to deploy AI applications securely. Instead, a token exchange server enables controlled collaboration between different systems and security domains.
The authors conclude that this approach is particularly relevant for organisations that need to bring together complex information landscapes, multiple Identity Providers, and the growing use of Non-Human Identities as AI tools. Token Exchange lays the foundation for an identity-centric architecture in which AI agents can operate securely, access relevant information flexibly, and meet the highest security requirements – without costly changes to existing applications.
