A weekend horror story involving a runaway summarization agent has prompted a new deep dive into theAuth, an open-source authentication library for AI agents. The incident, where a single worker agent exhausted a provider budget through endless retries, highlighted a critical gap in agent orchestration: valid credentials do not equate to affordable or safe operations. The new guide details how to implement three essential controlsβnarrow grants with expiration, enforced spend caps, and human approval checkpointsβto prevent such failures.
Delegation and Scoped Access
The foundation of the security model is scoped delegation via theAuth's delegate() function. In the guide's example, a planner agent grants a summarizer agent read-only access to GitHub issues for exactly 30 minutes, with a maximum delegation depth of one. This ensures that compromised agents cannot mint permissions they do not possess, and that access expires automatically, reducing the attack surface. The authorize() function checks these scoped permissions, but it does not inherently enforce budget limits or approval requirements.
Enforcing Budget Policies
Budget control is handled separately through theauth.policies. The guide demonstrates creating soft and hard limits: a warning at 800 units of cost and a block at 1,000 units. Crucially, the authorize() function does not consult these policies; developers must explicitly call checkBudget() before any LLM invocation and recordUsage() after. This design places the enforcement burden on the application code, requiring a wrapper function to ensure that no model call proceeds without passing the budget check. The system supports various actions, including warn, throttle, block, and revoke, though currently, the latter three all result in a block.
Human Approval for Destructive Actions
For irreversible actions like file deletion or financial transactions, theAuth introduces an approval workflow. By setting requireApproval: true on a permission, the authorize() function denies the action and triggers an approval request. The system stores this request, but the application must handle the notification and the subsequent execution. A key nuance is that approval does not bypass the permission check; once a human approves the request, the application code must explicitly check the approval status and then execute the action. The guide warns that authorize() will still return false for the action even after approval, forcing developers to implement a custom gate.
Cost Attribution and Reporting
To track spending across complex agent chains, the guide details the cost attribution module. This standalone component records costs per agent, tool, and delegation chain, allowing developers to roll up expenses for entire workflows. The module supports alert thresholds for warning and critical spending levels, with options to automatically revoke agents when budget limits are exceeded. However, the guide notes that these alerts are level-triggered, meaning they fire repeatedly while the threshold is breached, requiring deduplication logic in the notification handler.
Key Takeaways
- Delegation controls permissions and expiry, but not cost.
- Budget checks must be manually invoked via
checkBudget()andrecordUsage(). - Human approval requires custom application logic to execute the approved action.
- Cost attribution tracks spend per chain but requires careful unit consistency.
The Bottom Line
theAuth provides the primitives for agent governance, but it is not a plug-and-play firewall. Developers must build the enforcement layer themselves, treating budget checks and approval gates as explicit application logic rather than implicit security features.