As AI agents and automation gain access to business applications and sensitive data, many organizations still manage them through borrowed user accounts, shared credentials, and unmanaged API keys. When an agent or automation relies only on a human user account, any employee changes can break its access: it can continue acting after the employee is offboarded, or act with more access than intended.
Agent Identities introduces dedicated, non-human identity management to govern AI agents independently from employee user accounts. With Agent Identities, you can manage AI agents like digital employees, giving each agent its own identity, application access, lifecycle, and accountable human owner.
In the JumpCloud Admin Portal, you can:
- Register Agents and establish clear ownership.
- Organize them with Agent Groups.
- Control which enterprise applications they can access using OAuth-based authentication.
- Connect those applications through AI Gateway Model Context Protocol (MCP) servers.
You decide which agents exist, who owns them, how they authenticate, and which tools and applications they can reach, separating them from any one employee’s login. Using Agents and Agent Groups together with your SSO applications and AI Gateway servers ensures agent access configurable and revocable.
JumpCloud also provides other AI and SaaS security features such as SSO Applications, AI & SaaS Management, and AI Gateway for AI clients. These secure different stages of the AI lifecycle. Agent Identities adds admin-managed identities for automation and AI agents that use agent groups and AI Gateway for application connections. See Secure AI with JumpCloud to learn how these features work together.
Prerequisites:
- You must have the Administrator with Billing, Administrator, or Manager role to manage agents. See Admin Portal Roles to learn more.
- For application connection flows that use MCP, register the application’s MCP server under Access > AI Gateway. See Get Started: AI Gateway.
Considerations:
- Application access for agents is assigned through Agent Groups only. Direct agent-to-application assignment is not supported in Public Preview.
- Agent Group membership supports static associations only. Dynamic group membership is not available.
- Suspending or deleting an agent blocks authentication and application connections through JumpCloud and the AI Gateway.
Key Features and Benefits
- Control agent registration, ownership, authentication, and application access. Agents no longer require ad hoc user credentials.
- Separate agent access from a single employee’s account, so personnel changes don’t break or over-privilege an agent.
- Assign applications through Agent Groups (parallel to how user groups work for users).
- Connect agents to enterprise applications through AI Gateway MCP servers with clear connection status.
- Suspend or delete an agent to block authentication and connected app access without suspending the human Owner.
Understanding Differences Between Agents and Users
Understanding Agents and Users
| Concept | Users | Agents |
|---|---|---|
| Where you manage them | Identity Management > Users | Identity Management > Agents |
| Grouping | User Groups | Agent Groups |
| Who is accountable | The user (and admins) | Required JumpCloud Owner (user) |
| How they authenticate | Password, MFA, federation, and related authentication methods | OAuth client credentials |
| How they get applications | User groups and related associations | Agent groups only |
| Portal login | User Portal | No User Portal or Admin Portal login |
See Get Started: Agents and Get Started: Agent Groups to learn more.
Using Agents, Agent Groups, SSO Applications, and AI Gateway
- SSO application: The enterprise application you already manage in JumpCloud (for example Slack or GitHub). When you add an MCP server in AI Gateway, the App dropdown lists SSO applications already configured in your org. An application in that list does not mean it natively supports MCP, so verify with the vendor first. See Secure AI with JumpCloud and Get Started: AI Gateway to learn more.
- AI Gateway MCP server: The MCP registration for that application under Access > AI Gateway. The gateway routes and governs MCP tool access.
- Agent Group: You assign SSO applications to an agent group. Membership makes those apps available to member agents.
- Agent connection: On the agent’s Applications tab, use Manage connections to authorize as the agent and complete MCP authorization. Status badges include Connected, Not Connected, and Setup AI Gateway.
Recommended Configuration
- Register MCP servers for the SSO applications you need in Access > AI Gateway.
- Create Agent Groups and assign applications on the group Applications tab.
- Create Agents (name, owner, company email) under Identity Management > Agents.
- On the agent Authentication tab, generate OAuth client credentials.
- Add the agent to agent groups.
- On the agent Applications tab, use Manage connections to connect available applications.
Accessing Agents and Agent Groups
- Log in to the JumpCloud Admin Portal.
- Go to Identity Management > Agents or Identity Management > Agent Groups.
FAQ
See FAQ: Agent Identities to learn more.