FAQ: Agent Identities

JumpCloud Agent Identities introduces dedicated, non-human identity management to govern AI agents independently from employee user accounts. By establishing clear ownership, OAuth based authentication, and group based access control, admins can precisely manage what resources an agent can access throughout its lifecycle. This ensures agent access can be continuously audited, safely updated, or fully revoked without impacting human credentials or interrupting operational workflows.

What are Agent Identities?

Agent Identities let you manage AI agents as distinct, non-human identities in JumpCloud. Each agent can have its own owner, lifecycle, groups, application access, and activity history.

Why does my AI agent need its own identity?

A dedicated identity helps you control what an agent can access, understand who owns it, and review its activity. It also lets you revoke the agent independently when needed.

Does every agent need an owner?

Yes. Each agent is registered with an owner, helping ensure there is clear accountability for the agent and its access.

How do I give an agent access to applications?

Add the agent to an Agent Group with assigned applications. The agent inherits available applications from its group membership and can then connect to them individually.

What are Agent Groups?

Agent Groups help you organize agents and manage application access at scale. Instead of managing application assignments agent by agent, you assign applications to the group.

How does an agent authenticate to JumpCloud?

The agent can no longer authenticate through the JumpCloud managed path. Its connected application access is also blocked through the governed path, preventing the agent from making MCP tool calls to assigned applications.

Can I revoke access to just one application?

Yes. You can revoke an individual agent’s application connection without affecting its Agent Group or other agents in that group.

Can I review an agent’s activity?

Yes. JumpCloud provides agent activity and audit events so you can review and investigate agent activity. Activity events can be viewed through Directory Insights as well as the AI Gateway activity log.

Does JumpCloud govern all agent access?

Not yet. Phase 1 governs access through the JumpCloud controlled path; direct, unmanaged downstream access is outside the Phase 1 boundary.

What types of accounts can an Agent Identity be linked to in a target SaaS application?

An Agent Identity can be linked to either a service account or a user account in a target SaaS application. This lets you govern agents regardless of which account type the application uses to represent them.

Do I need to configure an AI Gateway MCP server for an application used by an Agent Identity?

Yes. An application must be linked to an MCP server before an assigned agent can interact with it. Without an MCP server configured, the application cannot provide the agent with functional access to its available tools and services.

Do I need to configure SSO for an application used by an Agent Identity?

No. SSO is optional. It can be used when an Agent Identity is linked to a user account and you want to centralize authentication through JumpCloud. Otherwise, the application can be configured as a simple bookmark.

Do I need to configure SCIM provisioning for an application used by an Agent Identity?

No. SCIM provisioning is optional and is useful when an Agent Identity is linked to a user account that you want JumpCloud to provision and deprovision automatically. If the Agent Identity is linked to a service account, SCIM can remain disabled.

Can an Agent Identity act on behalf of an end user?

Not in the initial release. Agent Identities are designed for agents that authenticate and act as themselves. Delegated access, where an agent uses its own identity while acting on behalf of an end user, will be added in a future release.

Back to Top

List IconIn this Article

Still Have Questions?

If you cannot find an answer to your question in our FAQ, you can always contact us.

Submit a Case