JumpCloud Agent Identities introduces dedicated, non-human identity management to govern AI agents independently from employee user accounts. By establishing clear ownership, OAuth based authentication, and group based access control, admins can precisely manage what resources an agent can access throughout its lifecycle. This ensures agent access can be continuously audited, safely updated, or fully revoked without impacting human credentials or interrupting operational workflows.
Agent Identities let you manage AI agents as distinct, non-human identities in JumpCloud. Each agent can have its own owner, lifecycle, groups, application access, and activity history.
A dedicated identity helps you control what an agent can access, understand who owns it, and review its activity. It also lets you revoke the agent independently when needed.
Yes. Each agent is registered with an owner, helping ensure there is clear accountability for the agent and its access.
Add the agent to an Agent Group with assigned applications. The agent inherits available applications from its group membership and can then connect to them individually.
Agent Groups help you organize agents and manage application access at scale. Instead of managing application assignments agent by agent, you assign applications to the group.
The agent can no longer authenticate through the JumpCloud managed path. Its connected application access is also blocked through the governed path, preventing the agent from making MCP tool calls to assigned applications.
Yes. You can revoke an individual agent’s application connection without affecting its Agent Group or other agents in that group.
Yes. JumpCloud provides agent activity and audit events so you can review and investigate agent activity. Activity events can be viewed through Directory Insights as well as the AI Gateway activity log.
Not yet. Phase 1 governs access through the JumpCloud controlled path; direct, unmanaged downstream access is outside the Phase 1 boundary.
An Agent Identity can be linked to either a service account or a user account in a target SaaS application. This lets you govern agents regardless of which account type the application uses to represent them.
Yes. An application must be linked to an MCP server before an assigned agent can interact with it. Without an MCP server configured, the application cannot provide the agent with functional access to its available tools and services.
No. SSO is optional. It can be used when an Agent Identity is linked to a user account and you want to centralize authentication through JumpCloud. Otherwise, the application can be configured as a simple bookmark.
No. SCIM provisioning is optional and is useful when an Agent Identity is linked to a user account that you want JumpCloud to provision and deprovision automatically. If the Agent Identity is linked to a service account, SCIM can remain disabled.
Not in the initial release. Agent Identities are designed for agents that authenticate and act as themselves. Delegated access, where an agent uses its own identity while acting on behalf of an end user, will be added in a future release.