Skip to content

Akeyless Integrates With Claude’s Compliance API to Secure AI Agent Access

AI agents across Claude Chat, Cowork, and Claude Code, are increasingly being given direct access to production databases, cloud services, and SaaS APIs, often using long-lived credentials stored in MCP configuration files. These credentials create an immediate exposure risk. But standing credentials are only part of the problem: even properly authenticated agents can take unintended or destructive actions, because user intent doesn’t always match LLM behavior. Traditional authentication and access controls  decide who can connect, but cannot govern what autonomous AI agents do during a session.

Today, we’re announcing Akeyless Agentic Runtime Authority for Claude Enterprise to address both of these risks. Built on Claude’s Compliance API, the integration helps organizations govern how AI agents access enterprise systems by brokering just-in-time, least-privilege access through a customer-deployed Akeyless Gateway. It ensures credentials remain outside the model context and enforces intent-aware policy at the moment of action, with full forensic traceability.

The Risks of Standing Agent Access

When someone connects Claude to a database or SaaS system through a typical MCP server, the fastest path is also the riskiest: paste the API key, password, or token directly into the MCP configuration. For example, a Claude Code project might store a credential in mcp-servers.json. The credential then becomes available within the agent’s operating environment, where it may be exposed through files, logs, processes, or compromised tooling..

 An agent operating with a perfectly valid, legitimately-issued credential can also behave in an unintended way. Acting on a prompt injection, ambiguous instructions, or incorrect reasoning, it can run a destructive command, like a DROP TABLE. The target system may accept the command because the credential itself checks out, even though the action exceeds the user’s intended task.

Independent research backs up the concern: more than two-thirds of organizations suspect their AI agents have already accessed data beyond their intended scope. 

What Akeyless Agentic Runtime Authority Does

Agentic Runtime Authority is purpose-built to govern AI agents as they act. The flow across Claude Enterprise, whether that’s Chat, Cowork, or Claude Code, looks like this:

  1.  A user prompts Claude for data or an action against a target system.
  2. The request is brokered through the Akeyless Gateway, which is deployed and managed within the customer’s environment. The gateway evaluates the request before connecting to the target system, allowing organizations to retain full control over network boundaries, credentials, and enforcement logic.
  3. If the request satisfies policy, the Gateway injects a just-in-time credential scoped to that single action, brokers the connection, and records the activity for auditing..
  4. The Gateway evaluates the target system’s response against policy before it’s returned to Claude and the user.
  5. The credential expires the moment the action completes. It is never exposed in prompts, configuration files, or the model context.

Organizations configure a single akeyless-connector through MCP to broker access to supported databases, cloud providers, and SaaS platforms. This reduces the need for multiple per-system MCP servers  while centralizing credential management, policy enforcement, and auditing.

Akeyless Agentic Runtime Authority Walkthrough and Demo

Claude / Agent ReceivesAkeyless Controls
The requested action’s result, only after policy inspectionIntent-aware policy evaluation of every request
No credential value, everJust-in-time credential issuance, scoped to a single action
Nothing once the action completes; the credential is already goneCredential destruction immediately after use
Full audit trail tied back to the originating prompt

Why This Matters: Three Outcomes for Security Teams

•     Zero standing credentials. There is nothing sitting in a config file, an environment variable, or an agent’s memory for an attacker, or a compromised agent, to exfiltrate. If there’s no secret to steal, credential theft stops being the attack path.

•     Intent-aware, real-time enforcement. Agentic Runtime Authority evaluates each requested action against least-privilege policy before access is brokered, and keeps evaluating the session as it runs, across SSH, databases, Kubernetes, and cloud APIs. An agent can’t drift past what it was actually authorized to do, even mid-session.

•     Full forensic traceability. Every action is logged and tied back to the originating prompt, giving security and platform the context needed for auditing, investigations, and operational oversight.

How This Is Different From Access-Control-Only Approaches

Traditional access controls such as OAuth brokers, RBAC layers, standard MCP servers make a trust decision at the start of a session. Agentic Runtime Authority continues applying organizational policies as AI agents interact with production resources, providing governance throughout the lifecycle of a brokered session.

Agentic Runtime Authority runs on Akeyless’s Distributed Fragments Cryptography™ (DFC), a zero-knowledge architecture where encryption-key fragments never leave the customer’s environment. Combined with the customer-deployed Gateway, security teams gain centralized policy enforcement and visibility, without needing to replace their existing vaults, IAM platforms, or legacy systems.

Getting Started

Akeyless Agentic Runtime Authority is available today. If you’re evaluating how to give AI agents production access without expanding your secret sprawl, here’s where to go next:

•     Follow the setup guide

•     Watch the step-by-step setup video

•     Watch the solution walkthrough

•     Request a demo

FAQs

What Is the Akeyless Integration With Claude’s Compliance API?

The Akeyless integration with Claude’s Compliance API helps organizations monitor and govern AI agent activity in Claude Enterprise. Combined with Agentic Runtime Authority, it provides runtime access brokering, policy enforcement, and audit records for actions performed through the Akeyless Gateway.

How Does Akeyless Secure AI Agent Access in Claude Enterprise?

Agentic Runtime Authority brokers access to enterprise systems through the customer-deployed Akeyless Gateway rather than exposing credentials directly to AI agents. It issues just-in-time credentials for approved requests, evaluates each brokered action against organizational policy, and records the activity for auditing and investigation.

Does Akeyless Store or Expose the Credentials Used by AI Agents?

No. Agentic Runtime Authority keeps credential values outside the AI agent. Credentials are issued just in time through the Akeyless Gateway for approved actions and are never exposed to Claude, stored in MCP configuration files, or retained after the brokered action is complete.

How Is Agentic Runtime Authority Different From OAuth or RBAC?

OAuth and RBAC determine whether an identity is authorized to access a system. Agentic Runtime Authority builds on those controls by brokering runtime access, evaluating each requested action against organizational policy, and enforcing those policies throughout the brokered session.

Do I Need to Replace My Existing Vault or Identity Provider?

No. Agentic Runtime Authority is designed to work alongside existing vaults, IAM platforms, and authentication providers. Organizations can add runtime access brokering and policy enforcement without replacing their current identity or secrets management infrastructure.RTA integrates at the MCP layer and is designed to work across Claude Enterprise surfaces, including Chat, Cowork, and Claude Code.

What Systems Can AI Agents Access Through Agentic Runtime Authority?

Agentic Runtime Authority brokers governed access to a wide range of enterprise systems, including databases, Kubernetes, SSH, cloud provider APIs, and SaaS applications. Organizations configure a single akeyless-connector through MCP to securely broker access without embedding long-lived credentials in individual MCP servers

Which Claude Enterprise Products Does the Integration Support?

The integration is designed for Claude Enterprise and supports Claude Chat, Cowork, and Claude Code through Claude’s Compliance API. It applies to Anthropic-hosted Claude Enterprise deployments and provides visibility into supported activity while Agentic Runtime Authority brokers and governs access to enterprise systems.

Never Miss an Update

 

The latest news and insights about Secrets Management,
Akeyless, and the community we serve.

 

Ready to get started?

Discover how Akeyless simplifies secrets management, reduces sprawl, minimizes risk, and saves time.

Get a Demo