[ The familiar sign-in, built for agents ]

Your agent can sign in. You stay informed.

Choose Agent ID the way you’d choose “Sign in with Google.” The app shows exactly what it needs, your agent confirms with its own key, and you’re in — without creating a password or handing over an API key.

  • No new password
  • See what is shared
  • A key your agent controls

Get notified when Agent ID is available.

mytool.dev/login

Welcome back

Sign in with Agent ID
[ How it works ]

A sign-in you already know how to use.

It feels like Google or Microsoft sign-in. The difference is that your agent confirms the request with its own identity.

01

Choose Agent ID

Pick “Sign in with Agent ID” on a supported app. There is no registration form and no password to create.

02

Review the request

Agent ID names the app and shows the identity details it is asking for, before the sign-in continues.

03

Your agent confirms

Your agent signs this one request with its private key. Agent ID verifies it, then returns you to the app signed in.

Under the hood, Agent ID uses OpenID Connect — the same open sign-in standard used by Google, Microsoft, and many workplace accounts.

[ What's shared ]

You see what the app is asking for.

Every request names the app and lists the identity details it will receive. A standard sign-in shares two useful facts — not access to your accounts.

A standard sign-in can share

  • Agent inboxThe agent’s verified email address and sign-in identity.
  • Owner emailThe address of the person or team responsible for the agent.

Signing in does not share

  • A passwordAgent ID does not create or send one.
  • Email contentsAn address is identity, not permission to read or send mail.
  • Your AgentMail API keyThe app never receives a reusable AgentMail credential.
[ Your control ]

Secure by design, simple in practice.

No password or API key is handed to the app. Each sign-in is a fresh, scoped proof from the agent that owns the identity.

The private key stays put

Your agent confirms with a scoped signing key. The private half stays in its keystore and never crosses the login flow.

One request, one confirmation

The confirmation is tied to one short-lived sign-in request. It cannot be saved and reused as a password.

Checked live every time

Before completing sign-in, Agent ID checks that the inbox is live and inside the signing credential’s allowed scope.

Stop future sign-ins

Revoke the agent’s signing credential to prevent it from confirming another Agent ID request.

[ FAQ ]

Frequently asked questions