DocsAgentID and WorkOS
AgentID and WorkOS
AgentID can’t be added to WorkOS AuthKit yet. It needs WorkOS to support AgentID as a sign-in provider, and no setting on your side gets around that. Leave your email and we’ll tell you when it works.
All docs
On this page
Where it stands#
There is no supported way to put a Continue with AgentID button on an AuthKit login page today. This isn’t a missing step in a guide: WorkOS doesn’t let apps add their own sign-in providers, so AgentID has to become one of WorkOS’s built-in options first.
Why it doesn’t work#
Every other guide adds AgentID the same way you’d add Google: as a social or OAuth provider that anyone can pick. WorkOS has no slot for that.
- 01
Social sign-in is a fixed list.
AuthKit’s social providers are the ones WorkOS builds in: Google, Microsoft, GitHub, Apple, GitLab, LinkedIn, Slack and Xero. There is no custom or generic OAuth provider, which is how Supabase and Better Auth add AgentID. Clerk and Auth0 went the other way and ship AgentID as a built-in connection; WorkOS hasn’t yet, and only WorkOS can add to its list.
- 02
Custom OIDC means enterprise SSO.
WorkOS does accept any OpenID Connect provider, as a Generic OIDC SSO connection. But an SSO connection belongs to one organization in your app, and WorkOS sends a user to it based on their email domain. That makes AgentID one customer’s login, not a sign-in option for everyone.
- 03
Agents don’t share a company domain.
Most agents sign in with an @agentmail.to inbox. Routing by domain would send every one of them to the same organization, whoever owns them, when each agent is meant to be its own account. SSO connections are also billed per connection, which doesn’t fit a sign-in method open to anyone.
In the meantime#
AgentID is a standard OpenID Connect provider, so you can run its sign-in outside WorkOS with any OIDC library and create the session in your own app. Add AgentID to any OIDC stack has the values and the settings to watch for. Linking those agents to your WorkOS users, if you need to, is up to your app.
Or, if you’re choosing an auth provider now, Clerk, Supabase, Auth0, Better Auth and Auth.js each have a step-by-step guide.
Not the same as auth.md#
WorkOS also wrote auth.md, a file an app hosts to tell agents how to register on behalf of a user. It’s a separate protocol that doesn’t need a WorkOS account, and it doesn’t add AgentID sign-in to AuthKit. How the two differ: AgentID vs WorkOS auth.md.
Get notified#
We’ll send one email when AgentID works with WorkOS, with a link to the guide.