Keenable is search infrastructure built only for AI agents, and it takes an unusual position on credentials: each agent gets its own account with its own API key, rather than a shared key belonging to whoever set things up. With Sign in with AgentID, the agent can establish that account under its own verified identity, so a key per agent rests on an identity per agent.
In short
- Keenable is a web search and fetch API designed for agents rather than people, over an index in the range of 100 billion documents.
- Its account model is per agent: separate accounts, individual API keys.
- AgentID supplies the verified, stable identity that makes that model workable at fleet scale.
- The agent signs in as itself over OpenID Connect; no human pastes a key into it.
- Keenable keeps control of the index, the API, quotas, and pricing throughout.
What is Keenable?
Keenable is a search and fetch API for AI agents, founded by veterans of large-scale web search and backed by a $26 million seed round led by Accel. Where a human search engine optimizes for a page of links a person will skim, Keenable serves machines: structured results an agent can act on, drawn from an index it puts in the range of 100 billion documents.
Its customers, by design, are agents. The API was never meant for a person to call by hand.
Should every AI agent have its own API key?
Keenable's answer is yes, and the reasoning holds beyond search. A shared key across a fleet of agents means the provider sees one undifferentiated stream of traffic. Nothing can be attributed, one leaked key exposes everything, and revoking it stops every agent at once, including the innocent ones. Quotas, debugging, and abuse response all degrade to guesswork.
Per-agent keys fix that, but they raise the question a key cannot answer for itself: which agent is this key for? Minting keys per agent without identities per agent just moves the bookkeeping problem into a spreadsheet. Someone still has to know which key maps to which agent, keep that mapping current, and vouch for it when it matters.
That is the gap identity fills. If each agent can present a verified identity of its own, the account and its key attach to that identity rather than to a row in someone's tracking sheet.
How does an agent open its own Keenable account?
By signing in as itself. Keenable accepts AgentID, AgentMail's sign-in service for AI agents. It runs on OpenID Connect, the same standard behind Sign in with Google, and it identifies the agent by something the agent actually owns: its AgentMail inbox. The sign-in delivers a verified email address and a stable identifier, and the agent approves it with a single-use cryptographic signature from its own key. No password exists in the flow, and no human generates or pastes anything.
Two properties matter for the per-key model.
The identity is stable. The same inbox presents the same identifier on every sign-in, so an agent returns to its own account and its own key rather than accumulating duplicates.
The identity is distinct. Two agents hold two inboxes, so they are two account holders by construction. A fleet of fifty agents is fifty attributable accounts, not one key photocopied fifty times.
The address is also a working mailbox, so account mail reaches the account holder rather than a person who set up a key once and moved on.
Who controls what
| Stage | AgentID | Keenable |
|---|---|---|
| Identity at sign-in | Supplies verified agent email and stable identifier through OpenID Connect | Accepts the sign-in, creates the agent's account |
| API keys | Not involved | Issues each agent's key, scopes it, revokes it |
| The index and result quality | Not involved | Owns both |
| Quotas and rate limits | Not involved | Sets and enforces them per account |
| Pricing and plans | Not involved | Controls both |
| Account email | Provides the inbox behind the identity | Decides which messages it sends |
What does per-agent identity change operationally?
For a developer running agents on Keenable, the unit of everything becomes the agent. Usage is metered to the agent that generated it. A misbehaving or retired agent's key is revoked without touching the rest of the fleet. Quota questions are answerable per agent instead of argued over a shared pool.
For Keenable, the same identity supports policy. An account established through a verified identity is one it can recognize, limit, and act on, which is a firmer footing than a key whose holder is a mystery.
Start at Keenable. The AgentID sign-in guide covers preparing an agent's inbox identity before its first sign-in.
