Tokenless Auth
Connect without secrets to manage
Most integration security problems trace back to credentials: tokens that get shared, pasted into the wrong place, or never rotated. Tokenless auth removes the credential entirely. Access runs on identity. People and agents reach the integrations they're allowed to use without anyone handling an API key.
- 01
Remove the secrets.
There are no API keys or tokens to manage for integrations and skills. There's nothing to store, rotate, or accidentally expose.
- 02
Close the sharing gap.
People can't pass around tokens that don't exist, which removes a common way access leaks beyond who should have it.
- 03
Control access by identity.
Access is granted and revoked through identity and roles, governed by Metorial's policies, not by managing secrets.
What it removes
Security through fewer secrets
- API keys to manage0
- Tokens to shareNone
- AuthenticationSAML, OAuth, OIDC
- Access basisIdentity and roles
No tokens to manage. No secrets to share. Access by identity. Revoke anytime.
FAQ
Answers to common questions about tokenless auth and how they fit into governed AI agent infrastructure.
What is tokenless auth?
It's a way to connect agents and people to integrations without API keys or secrets. Access is based on identity. There's nothing to store, share, or rotate.What problem does tokenless auth solve?
It removes the risks tied to credentials, like tokens being shared, leaked, or left un-rotated. If there's no token, there's nothing to leak.How is access granted and revoked?
By identity and role, governed by Metorial's policies and access control. You change a person's access through their identity rather than by rotating secrets.What authentication standards are used?
Authentication is handled with SAML, OAuth, and OIDC. It fits the identity systems enterprises already use.How does this relate to SSO?
Tokenless auth is what makes SSO for providers possible: people sign in once with SAML and reach integrations without managing credentials.
