WorkOS walks Datadog's CoPhish finding through to a product-design lesson: an agent-building platform can itself become an OAuth phishing vector. A consent screen on a trusted first-party domain is not proof the product built the auth path.

What WorkOS Published

On September 29, 2026, WorkOS published CoPhish and the Agentic Consent Problem. The source incident is Datadog Security Labs' October 2025 CoPhish disclosure against Microsoft Copilot Studio.

Copilot Studio can host a demo agent under copilotstudio.microsoft.com. Datadog found that an agent's sign-in configuration can be pointed at an arbitrary redirect, including a malicious OAuth consent request. After the victim consents, the agent's workflow can forward the token to an attacker-controlled server via an outbound HTTP call from Microsoft's infrastructure — so the exfiltration does not appear in the victim's browser traffic.

The Shape, Not The Brand

WorkOS strips the Copilot Studio branding down to three properties:

  1. A platform lets users build and host something under the platform's own trusted domain.
  2. That something can start an OAuth consent flow with a configurable, attacker-controlled destination or app registration.
  3. That something can then take an automated action after consent with no further user visibility.

Those properties describe agent builders, GPT-store-style directories, MCP server marketplaces, and low-code "connect your tools" flows — not only one Microsoft product.

First-Class Agent Identity

WorkOS argues agents need to be first-class, governable identities rather than service accounts with a login button bolted on. The post cites two industry moves:

  • Entra Agent ID became mandatory for every new Copilot Studio agent in July 2026.
  • WorkOS Agent Auth entered early access in AuthKit in September 2026: short-lived scoped tokens, blueprints, and revoke.

Neither, WorkOS says, prevents someone from building a CoPhish-shaped consent trap inside a no-code builder. Both shrink the blast radius if it happens: a distinct auditable actor holding a short-lived, narrowly scoped token instead of a long-lived Graph token nobody is tracking.

What Operators Should Change

The operator control plane is a distinct agent identity, scoped short-lived credentials, and audit as a distinct actor — not borrowing the user's session. On a builder surface: restrict login redirects to an allowlist, treat post-consent HTTP actions as a privileged capability, bind tokens to their audience, and correlate agent-creation events with consent grants.

What The Post Does Not Prove

  • CoPhish is Datadog's finding. Microsoft acknowledged the report and described the technique as social engineering rather than a software vulnerability.
  • Agent Auth early access and Entra Agent ID mandates are vendor and platform facts from the WorkOS post, not an Institute product recommendation.
  • This is a consent-path note. It is not a rewrite of four agent-credential architectures or Airlock intent gates.

Related: See our notes on WorkOS comparing agent-credential architectures and WorkOS Airlock.