IdentityWorkOS

WorkOS Airlock

Intent-bound token and policy gate between an agent and WorkOS Pipes provider credentials

WorkOS Airlock sits between the agent and provider connections (Pipes): the agent receives an intent-bound token, and provider OAuth credentials stay behind the gateway. Airlock checks the proposed action and content against policy before the call proceeds (allow, deny, or human-approval). Declared intent does not grant a policy exception. WorkOS lists Airlock as early access, with no public pricing yet. Unstealable credentials are not enough if action and content are unconstrained. See https://workos.com/blog/workos-airlock and https://workos.com/blog/mcp-authorization-failures.

Use Cases

  • Issue the agent an intent-bound token instead of the live provider OAuth credential
  • Check proposed action and content against policy before a Pipes call proceeds
  • Allow a routine planning email, deny a financial-data leak, or pause a new distribution list for human approval
  • Keep provider account permissions as the outer bound and add agent-use restrictions on top
  • Keep direct provider credentials out of the agent environment so the gateway cannot be bypassed

Key Features

Intent-bound token

The agent receives an intent-bound token. Provider OAuth credentials stay behind the Airlock gateway on Pipes connections.

Action-and-content policy

Airlock checks the proposed action and content against policy before the call proceeds. Outcomes: allow, deny, or human-approval. Declared intent does not grant a policy exception.

Demo outcomes (WorkOS)

Routine planning email allowed. Email containing LLM token-spend figures blocked under a financial-data policy. New distribution list paused for IT admin Slack approval. These are WorkOS illustrations, not Institute scores.

Account permissions still bind

Provider account permissions still bound the account. Airlock adds restrictions on the agent's use of that connection. Direct provider credentials in the agent environment are the bypass risk.

Early access

Announced 23 Sep 2026. WorkOS lists Airlock as early access, with no public pricing yet. A same-day post covers four MCP authorization failure shapes vs the 2026-07-28 MCP auth spec and mentions LiteLLM CVE-2026-59822 / CISA KEV.

Integrations

WorkOS PipesOAuthSlack (approval demo)