Skip to content
← All termsGlossary

Confused deputy problem

The confused deputy problem happens when a trusted system uses its own broad access to act for a caller with less access. With AI agents, a gateway often calls tools with its own login instead of the agent's. The tool can't tell which agent asked. The agent gets more reach than it should, and the logs name the wrong caller.

Also called: confused deputy, confused deputy attack, confused deputy vulnerability, confused deputy issue, confused deputy risk

Updated

The term is decades old. It describes any program that holds strong permissions and uses them for a caller with weaker ones. The program isn't malicious. It just can't check whether the request should be allowed for the one really asking.

Why AI agents make it worse

Most AI gateways were built the way API gateways always were. One shared service account and one wide credential serve every request. An agent can call dozens of tools a minute. Each call needs its own answer to one question: who is actually asking right now.

Where teams get it wrong

They put OAuth at the front door and stop there. That proves the agent logged in. It says nothing about which credential the gateway uses for the call it makes next. The confused deputy problem lives at that second hop.

How teams fix it

The usual fix is token exchange. The IETF standard for it is RFC 8693, published in January 2020. For every downstream call, the gateway trades the agent's token for a new one. The new token does four things:

  • It names the real agent as the caller.

  • It works only for the one tool being called.

  • It allows only what that single call needs.

  • It expires in minutes.

Microsoft's version is called On-Behalf-Of. The format is different. The idea is the same.

A concrete example

A user's AI assistant asks an MCP server for one customer record. The MCP server calls the CRM with a shared API key that can read every record. The agent asked a narrow question. The system answered with a broad key, and the CRM log shows the MCP server instead of the assistant. With token exchange, the CRM gets a token for that one read, naming that one agent.

Let's figure out what you actually need.

No pitch. No pressure. Every conversation starts with a senior practitioner, not a sales team. We'll tell you straight where you stand and whether we're the right fit. If we're not, we'll point you to who is.