4 min readAI Agents · Cybersecurity
How do you score how your AI agents log in?
By Josh Woodruff, Founder & CEO, MassiveScale.AI | Founding Chair, Agentic Trust Framework at the CSAI Foundation

TL;DR: Give each AI agent a login score from 1 to 5. A shared key scores 1. A short-lived token that rotates scores 4. Then prove the score with two tests. Try an expired token and see if it still works. Search for one key used by two agents. Your real score is the lowest one among your high-impact agents.
When an agent reaches for a system, it has to show something at the door. Security people call that authentication. I'll call it logging in.
Most teams can't tell me what their agents show at the door. So they can't tell me how long a stolen one would keep working.
What does a login score measure?
It measures how much damage a stolen login could do. Two things decide that. One is whether the login belongs to one agent or many. The other is how long it stays good.
A shared key that never expires is the worst case. Anyone who copies it can act as every agent that uses it, for as long as they like.
This is a different question from where the key is stored. I score storage in which rung of the credential ladder each AI agent is on.
How does the assessment score this?
Question 2 of the free assessment asks how AI agents authenticate when accessing systems. It's part of Identity Management, the first of the five ATF elements. The five answers make a ready scale.
Score | What the assessment answer says | What a thief gets |
|---|---|---|
1 | Agents share credentials or API keys across the organization. | Every agent's access, with no end date. |
2 | Agents have their own credentials, but those never expire or rotate. | One agent's access, with no end date. |
3 | Agents use tokens that expire on a timer, such as one hour. | One agent's access for up to an hour. |
4 | Agents use modern sign-in (OAuth2 or OIDC) with short-lived, rotating tokens. | One agent's access for minutes. |
5 | Agents use hardware-bound credentials or mutual TLS for high-security work. | Very little. The login is tied to the machine it lives on. |
Mutual TLS means both sides prove their identity before they talk.
How do you prove the score?
A score you haven't tested is a guess. Run two tests.
The expiry test.
Have an agent get a fresh token in a test setting.
Copy the token and note the time.
Wait until its stated life has passed.
Try the copied token.
It should fail. If it still works, your real score is 2, whatever the design document says.
The shared key test.
List the keys your agents use. Your secrets manager can export them.
Look for any key that shows up under more than one agent.
Count them.
Write down which agents share each one.
The pass bar is zero shared keys. One shared key puts every agent that uses it at a score of 1.
How common are low scores?
Common. In Gravitee's State of AI Agent Security 2026 report, 45.6% of teams said they still rely on shared API keys between agents.
So a score of 1 doesn't make you unusual. It makes you a target with a lot of company.
What do you do with the scores?
Sort your agents by what they can reach. The ones that touch money or customer data go first.
Then set a floor. Mine is simple. No agent scores 1. High-impact agents score 4 or better.
Move one agent at a time. Give it its own login first, since nothing else works without that. Then shorten how long its token lives. Once it has its own login, check that the login doesn't open more than the job needs, using the test for whether an AI agent has more access than its job needs.
Frequently asked questions
Is a one-hour token good enough?
It's a fair middle. An hour is a long time for an agent, though. Aim for minutes on anything that touches money or customer data.
Do all agents need a score of 5?
No. Level 5 is for high-security work. Most agents are well served at 4.
What if a tool only accepts an API key?
Then the key stays, and you limit who holds it. Put it behind a gateway so the agent never sees it.
How often should I rescore?
Every quarter, and whenever an agent gets a new tool. Each new tool is a new door.
Key takeaways
A login score measures what a thief gets and for how long.
The scale runs from 1, a shared key, to 5, a hardware-bound credential.
Prove it with an expiry test and a shared key test.
Your real score is the lowest one among your high-impact agents.
Question 2 is one of 30 in the free assessment. It takes about ten minutes and scores you on all five ATF elements.
Every agent shows something at the door. Find out what, and how long it stays good.