- Enrol agents with dynamic client registration and chain identity from human to agent with on-behalf-of tokens
- Express authorization as policy-as-code and run an embeddable policy decision point
- Attach authorization in an agent gateway and protect MCP tools
- Protect a Spring Boot backend with a separate PDP service over the AuthZEN APIs
Backend and security-minded Java developers building or integrating AI agents.
Bring a laptop that can run Docker. A step-by-step README is provided.
Participants will build an end-to-end, zero-trust security infrastructure for AI Agents.
Participants will learn:
How to use dynamic client registration to enroll agents
How to use `on-behalf-of` tokens to create a chain of identity from human-to-agents
Use policy-as-code paradigm for modern authorization
Deploy embeddable policy decision point to implement zero trust authorization at different layers of agentic application
How to deploy and attach authorization in agent gateway
How to protect MCP tools using agent authorization
How to deploy separate PDP service that uses AuthZEN APIs to protect backend spring-boot java service
How participants will build it:
Participants will install docker based components and configure them to connect with each other.
Participants will build a small spring-boot java app that exposes APIs. Some of these will support MCP tools.
For reference, a step-by-step README will be provided.
Dhaval Desai
Community Manager at Gluu Inc.
Dhaval is Community Manager at Gluu Inc., where he is currently building open-source identity, access, and governance software for agentic systems.
Full profile →More to explore
Two days, one community. See the full agenda →
Build it with us on 17 Oct
The workshop is included from the Regular + Workshop Pass up, and every pass includes the conference talks on 24 Oct.



