{"schema_version":"newruntime-agent-readable-v0.2","type":"post","stable_id":"post:vercel-passport-agent-identity-boundary","slug":"vercel-passport-agent-identity-boundary","title":"Vercel Passport Makes Identity a Deployment Boundary","description":"Vercel Passport is now generally available, adding verified identity tokens, group claims, audit events, and automation bypasses to protected deployments.","retrieval_nugget":"Vercel Passport is now generally available, adding verified identity tokens, group claims, audit events, and automation bypasses to protected deployments. Vercel Passport is now generally available for Enterprise customers. It protects deployments with an organization's identity provider, then forwards a signed identity token to the deployment so application code can reason about the authenticated visitor. The mechanics are important.","status":"published","published_at":"2026-07-31","updated_at":"2026-07-31","record_date":"2026-07-31","date_kind":"published_at","topics":["security","infrastructure","api-design","enterprise-ai"],"source_urls":["https://x.com/vercel/status/2083193506940829949","https://vercel.com/changelog/vercel-passport-generally-available"],"visuals":[{"id":"vercel-passport-agent-identity-boundary-nano-banana","kind":"editorial-diagram","role":"hero","src":"https://newruntime.com/images/posts/vercel-passport-agent-identity-boundary-nano-banana.webp","alt":"Hand-drawn deployment boundary diagram where an identity provider signs a visitor token before a protected Vercel deployment forwards verified identity to app code and downstream services.","caption":"Passport moves identity verification in front of the deployment and forwards a signed token that app code can use.","credit":"New Runtime synthesis from public source inspection","source_url":"https://vercel.com/changelog/vercel-passport-generally-available","generated_with":"nano-banana-style-imagegen","width":1600,"height":900,"legend":[{"label":"Verified token","description":"Vercel strips client-supplied identity headers and injects a verified Passport token."},{"label":"Groups","description":"Provider claims such as group membership can be carried into application authorization."},{"label":"Automation","description":"Bypass secrets and trusted OIDC sources keep webhooks, CI, and cron jobs working."}]}],"routes":{"html":"https://newruntime.com/posts/vercel-passport-agent-identity-boundary/","markdown":"https://newruntime.com/posts/vercel-passport-agent-identity-boundary.md","json":"https://newruntime.com/posts/vercel-passport-agent-identity-boundary.json"},"source_format":"markdown","next_reads":[{"type":"topic","path":"/topics/api-design/","reason":"Explore the api design topic hub.","url":"https://newruntime.com/topics/api-design/","title":"API Design - New Runtime","media_type":"text/html"},{"type":"topic","path":"/topics/enterprise-ai/","reason":"Explore the enterprise ai topic hub.","url":"https://newruntime.com/topics/enterprise-ai/","title":"Enterprise AI - New Runtime","media_type":"text/html"},{"type":"related_material","path":"/posts/langsmith-llm-gateway-runtime-controls/","reason":"Shares api design and infrastructure.","url":"https://newruntime.com/posts/langsmith-llm-gateway-runtime-controls/","title":"LangSmith LLM Gateway Puts Runtime Controls Between Agents and Models","media_type":"text/html"},{"type":"related_material","path":"/posts/vercel-sandbox-multi-user-agents/","reason":"Shares infrastructure and security.","url":"https://newruntime.com/posts/vercel-sandbox-multi-user-agents/","title":"Vercel Sandbox Adds Unix Boundaries for Multi-Agent Work","media_type":"text/html"},{"type":"related_material","path":"/posts/llm-inference-backpressure-before-autoscaling/","reason":"Shares api design and infrastructure.","url":"https://newruntime.com/posts/llm-inference-backpressure-before-autoscaling/","title":"LLM Inference Fails Quietly Before It Fails Loudly","media_type":"text/html"}]}
