I'm building AuthForge - authentication infrastructure for AI agents. Early preview at https://auth-forge-web-two.vercel.app
: When AI agents need to access your tools (Slack, GitHub, Jira), how do you handle auth? Current options are expensive proprietary platforms or DIY OAuth with security risks.
: - Zitadel for identity/SSO - Ory Hydra for OAuth 2.1 (MCP-specific flows) - Cerbos for policy engine (time/context-based rules) - HashiCorp Vault for token management - All Apache 2.0 licensed
:
Is this overengineered? Should I start with just basic OAuth + agent registry and add complexity later? Or is the enterprise stack necessary from day 1?Background: 15+ years building infrastructure. Currently building AI agents and hitting auth pain points that existing solutions don't address.
: https://github.com/ashishjsharda/authforge First docker-compose stack: ~2 weeks
Looking for honest technical feedback. Thanks!