Add AgentID as a social connection
Before you start
Enabling OAuth with AgentID allows your users to sign up and sign in to your Clerk app with their AgentID account.
Configure for your development instance
For development instances, Clerk uses preconfigured shared OAuth credentials and redirect URIs—no other configuration is needed.
- In the Clerk Dashboard, navigate to the SSO connections page.
- Select Add connection and select For all users.
- Select AgentID from the provider list.
Configure for your production instance
For production instances, you must provide custom credentials.
Keep two browser tabs open during setup: one for the Clerk Dashboard and one for your AgentID console.
Enable AgentID as a social connection in Clerk
- In the Clerk Dashboard, navigate to the SSO connections page.
- Select Add connection and select For all users.
- Select AgentID from the provider list.
- Ensure that both Enable for sign-up and sign-in and Use custom credentials are toggled on.
- Save the Redirect URI somewhere secure. Keep this page open.
Create an AgentID application
- In the AgentID console, select Create application.
- Complete the form as follows:
- In the Auth provider dropdown, select Clerk.
- Under App name, enter the name of your app.
- Under Redirect URIs, paste the Redirect URI value you saved from the Clerk Dashboard.
- In the Token endpoint auth method dropdown, select
client_secret_basic.
- Select Create application. You'll be redirected to your application's page.
- Save the Client ID and Client secret values somewhere secure. The client secret is shown only once. If you lose it, select Settings on the application's page and select Regenerate secret to issue a new one.
Set the Client ID and Client Secret in the Clerk Dashboard
- Navigate back to the Clerk Dashboard where the configuration page should still be open. Paste the Client ID and Client Secret values that you saved into the respective fields.
- Select Save.
Request the owner's identity
Clerk requests the openid, email, and profile scopes from AgentID by default. To also receive the identity of the human who owns the agent:
- In the Clerk Dashboard, the configuration page should still be open.
- Select your AgentID connection.
- Under Scopes, add the
owner_profileandowner_emailscopes. The agent's signing credential must permit those claims. - Select Save.
Test your connection
The simplest way to test your connection is to visit your Clerk app's Account Portal, which is available for all Clerk apps out-of-the-box.
- In the Clerk Dashboard, navigate to the Account Portal page.
- Next to Sign-in, select the button to visit the sign-in page. The URL should resemble:
- For development -
https://your-domain.accounts.dev/sign-in - For production -
https://accounts.your-domain.com/sign-in
- For development -
- Sign in with your connection's credentials.
Once you confirm the connection, get the user's OAuth access token from your backend using the getUserOauthAccessToken() method to retrieve their data from the social provider.
Feedback
Last updated on