Startup Keycard, which develops AI agent identity and access management technology, has acquired the specialized security certificate management startup Anchor.dev. Through this acquisition, Keycard gains an experienced senior development team with expertise in certificate automation and security infrastructure. The team has a track record of supporting major enterprise infrastructures such as Cloudflare, GitHub, and Salesforce’s Heroku.
Keycard has been dedicated to solving the challenge that, in environments where AI agents autonomously run code and control operating systems, developers must manually delegate permissions. Currently, many teams require manual approval or restrict agent activities for security reasons, which largely offsets the advantages of autonomous agent development.
Recently, with the widespread use of AI coding agents like Cursor, Claude Code, Codex, and Windsurf in business operations, scenarios where these software access real-time operating systems have increased. However, during this process, when they access source code management systems, issue trackers, internal services, and other elements, security and compliance risks are heightened.
To address these issues, Keycard has introduced an alternative architecture that provides “short-lived work unit credentials.” This design aims to be tool-agnostic, applying the same policies and audits even for self-generated tools or integrated commands by agents. Developers can automate path setup without manual intervention for all tasks, while still requiring explicit manual approval for critical tasks.
With this acquisition, Keycard is expected to expand into a unified identity platform, enabling protocol-agnostic access control across model context protocols (MCP), command-line tools, and various tools generated by AI agents. All API calls, CLI commands, and tool-generated events will be logged in agent-based audit logs, which are anticipated to be a key method for enhancing security and traceability.
Wesley Beary, co-founder of Anchor.dev, stated, “We have always focused on automating and simplifying complex certificate workflows. We will now actively apply this expertise within Keycard to build AI agent security.”
Through this acquisition, Keycard solidifies its position as a core platform providing practical security controls in the era of AI development that prioritizes autonomy. Its technical capabilities to balance flexible agent behavior with stable developer control are also seen as potentially becoming the standard for future AI development tools.