---
title: "Agents can read your own workspace record after sign-in: Trooth changelog - Trooth"
description: "The signed-in part of the public Model Context Protocol (MCP) server and the A2A agent is live: an agent with an OAuth access token from Trooth's sign-in provider can read your own workspace's company record and keep A2A tasks for 24 hours. No scope is required."
canonical_url: "https://trooth.co/changelog/2026-10-05-signed-in-agent-access"
markdown_url: "https://trooth.co/changelog/2026-10-05-signed-in-agent-access.md"
generated_from: "the rendered page, converted to Markdown when this was requested"
agent_index: "https://trooth.co/llms.txt"
---

[Back to changelog](https://trooth.co/changelog)

New

October 5, 20261 minute read

# Agents can read your own workspace record after sign-in

The signed-in part of the public Model Context Protocol (MCP) server and the A2A agent is live: an agent with an OAuth access token from Trooth's sign-in provider can read your own workspace's company record and keep A2A tasks for 24 hours. No scope is required.

## What changed

Both protected-resource metadata documents now answer and name Trooth's WorkOS AuthKit authorization server. A client registers itself there, through dynamic client registration or a client ID metadata document, and requests a token with the MCP server or the A2A agent as the resource. No scope is required: AuthKit does not grant custom scopes to a client that registers itself, so none is asked for. Every token is still checked for its issuer, its audience, its signature, its expiry, its client and its subject. trooth_my_company_record reads only the workspace linked to the token's subject, a link made when that person signs in to trooth.co with Continue with enterprise SSO; until then it answers not_linked. The A2A agent keeps a task for a token holder for 24 hours, readable only by that subject and client.

## Why it changed

Until October 5, 2026 no authorization server was configured, so these parts answered that sign-in was not configured. Trooth sign-in now runs on WorkOS AuthKit in production, which is also an OAuth authorization server for agents.

## Who is affected

- **Affected:** Developers and agents calling the MCP server at api.trooth.co/public/mcp or the A2A agent at api.trooth.co/a2a/v1. The public tools and the A2A skills are unchanged and still need no token.
- **Availability:** Public, at api.trooth.co. Reading your own record needs a workspace member who has signed in to trooth.co with enterprise single sign-on (SSO), using Continue with enterprise SSO.
- **Release stage:** Available.
- **Areas:** API, Company workspace.

## What to do

**No action required.** Nothing is required. To use the signed-in tool, let your client register itself with the authorization server the protected-resource metadata names, and sign in to trooth.co once with Continue with enterprise SSO to link your workspace.

## Dates

- **Announced:** October 5, 2026, the day this entry was written. Entries are never backdated.
- **Released:** October 5, 2026.

## Read more

- [Agents and MCP](https://trooth.co/docs/agents)

On this page

- What changed
- Why it changed
- Who is affected
- What to do
- Dates
- Read more

[New](https://trooth.co/changelog?type=new)[API](https://trooth.co/changelog?area=api)[Company workspace](https://trooth.co/changelog?area=workspace)

[Back to changelog](https://trooth.co/changelog)

## Related changes

- [OCT.04NewYour own AI agent can publish your Trust ProfileTrust Profiles +1](https://trooth.co/changelog/2026-10-04-your-agent-can-publish)
- [OCT.03ImprovementA reading limit that holds, token discovery for agents, and connected tracesAPI +3](https://trooth.co/changelog/2026-10-03-requirements-batch-17-50)
- [SEP.29ImprovementSearch that finds products, standard errors, and a keyboard that reaches everythingNetwork +5](https://trooth.co/changelog/2026-09-29-requirements-batch-17-49)
- [SEP.28ImprovementPlainer states, fairer comparisons, and a record you can pageTrust Profiles +5](https://trooth.co/changelog/2026-09-28-requirements-batch-17-48)
- [SEP.28SecurityRecovery codes, confirmed alerts, and a key policy the verifier followsCompany workspace +2](https://trooth.co/changelog/2026-09-28-recovery-codes-and-confirmed-alerts)
- [SEP.28FixCorrections from the September 28 audit: contract 1, one interface catalog, a complete bill of materialsAPI +5](https://trooth.co/changelog/2026-09-28-fresh-audit-corrections)

## Follow what changes at Trooth

Every entry by email, or a feed narrowed to one area or to the changes that need you to act.

## Product updates by email

Occasional notes when something on this page changes. You get one confirmation email when you subscribe, every email carries an unsubscribe link, and the address is never sold or shared.

Email address

[RSS](https://trooth.co/changelog/rss.xml)[API only](https://trooth.co/changelog/rss.xml?area=api)[Needs action](https://trooth.co/changelog/rss.xml?action=required)

## Structured data

```json
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "Organization",
      "@id": "https://trooth.co/#org",
      "name": "Trooth",
      "legalName": "Trooth, LLC",
      "alternateName": [
        "Trooth, LLC",
        "Trooth Network",
        "trooth.co"
      ],
      "url": "https://trooth.co",
      "logo": {
        "@type": "ImageObject",
        "@id": "https://trooth.co/#logo",
        "url": "https://trooth.co/brand/trooth-mark_black-on-white_1024.png",
        "contentUrl": "https://trooth.co/brand/trooth-mark_black-on-white_1024.png",
        "width": 1024,
        "height": 1024,
        "caption": "Trooth"
      },
      "image": {
        "@id": "https://trooth.co/#logo"
      },
      "description": "Trooth is an infrastructure and cybersecurity company providing Machine-Readable Trust. The Trooth Network keeps one current Machine-Readable Trust Profile per company, each fact sourced. Trooth signs what it witnessed; company declarations are unsigned.",
      "foundingDate": "2025-12-16",
      "address": {
        "@type": "PostalAddress",
        "streetAddress": "777 Brickell Ave, Suite 500, PMB 1174",
        "addressLocality": "Miami",
        "addressRegion": "FL",
        "postalCode": "33131",
        "addressCountry": "US"
      },
      "contactPoint": {
        "@type": "ContactPoint",
        "contactType": "customer support",
        "email": "hello@trooth.co",
        "url": "https://trooth.co/contact"
      },
      "sameAs": [
        "https://x.com/Troothllc",
        "https://github.com/troothllc",
        "https://www.crunchbase.com/organization/trooth",
        "https://www.wikidata.org/wiki/Q141292994",
        "https://www.youtube.com/@Troothllc",
        "https://www.trustpilot.com/review/trooth.co"
      ]
    },
    {
      "@type": "WebSite",
      "@id": "https://trooth.co/#website",
      "url": "https://trooth.co",
      "name": "Trooth",
      "alternateName": "Trooth Network",
      "inLanguage": "en",
      "publisher": {
        "@id": "https://trooth.co/#org"
      },
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://trooth.co/network?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@type": "ItemList",
      "@id": "https://trooth.co/#sitelinks",
      "name": "Trooth sitelinks",
      "itemListElement": [
        {
          "@type": "SiteNavigationElement",
          "position": 1,
          "name": "Join Trooth for free",
          "url": "https://trooth.co/signup"
        },
        {
          "@type": "SiteNavigationElement",
          "position": 2,
          "name": "Company, Trooth",
          "url": "https://trooth.co/network/company/trooth"
        },
        {
          "@type": "SiteNavigationElement",
          "position": 3,
          "name": "Trooth Network",
          "url": "https://trooth.co/network"
        }
      ]
    }
  ]
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "BreadcrumbList",
  "itemListElement": [
    {
      "@type": "ListItem",
      "position": 1,
      "name": "Home",
      "item": "https://trooth.co/"
    },
    {
      "@type": "ListItem",
      "position": 2,
      "name": "Changelog",
      "item": "https://trooth.co/changelog"
    },
    {
      "@type": "ListItem",
      "position": 3,
      "name": "Agents can read your own workspace record after sign-in",
      "item": "https://trooth.co/changelog/2026-10-05-signed-in-agent-access"
    }
  ]
}
```
