
%20(400%20x%20200%20px)%20(800%20x%20300%20px)%20(6).png?width=1600&height=600&name=Texto%20(800%20x%20400%20px)%20(400%20x%20200%20px)%20(800%20x%20300%20px)%20(6).png)
Speakers: Hunter Hawke, Sr. Solutions Architect and Josh Drake, Chief Technology Officer
AI agents are getting real access to APIs, tools, and sensitive data, often taking actions without a human in the loop. As that access grows, so does a fundamental identity problem: how do you prove what’s actually executing the request?
Authorization tells you what an agent can do, but Oauth Tokens and API keys can be stolen, copied, or replayed. They don't necessarily prove that a request is coming from the trusted agent or workload you intended.
In this live demo, we'll show how Smallstep uses hardware-bound device identity to establish stronger trust for AI agents, MCP servers, and autonomous workloads by binding credentials to the system actually executing the request.
We'll cover:
- Why authorization alone isn't enough for autonomous agents and workloads
- How hardware-bound credentials prevent identities from being copied or replayed
- Using device identity to secure MCP and agent-to-agent communication
- A live demo of hardware-bound identity in an AI workflow
We'll also share what we've learned dogfooding this approach with Tsunami, Smallstep's internal AI fleet that turns our meetings, documents, and knowledge into a live, queryable, but secure RAG system.
%20(400%20x%20200%20px)%20(800%20x%20300%20px)%20(9).png?width=1600&height=600&name=Texto%20(800%20x%20400%20px)%20(400%20x%20200%20px)%20(800%20x%20300%20px)%20(9).png)
Speakers: Ted Malone, VP of Strategy and GTM and Andy Mast, Customer Success Manager
Zero Trust changed how organizations think about user identity. We added MFA, SSO, conditional access, and stronger authentication—but the device on the other end is often still taken at face value.
That’s the missing half of Zero Trust.
MFA can verify who is requesting access. Conditional access can check posture. MDM can tell you a device is managed. But none of those necessarily provide **cryptographic proof of the device making the request**.
In this webinar, we'll explore why verifying the user is only half the Zero Trust model—and what changes when you can establish and enforce the identity of the device, too.
We'll cover:
- Why user identity and device posture aren't the same as device identity
- How stolen credentials become more dangerous when they can be used from an unverified device
- How hardware attestation provides cryptographic proof of device identity
- How hardware-bound credentials prevent device identity from being copied or exported
- How to carry device trust into access decisions across Wi-Fi, SSH, internal apps, and other sensitive resources
We'll also walk through a live demo showing how Smallstep turns device trust from something you assume into an identity you can cryptographically verify and enforce.
%20(400%20x%20200%20px)%20(800%20x%20300%20px)%20(10).png?width=1600&height=600&name=Texto%20(800%20x%20400%20px)%20(400%20x%20200%20px)%20(800%20x%20300%20px)%20(10).png)
Speakers: Carl Tashian, Sr. Staff Engineer and Hunter Hawke, Sr. Solutions Architect
PKI quietly secures nearly everything—TLS, Wi-Fi, VPNs, APIs, devices, workloads, and the systems they connect to.
But for a lot of teams, PKI still means manual certificate requests, painful renewals, aging CAs, and the constant fear that an expired certificate will take something important offline.
PKI isn't the problem. Running it like it's still 2010 is.
The number of devices, workloads, services, and AI agents that need identities is growing, while certificate lifetimes are getting shorter. Managing that infrastructure manually doesn't scale.
In this webinar, we'll explore what modern PKI looks like when certificate lifecycle management is built around automation from the start.
We'll cover:
- Why traditional PKI became so difficult to operate
- How ACME automates certificate issuance and renewal
- How shorter-lived certificates change the way teams need to think about lifecycle management
- Where hardware-bound keys add stronger identity guarantees
- How to manage certificates across devices, workloads, services, and other non-human identities
We'll also walk through a live demo showing how Smallstep automates certificate issuance, renewal, and lifecycle management—so PKI becomes infrastructure your systems can depend on without your team constantly thinking about it.