{"id":"pg_ryjzcdamn_gh","property_id":"prp_pklgwresh6hp","domain_id":"dom_zrkwapcbulfb","root_domain":"vercel.com","locale":"en","url":"https://vercel.com/passport","url_hash":"0e094c246b76f74d03df365e1a9cda01cd8584d046f2e26a297014f311acb2fd","path":"/passport","depth":1,"canonical_url":"https://vercel.com/passport","canonical_page_id":null,"page_type":"landing","page_type_guess":"landing","state":"indexed","skip_reason":null,"priority":"0.9","discovered_via":"link","first_seen_at":"2026-08-27T09:05:14.179Z","last_seen_at":"2026-08-27T09:06:06.334Z","http_status":200,"content_hash":"4eac7258b98ad1b50d0a539cd4251ffde71b322b11162a0e82ca236d4e0c834b","title":"Vercel Passport - Vercel","description":"Secure identity and access for AI apps and agents on Vercel.","author":null,"published_at":null,"modified_at":null,"word_count":497,"reading_time_sec":136,"lang_detected":"en","images":[],"links_out":null,"markdown_source":"readability","refresh_interval":"monthly","last_fetched_at":"2026-08-27T09:05:40.801Z","next_refresh_at":"2026-09-26T09:05:40.801Z","runs_count":1,"changes_count":0,"last_changed_at":null,"fail_count":0,"last_error":null,"created_at":"2026-08-27T09:05:14.179Z","updated_at":"2026-08-27T09:05:14.179Z","inlinks":12,"inlinks_body":2,"outlinks":74,"outlinks_external":11,"anchor_terms":["Passport","PassportNew","VercelPassportPasaportePassaportoパスポートIss 2026PassportSecure every internal agent, app, and deployment with your identit"],"template_score":"0.92307692307692307692","cash":"0.00270419526487898962","cash_total":"0.71298862643716952501","pagerank":null,"is_orphan":false,"link_confirmed":true,"discovered_wave":1,"embedded_hash":"4eac7258b98ad1b50d0a539cd4251ffde71b322b11162a0e82ca236d4e0c834b","embedded_at":"2026-08-27T09:13:31.797Z","domain_name":"Vercel Inc.","brand_color":null,"domain_rank":579,"spam_score":14,"markdown":"## Introducing Vercel Passport\n\nSecure every internal agent, app, and deployment with your existing identity provider.\n\n## Forge-proof verification\n\nAfter a user clears the gate, Passport gives the agent a signed JWT in the `x-vercel-oidc-passport-token` header. Read from your data source like Snowflake or Salesforce and your permissions apply to the real person, not a shared service account.\n\n## Authenticate once,  \ncontrol everything\n\n-   Every deployment is gated by your identity provider. Authenticate with Okta, Auth0, or any OAuth 2.0 / OpenID Connect provider.\n    \n-   Flat-rate pricing. Put Passport in front of every internal tool, agent, and app, and let the whole company in at no additional cost.\n    \n-   Never write a line of auth. Define access for your whole organization in one place while all agents and applications inherit.\n    \n\n## Frequently asked questions\n\nWhat is Vercel Passport?\n\nVercel Passport gates every app and agent you deploy behind your own identity provider. Each deployment is private by default, and once a user signs in, the app receives a signed identity it can trust, so your IdP controls what that person can reach downstream.\n\nWhat problem does Vercel Passport solve?\n\nIt takes staying internal off the shoulders of individual builders and ends per-app login. Instead of every app rolling its own auth and its own idea of who the user is, deployments are private behind your IdP, and the app receives a verified identity that reaches all the way to connected systems like Snowflake and Salesforce.\n\nWhich identity providers can I use?\n\nAny provider that supports OAuth 2.0 or OpenID Connect, including Okta and Auth0. You add it as a Generic OAuth application, entering your issuer and endpoints through discovery or manually, with `https://connect.vercel.com/callback` registered as the redirect URI.\n\nHow does Vercel Passport work?\n\nWhen a visitor opens a protected deployment, Vercel redirects them to your identity provider. After your provider authenticates them, Vercel validates the response, sets a session cookie for that deployment, and forwards a signed identity token to your server. A visitor with a valid session can view the deployment until the session expires.\n\nHow do I read a signed-in visitor's identity?\n\nRead the `x-vercel-oidc-passport-token` header from server-side code. It is a Vercel-signed JWT, and the `external_sub` claim is the reliable user identifier. Vercel strips any client-supplied value and injects the verified token after validating the session, so your server can trust it. Profile fields like email or name appear only if your provider returns them.\n\nDoes Vercel Passport work with Vercel Connect?\n\nYes, they work together. Passport carries a verified identity in at the door. Connect carries it downstream when the app mints scoped tokens for third-party services. Who the user is, what they can open, and what their tokens can reach are the same person, end to end.\n\nDoes Vercel Passport work for agents too?\n\nYes. Agents you deploy sit behind the same gate and inherit the same policy, so the identity that governs your apps governs your agents.\n\nWhat does Passport cost?","storage":{"htmlKey":"stealpage/html/vercel.com/pg_ryjzcdamn_gh/run_hel272nw6ken.html.gz","markdownKey":"stealpage/md/vercel.com/pg_ryjzcdamn_gh/run_hel272nw6ken.md.gz"},"facets":{"page_id":"pg_ryjzcdamn_gh","domain_id":"dom_zrkwapcbulfb","root_domain":"vercel.com","locale":"en","format":"landing-copy","depth":2,"technicality":3,"promotional":4,"originality":2,"audience":"developer","funnel_stage":"awareness","intent":"informational","evidence":"none","tone":"conversational","has_code":true,"code_langs":[],"has_data":false,"has_tables":false,"has_images":false,"has_video":false,"has_faq":false,"external_links":0,"heading_count":4,"topics":["identity","security","authentication"],"keywords":["Vercel Passport","JWT","OAuth 2.0","OpenID Connect","identity provider","signed token","session cookie","external_sub"],"entities":{},"takeaways":["Vercel Passport allows apps and agents to be secured behind an identity provider, ensuring that only authenticated users can access them.","It uses a signed JWT in the `x-vercel-oidc-passport-token` header to verify user identity, which can be trusted by the app's backend.","The solution eliminates the need for per-app authentication, allowing organizations to manage access from a single point.","Vercel Passport works with any OAuth 2.0 or OpenID Connect provider, including Okta and Auth0, and integrates with Vercel Connect for downstream services.","It provides a flat-rate pricing model, making it cost-effective to secure all internal tools, apps, and agents with a single solution."],"summary":"Vercel Passport provides a way to secure internal apps and agents with verified user identities through existing identity providers.","ai_likelihood":"0.126","shelf_life":"evergreen","quality_score":"0.4339","fingerprint":"4eac7258b98ad1b50d0a539cd4251ffde71b322b11162a0e82ca236d4e0c834b","model":"qwen/qwen3-30b-a3b","classified_at":"2026-08-27T09:11:01.283Z","created_at":"2026-08-27T09:11:01.283Z","updated_at":"2026-08-27T09:11:01.283Z"},"assets":[{"kind":"image","src_url":"https://lishhsx6kmthaacj.public.blob.vercel-storage.com/og-images/passport-og.jpg","r2_key":null,"alt":null,"caption":null,"width":null,"height":null,"is_hero":true,"zone":"main"},{"kind":"image","src_url":"https://vercel.com/vc-ap-vercel-marketing/_next/static/immutable/media/logo-okta-light.2_arwu_jb4lqm.svg","r2_key":null,"alt":"","caption":null,"width":16,"height":16,"is_hero":false,"zone":"main"},{"kind":"image","src_url":"https://vercel.com/vc-ap-vercel-marketing/_next/static/immutable/media/logo-okta-dark.1krxsttyvb3ql.svg","r2_key":null,"alt":"","caption":null,"width":16,"height":16,"is_hero":false,"zone":"main"},{"kind":"image","src_url":"https://vercel.com/vc-ap-vercel-marketing/_next/static/immutable/media/vercel-light.3_gxxexgi1nmy.svg","r2_key":null,"alt":"Vercel","caption":null,"width":115,"height":100,"is_hero":false,"zone":"main"},{"kind":"image","src_url":"https://vercel.com/vc-ap-vercel-marketing/_next/static/immutable/media/vercel-dark.1f3cgy23m5_jy.svg","r2_key":null,"alt":"Vercel","caption":null,"width":115,"height":100,"is_hero":false,"zone":"main"}],"shots":[],"history":[{"id":"run_hel272nw6ken","started_at":"2026-08-27T09:05:40.732Z","http_status":200,"fetcher":"direct","changed":false,"diff":null,"word_count":497}],"citedBy":[{"id":"pg_2l0thjdrkhtn","url":"https://vercel.com/","title":"Agentic Infrastructure - Vercel","anchors":["Passport","VercelPassportPasaportePassaportoパスポートIss 2026PassportSecure every internal agent, app, and deployment with your identit","PassportNew"],"zone":"main"}]}