Arcade raises $60M to secure enterprise AI agent permissions

๐กLearn how to solve the critical security bottleneck preventing autonomous AI agents from scaling in enterprises.
โก 30-Second TL;DR
What Changed
Raised $60M in funding to address AI agent security
Why It Matters
This funding highlights a growing market shift toward agent governance and security, which is essential for enterprise-scale AI deployment.
What To Do Next
Audit your current AI agent architecture to ensure granular permission controls are implemented before scaling.
๐ง Deep Insight
Web-grounded analysis with 10 cited sources.
๐ Enhanced Key Takeaways
- โขArcade was founded in 2024 by Alex Salazar, formerly of Okta, and Sam Partee, previously from Redis, bringing expertise in identity and data infrastructure to AI agent security.
- โขThe company previously secured a $12 million seed round in March 2025, bringing its total funding to $72 million with the latest $60 million Series A.
- โขArcade has authored the MCP (Multi-User Authorization Protocol) authorization specification, which has been adopted by Anthropic, positioning it as a potential standard-setter for AI agent authentication.
- โขThe platform offers three core capabilities: fine-grained authorization linked to user permissions, enhanced reliability through a catalog of over 8,000 purpose-built MCP tools, and a comprehensive governance audit trail.
- โขArcade has seen a 25x growth in tool call volume over the past six months, with its solutions already deployed in production at major financial institutions, including a top US bank, Prosus, and LangChain.
๐ ๏ธ Technical Deep Dive
- Integrates with enterprise identity providers (IdP) and leverages the OAuth 2.0 protocol to manage AI agent access via tokens.
- Dynamically updates agent permissions in response to changes in IdP records, eliminating the need for manual adjustments.
- Encrypts OAuth tokens prior to storage and employs a 'salting mechanism' to enhance security and mitigate risks associated with identical plaintext credentials.
- Enforces permissions by ensuring agents act strictly on behalf of authenticated users, rather than through broad service accounts, with every action evaluated against both user and agent-scoped permissions.
- Provides a central control plane for policy enforcement and a complete audit trail, detailing which agent performed what action, on behalf of which user, and against which resource.
- Offers over 8,000 MCP tools specifically designed for AI agents to improve reliability, reduce failed actions, and optimize token consumption.
- Designed for flexibility, supporting integration with any Large Language Model (LLM), framework, identity provider, and MCP client.
- Is SOC 2 compliant and includes out-of-the-box features like Single Sign-On (SSO), Role-Based Access Control (RBAC), and comprehensive audit logs.
- Supports various deployment models, including cloud, on-premise, air-gapped, and hybrid environments, allowing enterprises to control data residency and security.
- For financial services, it ensures user-specific multi-user authorization, scoped permissions (e.g., read-only vs. transactional), just-in-time credential retrieval (tokens fetched at execution and not exposed to LLM), and complete audit trails.
- Integrates with frameworks like LangChain to provide a secure tool execution and multi-user authorization layer.
๐ฎ Future ImplicationsAI analysis grounded in cited sources
โณ Timeline
๐ Sources (10)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
Weekly AI Recap
Read this week's curated digest of top AI events โ
๐Related Updates

Trump claims Apple will manufacture chips with Intel in US

Parafin secures Goldman Sachs credit for embedded lending

Telepatia raises $33M to scale AI healthcare in LatAm

European automakers pivot to defense amid EV slowdown
AI-curated news aggregator. All content rights belong to original publishers.
Original source: The Next Web (TNW) โ