Amp locks thread control behind passkeys
Amp now requires an active passkey-authenticated sudo session for sensitive operations like remote-controlling a thread. The feature adds a second factor to protect against account compromise and is framed as a proof-of-human mechanism for future Amp capabilities. Workspace admins can enforce it for members, and some privileged admin actions now always require sudo.
Solid security hardening, but this reads more like infrastructure for trust and access control than a flashy product launch.
- –Passkeys make the extra factor resistant to phishing compared with password-based approval.
- –The main practical win is reducing the blast radius if an attacker gets into an Amp account.
- –The “proof-of-human” framing suggests Amp is preparing to gate more powerful or autonomous actions behind stronger verification.
- –Admin-enforceable policy matters here because agent tools are increasingly team-shared, not just individual workflows.
DISCOVERED
1h ago
2026-05-27
PUBLISHED
2h ago
2026-05-27
RELEVANCE
AUTHOR
AmpCode