Don't vibe code your auth: Common Room’s playbook for secure AI

About the Author

Lauren Everitt

Director, Okta Newsroom

Lauren Everitt is the Director of the Okta Newsroom, where she leads content strategy and editorial direction. She previously held senior editorial and management roles at Slack and worked as a journalist in East Africa.

September 01, 2026 Time to read: ~

Vidyard video

This is the first episode of Agent Eye-Openers, a series of conversations that delves into the decisions, discoveries, and wake-up calls defining the AI era. 

When Tom Kleinpeter, Co-Founder and Chief Architect at Common Room, got a call from relatives in Louisiana asking how to use AI agents to automate their gravel business, he realized the technology had hit a turning point. “They’re everywhere,” he explained.

Kleinpeter is an AI enthusiast, especially when it comes to agents. “It’s eye-opening how awesome agents are. There is just so much power to be unlocked,” he says. But that optimism is tempered with a healthy dose of caution when it comes to security. Because Common Room—an intelligence platform for go-to-market teams—deals in customer data, security is a top priority, even more so with the rapid adoption of AI agents, according to Kleinpeter. 

“When we're integrating with a new customer, we have to prove that our platform is not going to put anyone’s data at risk,” he explains. “We would never want to say, ‘Oh, that auth solution that's gaining access to your data, we just vibe coded that this weekend.’"

The high stakes of agentic access

While granting agents access to account data carries risk, it’s also a requirement for new features that Common Room’s customers demand. “We couldn’t credibly be in this marketplace if we didn't have agentic access to our data,” Kleinpeter says. With this access, Common Room’s AI agents can execute tasks ranging from researching key accounts to predictive lead scoring to drafting outbound emails. 

Common Room’s agents can parse reams of account data and identify buyer signals that human eyes might miss. These agents not only surface fresh insights for Common Room’s customers, they also save them time. Agents can quickly assess multiple data sources about an account or contact and take the best next step, something that previously only elite sales reps could do with speed. 

But these outcomes require agent access. “Our customers can only realize these benefits if we can trust the security and open that data up to AI agents,” Kleinpeter says.

Waiting for the right standard: Auth for MCP 

Which is why they implemented Auth for MCP. When the Model Context Protocol (MCP) spec was released, the Common Room team knew about it within hours. But despite the fast-moving nature of the AI space, they decided to hit pause.

“That was not an auth use case that we were comfortable with,” Kleinpeter recalls. Handing out API keys for people to embed in local servers or relying on hard-coded auth tokens that sat un-refreshed on machines wasn’t a risk they were willing to take. 

It wasn't until Auth for MCP rolled out that Common Room felt comfortable integrating MCP broadly into their roadmap. By relying on a solution that adds an authentication and authorization layer for agents, they could confidently give their agents carefully scoped access to the data human reps use—no more, no less.

Speeding up innovation without sacrificing security 

For Common Room, choosing Auth0 wasn't just about risk mitigation; it also accelerated their product development. If developers are bogged down manually building complex trust layers for every agent, time-to-market takes a hit. 

“If we have to stop and deal with all the details of security and authentication, it prevents my team from being able to work on the things that deliver the most value to customers,” Kleinpeter says. Security is a non-negotiable, but by offloading the most critical and sensitive parts of the authentication process to Auth0, Common Room’s engineers can stay focused on building the breakthrough AI features that their customers want. 

The vibe-coding trap

Looking ahead at the next 12 to 18 months, Kleinpeter sees a landscape where attackers are moving faster than defenders. AI lowers the cost of exploiting vulnerabilities, meaning security best practices that worked in the past must be continually revisited.

His biggest warning to fellow tech executives architecting their first AI agent integrations? Don't fall into the trap of using AI to write your security protocols.

“Don't vibe code anything related to auth. It's a trap. You're going to think that it works, and it may work great a lot of the time, but you're just sowing the seeds of future pain,” he warns. AI agents are great at generating code that appears functional, but unless you are a security professional trained to spot edge cases and subtle flaws, you won't see the vulnerabilities. Attackers armed with better models eventually will.

By using Auth0, Common Room is better positioned to avoid these unknowns. Delegating identity to dedicated experts who continually maintain standards and run rigorous testing allows Common Room to focus on innovating for their customers and exploring new use cases for AI. "Relying on Auth0 to manage agent authentication lets me move more confidently and sleep better at night because I can focus on creating customer value and know that the security is being handled,” Kleinpeter says. 

Watch the full video above to hear more of Tom's insights on AI agents, auth, and emerging risks. 

About the Author

Lauren Everitt

Director, Okta Newsroom

Lauren Everitt is the Director of the Okta Newsroom, where she leads content strategy and editorial direction. She previously held senior editorial and management roles at Slack and worked as a journalist in East Africa.

Get our Identity newsletter

Okta newsletter image