#277 Alex Salazar: Arcade's Vision to Make AI Agents Secure and Scalable

6 Aug 2025 · 53 min

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Eye On A.I. - Episode #277: Alex Salazar: Arcade's Vision to Make AI Agents Secure and Scalable

Podcast Overview Host: Craig S. Smith Guest: Alex Salazar, Co-founder and CEO of Arcade.dev Episode Focus: Discusses the challenges in developing secure and scalable AI agents that can interact with real-world applications while maintaining user security and authorization.

Episode Highlights

Introduction to AI Agents

  • Current State: Many AI agents fail to progress beyond demo stages due to lack of secure infrastructure for integration with tools like Gmail, Slack, and GitHub.
  • Key Challenge: Ensuring secure tool execution and user-specific authorization is vital for functionality.

About Alex Salazar

  • Background: Former VP of Product at Okta and founder of Stormpath, with expertise in authentication and authorization.
  • Motivation: Transitioned from venture capital to founding Arcade to address issues faced in AI infrastructure.

Understanding Arcade.dev

  • Functionality: Arcade provides developers with the tools needed to build secure AI agents that can interact with various services.
  • Core Offerings:
  • Secure connections to multiple services.
  • User-specific authorization and OAuth integration.
  • Simplifies complex workflows for developers.

Technical Insights

  • Agent Protocols: Discussion of Model Context Protocol (MCP) and Agent Communication Protocol (ACP) as frameworks for agent communication.
  • Demos and Use Cases: Live demonstration of building a multi-tool AI agent that interacts with services like Slack and GitHub.
  • Authentication Management: How Arcade handles OAuth flows, ensuring secure and user-tied authorization.

Challenges in AI Agent Development

  • Production Hurdles: Identified challenges developers face when moving from demo to production, primarily around authentication and hallucination rates of models.
  • Execution Reliability: Importance of consistent tool execution, with Arcade implementing mechanisms to handle errors and improve reliability.

Focus on Developers

  • Target Audience: Arcade is designed for developers rather than direct consumer use, aiming to provide the infrastructure for building powerful AI applications.
  • Strategic Positioning: Arcade focuses on being the backbone (or infrastructure) for AI agent development, rather than competing with consumer-oriented AI products.

Market Landscape and Competition

  • Positioning against Big Tech: Discusses competing with companies like IBM and AWS while emphasizing Arcade's unique value in handling authentication seamlessly.
  • Collaborations: Partnerships with other platforms and tools to enhance agent capabilities and security.

Future of AI Agents

  • Predictions: Belief in a shift towards more automated workflows and multi-agent systems that extend beyond simple tasks to complex business processes.
  • Market Trends: Anticipation of growth in sectors like e-commerce and finance as AI agents become more integrated into everyday workflows.

Pricing Model

  • Usage-Based Pricing: Arcade employs a pay-as-you-go model based on monthly active users and request volume, aligning costs with value delivered.

Key Takeaways

  • Security and Authorization: A central theme in AI agent development revolves around secure access and user-specific authentication protocols.
  • Developer-Focused Infrastructure: Arcade’s approach emphasizes providing robust backend capabilities to facilitate the building of scalable AI agents.
  • Emerging Trends in AI: The rise of multi-agent systems and automation will transform how businesses utilize AI, making processes more efficient and user-friendly.

Conclusion The episode provides insights into the evolving landscape of AI agents, emphasizing the importance of security, developer-focused solutions, and the future implications of these technologies in various industries. Alex Salazar's vision for Arcade is positioned as a critical enabler of effective AI agent deployment, addressing the challenges currently faced in the field.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00In this one prompt, I've asked it to do three different things. What's also important about this prompt that we're about to execute is that all of these things I'm asking it to do are ultimately on other third-party services, right? We're going to talk to Gmail. We're going to talk to Slack. We're going to talk to GitHub. And that itself is pretty difficult for agents. But most importantly, all of these services are secured. You can't access someone's Gmail unless you've authenticated as them. And similarly for Slack. So all of this is happening on behalf of me. People are learning the hard way that APIs don't work with large language model very well.

0:37You can't just hand a large language model an API definition and have it go figure it out. It might, but the error rates, hallucinations, they won't work with enough confidence to make it valuable. Our sponsor for this episode is Xtreme Networks, the company radically improving customer experiences with AI-powered automation for networking. Xtreme is driving the convergence of AI networking and security to transform the way businesses connect and protect their networks to deliver faster performance, stronger security, and a seamless user experience. Visit extremenetworks.com to learn more. That's extremenetworks, all run together, dot com to learn more.

1:29So, hi, I'm Alex Salazar. I'm the founder CEO of Arcade.dev. And at a high level, we make it possible for AI agents and large language model based applications to perform actions and connect to other systems and other services securely. And to put it in a very relatable way, most of us have used ChatTPT to draft an email, but you can't send the email from ChatTPT. And that's because ChatTPT's agent can't properly connect to Gmail and authenticate as you in order to send the email or read the emails and vice person. So we helped solve that. Prior to starting the company, I did a brief stint in venture capital at a deep tech venture firm called NeoTribe.

2:23That's where I ran into the problem. I was mostly focused on AI infrastructure and started to see where the challenges were in AI. And as a former founder sitting in venture capital, I couldn't help but get the itch and go start the company that I wanted instead of funding it. Prior to that, I was VP of product for Okta for their developer products and manager for all their new products. And prior to that, I was a CEO, co-founder of a company called Stormpath, which was an API for developers to implement authentication, login, password reset in their applications. And Okta acquired that business.

3:05That's part of its developer-facing customer identity business. So my background is heavily in authentication, authorization, developer products, and helping organizations change how they do business with their customers through software. And then a computer science degree from Georgia Tech and MBA from Stanford University. Okay. And the arcade.dev is, how would you describe it? It's a platform for building agents? Yeah. Correct. So our customers are developers, people trying to build agents themselves. So typically organizations or all the way down to hobbyists who are trying to build something fun for themselves.

3:56But our customers are building the agents and then we're giving them the ability to connect those agents securely to other services like gmail and slack and twitter and salesforce.com and anything that might be custom and internal to their organization and you i think we began talking at some point about uh and this may have been the way that we met i don't remember about a model context protocol developed by Anthropic. And I know you guys have done some work with Anthropic on developing that protocol. And I was just at a conference with IBM where they were introducing their age and communication protocol, ACP.

4:48and it's all of that sounds like it would fit in in the arcade.dev platform so yeah can you can you talk through how a developer would use arcade uh and whether ibm's acp and anthropics mcp are are the dominant protocols or whether there are a bunch of them yeah yeah it's man it's a great question um so i'll start with the protocols uh there are there is an exploding number of protocols right now but they're all in their in their infancy it is it is uh it is like the very beginning of first inning. And so I would say MCP is the one that's most talked about. And it is getting tremendous popularity because some of the coding agents that developers use to write software, the most popular one being Cursor, adopted MCP and that really exploded its popularity with developers.

5:58when people are building agents there's a lot of promise with with these protocols uh there's a lot of promise mcp in fact we're we're pretty heavily involved with anthropic and helping to evolve mcp properly specifically around off and authentication authorization but it's still very early um but the protocols are really about helping everybody agree on how an agent and another service are going to talk to each other. Just like that language between the two. So we, as a platform that helps developers build this and automate these connections and properly handle the authentication and authorization and the retry logic and all that.

6:48We're ultimately protocol agnostic. We believe in MCP and we're investing heavily in MCP. But I don't I don't think that developers ultimately care at that level. What they really care about is they want to make sure it all works. And so that's where we put all of our energy is just making sure developers are able to check the box, deliver the product they want to deliver. and we'll give it to them in the best way we can. And yeah, so let's go to the platform and you can introduce the platform and what it does. And I'm guessing with these protocols, is there a dropdown menu and you pick the protocol?

7:35I mean, how does that work? Yeah, it's a great question. So I'll give a quick demo. And for people listening, I'll walk you through it and we can all experience it in the theater of the mind. All right. So what I'm showing here is not actually our product. It's what we refer to as a sample application. And this is an example of what a developer could build using our product and the kinds of features that they could deliver. And so for the people who can't see the screen, this looks very much like a chat TPT type interface. It was like a chatbot. And so one of the big differences is at the very bottom, you're going to see this little dropdown that says toolkits.

8:23This is our terminology for all the connectors and plugins to other services that you might have in your agent. And so we've set up five toolkits here. We've got GitHub, Google Workspace, so things like Gmail, LinkedIn, Notion, and Slack.

8:46And each of those toolkits themselves are going to have a set of what people in AI refer to as tools. So each of them will have, let's call it, on average, about 10 tools. The tools themselves are the actions. And so if it said, hey, read my email, reading an email is an action. Reply to the email, that's another action. Send the email is another action. And so each of these tools have at least 10, the Google one's actually pretty beefy. That one has a lot more than 10. And so that's gonna dictate what the agent can do. So let me show you a use case. So we're gonna say,

9:27read the general channel on Slack, pull the latest activity on the Arcade AI GitHub repo and send a summary of it all to alex at arcade.dev. So what I've written but not yet submitted is what's called a multi-turn prompt. And so in ChatTPT, you'll typically say, hey, write me a poem. And that's one turn. But if you say, hey, write me an email and then summarize it. And then this other thing, the LLM, the agent, the user will have to take multiple turns to achieve what you want. And so in this one prompt, I've asked it to do three different things. What's also important about this prompt that we're about to execute is that all of these things I'm asking it to do are ultimately on other third-party services.

10:38We're going to talk to Gmail. We're going to talk to Slack. We're going to talk to GitHub. And that itself is pretty difficult for agents. But most importantly, all of these services are secured. You can't access someone's Gmail unless you've authenticated as them. And similarly for Slack. So all of this is happening on behalf of me. This is end user-based authentication and authorization, which I haven't seen many examples of in the world today. So for many people, this is the first time I'll ever see something like that. So we're going to hit enter and we're going to pray to the demo gods that it works.

11:16Live demos are always tricky. And so what's happening is we sent the prompt to the large language model. And this is an off-the-shelf large language model. We're using GPT-4.0. And along with the prompt, under the hood, we sent it a collection of like a multiple choice question of all these different tools available to it. And we sent about 50, which is a very large number, most engineering teams can't get past 10 without the LLM hallucinating, we're able to get to about 80 or 100. So we sent about 50 in this scenario. And think of it like a calculator. If somebody asks you to multiply two really large numbers, you're probably not going to get it right.

12:02But if I hand you a calculator, you're going to get it right. And so what we've done here is all of these tools are like calculator buttons. Instead of the large language model trying to figure out what it even means to look up something in Slack, it knows to hit the button that it hit here, which is the Slack get message in channel by name tool. And then it also went and hit the GitHub list repository activities tool. And that's all it had to do. And then it passes us the arguments. So it needs to know, hey, channel by name, which channel based on the prompt, it's guessing the general channel.

12:43Hey, on GitHub, which repository based on the prompt, it's hitting the arcade dash AI repo. And then we execute all of that logic for the agent. Now, when we go receive that request to go execute those tools, the very first thing that happens in Arcade is we check to see, does this tool require authentication and authorization? And in both cases, the answer is yes. And so then we say, okay, great. Is that user for whom the agent's acting on behalf of, has it already authenticated and authorized the agent to perform these actions? And if the answer is yes, we proceed. If the answer is no, then we pop up a login screen and the developer goes through what's called an OAuth flow, which almost all of us have experienced on the Internet where you go to the Google's website and there's a screen telling you, hey, do you want to allow this other application all these rights to your system?

13:42yes or no and you hit approve we handle all of that for the developer and then once developed once the user does that it sends the alert back to the agent and the agent proceeds with the requests which is what's happening here and then so that's how the service works yeah let me just go back a little bit so when you make the initial request uh the the platform is like an orchestrator It knows what tools it has access to. And rather than, as I've seen with many platforms, you deciding which tool you need to use for this workflow, it'll automatically make that decision for you. And then it's just a question of whether it has authorization, whether the platform has already gone through authorization, for example, to access your Gmail.

14:40Correct. One thing, a lot of these tools or services require an API key. is is that what you're referring to on the authorization step or is that a different step yeah the people have to go through no it's it's a great question it actually speaks to the complexity of what has to get built so um if you think of if you think of how security works at a really high level, there's a resource. Let's think your email is the resource. And then there's the subject, the person trying to access the email. And so in most scenarios as humans, it's a very simple process. We show up, there's a login screen, we type in our information, and then we're in, and then there's permissions inside the system saying, what do we have access to?

15:38Which is in our Gmail, we have access to all of it. But if we're trying to access the finance system at our organization, we probably have very limited access. Very simple use case. There's also the concept of machine identity, which is not new. This has been around forever. And so you might give an API key to another service, another piece of software. And then that service can go authenticate in its way, very similar way, to another service like a finance system. and might be able to pull information. And once it authenticates, it itself has all kinds of permissions that it accesses. But this is different.

16:21And so the number of use cases where an AI agent can and should access something as itself and purely as itself, what we call a service account, are pretty limited. You know, it's the Google search API. It's a weather API. It's typically things that aren't terribly secure. You know, you don't worry a ton about them getting broken into. But the vast majority of where end users get value from an agent require the agent to go access something that is tied to the user. You want to access your email. It's tied to you. You want to access, you know, financial information at your organization. it's going to be tied to who's reading it.

17:08The CEO is going to have very different level of access than the intern. And so when you do that, the naive approach is to have the agent simply get the user credentials and just authenticate as the end user to those services. That's wildly insecure. And more importantly, it's unsafe from an AI perspective. So let's use an email example. Your inbox, you can do whatever you want. you can delete all the emails if you wanted to. Do you want to give the agent the ability to delete email? No, because it might hallucinate and accidentally delete your email. There's a very famous coding agent called Cursor that I use actively.

17:51It once hallucinated and tried to delete my root directory. Oh, wow. Right. For those people who aren't engineers, you know, deleting your root directory is the equivalent of deleting your entire computer. Now, thankfully, you know, my Mac operating system has a bunch of authorization already built in. And so even if I had said yes, it wouldn't have been able to do it. Thank God. But you don't want to, even though you, Craig, have full access to your email, you don't want to give the agent that same level of access. And so the right approach is to give the agent an intersection of permissions, an intersection of what you, Craig, have access to, but also an intersection of what the developer and Craig had granted the agent access to.

18:40And thankfully, there's protocols for that. There's a very popular protocol called OAuth, but it's very difficult for developers to implement. And it's, until recently, almost impossible for them to implement in the context of agents. And that's what we've sold. I see. And in that case, the, well, let's go back to the API issue because LLMs don't handle APIs very well. What happens when you need to hit a service or? Yeah, that's a great question. So I think this is the thing that a lot of people are learning. I mean, the AI industry is very new, right? You know, ChatTPT and GPT 3.5, you know, had their second year anniversary this last November, right?

19:35And so it's mind boggling to really like internalize how fast this all happened. And so people are, as people are trying to build agents that can take actions, that can do things and not just generate content, people are learning the hard way that APIs, don't work with large language model very well. You can't just hand a large language model an API definition and have it go figure it out. It might, but the error rates, hallucinations, won't work with enough confidence to make it valuable. And so what people do instead, the right way to give an agent access to other services is to build what's called a tool.

20:24Terrible name, SEO is terribly, but it's the terminology everyone in AI uses. And a tool is like an action. It's an intent-based action that might wrap one, zero, one, or multiple APIs to perform that action. So I'll give you a really simple example. Reply to an email. if you're in an agent that's email based and you say, Hey, reply to my email from Craig, there is no API endpoint on the Gmail API to respond to an email. There is lookup email and there is send email. And so a reply to Craig, you know, when I say reply to Craig's email, the tool it needs is going to be reply to email tool. That tool is going to do multiple things.

21:19The first thing it's going to do is it's going to go find the email I'm referencing that I want it to reply to. So that's already one API call. Once it retrieves that email, it then has to unpack the email structure. It's called MIME. You have to unpack this email structure. It's actually a fairly complex piece of software. There's attachments, there's HTML versions and full text versions, et cetera. Unpacks all of that. then has to go generate the response, insert the response, then repackage it all up again in that email structure called MIME, and then hit the send email endpoint. Altogether, it's about 100 or 200 lines of code, depending on how diligent you're being.

22:04And that's not even including all the error handling and checks to make sure it's all working and safe. That's a lot of work. that's a distinction between an API and a tool. Now you go something much more complicated, like, hey, DoorDash, order me a pizza. The order me food tool for DoorDash would be like 10 API calls. So there's just a different level of complexity, but most importantly, it's presented to the large language model very differently. If you've ever looked at an API, it looks like gibberish. It looks like a URL. out. AI systems don't understand that. So a large language model, when a tool is presented to it, it's presented in natural language English, is a tool for replying to an email by a sender.

22:56It takes in the name of the sender, the subject line, the body of the new response, and it's all explained in English. And that's what makes a large language model really good at selecting the right tool and then selecting the right input arguments for it to go execute okay and and the um this all takes place internally i mean is that the the chief uh i mean because there are a lot of platforms out there now to build agents uh differentiator with arcade that it handles this authorization in the background so you don't have to yeah so when we yeah so the the way to describe where we fit so we are not a large language model company yeah they're very good large-time model companies out there anthropic and open ai being the most notable and so the large language models the one that selects the tools we we've designed Arcade to be the system that receives the selection and then executes the tool.

24:06And so what we're really good at, at a really high level, is helping developers get that tool execution to be so good that they can get their agent from a demo to production. And so anything that requires that, we've put a lot of IP into. The very biggest problem everybody runs into is that end user authentication and authorization. And so that is the backbone of our feature set. But there are other things that are also critical, but they're a bit in the weeds, like parallel tool calling, retrieval tool logic. So that demo I gave you, it works remarkably consistently, which in AI, that is the performance metric in AI.

24:54It's not how fast it is, it's how often is the error out. That demo I gave you, I've given that demo like a hundred times. I don't think I've ever seen it error out. And it's not because the large language model is not hallucinating. It is hallucinating just like every other system out there. But part of our IP is that we can catch those errors and then have the large language model retry with additional context. And when you do that, the consistency rates go through the roof. And so all of that nitty gritty detail that helps a developer take an agent from demo to production, that's where we focus our efforts.

25:36Yeah. And this is a developer's platform. Why not make it a B2C product for general users? Yeah, it's a great question. um you know to know thyself right um my team and i we're just passionate about infrastructure um yes uh you know i always give a house analogy um i'm trying to give you the best pipes in the industry i want you to build a beautiful house right um i i just happen to be really passionate about pipes.

26:16And yeah, but that doesn't explain why not let, you know, I think from a consumer side, oh, why not let consumers use the service to build their own agents? Yeah. Oh, okay. That's different. Yeah. So the answer I was giving you, why didn't we just build an application? like why didn't we compete with Jack's right right oh I understand that so there we want to be that we want to you know be picks and shovels why do we not expose our picks and shovels to the average consumer um there you know people call this like you know no code or low code agent builders um that's not a space one we don't know that space particularly well so there is a bit of like a domain mismatch.

27:04But second, if I'm being perfect honest, I'm just not a big believer in those because the building an agent is extraordinarily complicated. And we really want to have a big impact on what everybody in the world, what the world of AI and agents looks like and and i think that the biggest impact we could have would be giving it to the developers because they're the ones who are think are going to we believe they're the ones who are going to build the the most powerful agents of tomorrow and so that's what that's where we focused yeah and so on the platform once you built an agent uh how is it deployed or how is it moved into a production product?

27:54Yeah. So the kind of the lifecycle of an agent developer is they start to build something and they get working in demo and everybody gets wowed. You know, I'm sure, you know, you've seen a lot of agents wow you in a demo and then, you know, they never quite make it to production. It's actually one of the biggest problems right now in agents is I think like the The stat I heard somewhere is less than 30 % of agents ever make their way to production because it's so hard. The demos are easy. And so what happens next is they show it to everybody, they get approval to go really invest in it. And then they start to build and start running into a bunch of problems.

28:32The biggest problem they run into is the first one they run into is authentication and authorization because they simply can't deliver a feature. Let's say they get past that. The next problem they run into is consistency and accuracy, right? that notoriously agents and AI hallucinate. And if those hallucination rates are below 80%, it's not going to be a valuable agent. People aren't going to use it. And so a lot of things fail over that. Now, if you clear that hurdle, the next thing you're going to run into is a cost issue. OpenAI and Anthropic, they cost money. Every time you call them, you're paying for each token and that stuff can really add up at scale.

29:14So a lot of teams we talked to who don't go to production yet, somebody did math and realized, oh, if we implement this, it's going to bankrupt us. And so then there's some re-engineering of how do we implement this with fewer large language models. Now, if you're using us, we unblock the first two. The third one is, unfortunately, out of our hands. And so to deploy us, it's very easy. The developer gets an API key from us, drops it into their software. And when they're implementing their logic, they're just calling out to us for what's called the tool calls. And then we handle everything else behind the scenes.

29:50So we've offloaded a lot of the logic so that they used to drop an API key. And that's typically it for them in most use cases. If a developer wants to build their own integration and they want to author their own tool, we have a whole SDK for them to do that and leverage all the same value and benefits. And how they deploy that custom tool really depends on what they want to do. They can deploy it in their own infrastructure, their own servers, or they can deploy it to us and then we'll put it on a cloud server and run it for them. But that's really all that's needed. Yeah. And then does it create

30:35a web app for the tool that then the developer can disseminate within their organization or how so i'm a developer at a large organization i i create this agent to help people manage their emails read and send and and all of that uh that the the actual um logic sits in in the cloud with uh arcade i hit it with an api but what's the interface that that's a great question so this is an important distinction so the agent itself let's call it let's call it the app because an agent is is is just an application the difference is that it's leveraging large language models for the workflows um so instead of a developer somewhere saying okay step one step two step three in this order the there's a large language model in there and the large language model is deciding what the next step in the workflows are you know whether it's a consumer facing you know a writing app or a CRM or a finance app.

31:51That's a distinction. That app, we don't touch. That app's deployed and written in whatever way the developers want. So maybe it's deploying to AWS or to Microsoft Azure. But when it goes to take an action that talks to another service, like an integration, at that point, that app calls out to us. Right. And for most of our customers, we are used as a cloud service ourselves. But for our larger customers, they can deploy us in their own private, you know, private clouds, their own, you know, private Azure and AWS environments. Yeah. And this platform, you say you're not a model company. then you can choose the model based on whatever, you know, whether it's price or latency or whatever.

Read the full transcript

32:51I was just up to see IBM's rollout of Granite 4, and they're building these small models that are much cheaper. And for something like reading and responding to an email, You don't need a behemoth like 4.0. Do you have smaller models like that? Yeah. So for us, in the demo I gave you, that demo uses GPT-4.0, but that's really just for the demo. For our customers, they can bring whatever models they want. Right. Now, that being said, when it comes to tool calling, the ability for a large language model to decide and select that right calculator button to hit and what the input arguments are, the calculator button.

33:47Today, there are very few models that can do tool selection or what's called tool calling or function calling. Today that I know of, I think it's just OpenAI, GPT 3.5 Turbo and Up, Claude. I know that Meta's Llama, the most recent Llama release now supports tool calling. And I think Grok. So the population of the ones that can actually integrate the tools is still pretty small. That's going to change quickly. but um but yes we're you know we're believers that there there are going to be a proliferation of smaller models for more specific tasks more narrow tasks but uh but they're not yet tool calling capable they'll come yeah yeah um and and this how do you price arcade is it a subscription by seat or pay as you go usage model?

34:52Yeah. It is primarily a usage-based model. That's what developers love, pay as you go. We do have subscriptions, but they're really just proxies for usage-based pricing to make it simpler. And so we charge on two metrics. We charge on monthly active users that we're authenticating and authorizing because the identity component of the product is very important. And then separately, we charge on what we call request volume. How often are you calling out to our service to perform an action? Both of those metrics we see as metrics of the value that someone is getting from our service. Yeah. And how, I mean, this is all moving so fast.

35:44And as I said, there are a lot of these platforms for building agents. Two questions. How do other platforms handle this authentication issue? Yeah. And how do you compete with the likes of IBM who has an agent building platform or AWS or, you know, all these people are coming out with agent building platforms. Yeah. Yeah. So for the smart agent building platforms like Relevance AI, they use us. Right. You know, we are the connectors. If you look at one of the more popular ones is N8N, a very robust community. If you look at how the connections work, they don't do this. You have to kind of really do abnormal things to connect to Google Drive, for example.

36:52And it really only worked for one user because it's using that particular user's credentials hard-coded in to the agent. So that's the state of the art today. And so for anyone building an agent builder, we make all of this very easy and very secure without them having to go spend, you know, a year of engineering time trying to figure out how to make it work. Half our team is out of Okta. We nailed the office. We don't compete with off builders. And so because our target demographic, the software developers, they're not really using agent builders. Right. What they're writing the agents themselves in code because they need that bespoke fidelity of how it's going to work.

37:42Morgan Stanley is not using agent builder. Right. And so so we partner very closely with what they're most likely using, which is which are called orchestration systems. So like a Lang chain is a really good example. So there we partner very closely with them. They handle the orchestration and we handle the tool column. Yeah, that's interesting. And where do you see this going? I mean, people are now talking about these networks, Microsoft calls it a society of agents or societies of agents that'll be operating alongside human workers. I mean, how do you see that developing? And do you see that in your usage metrics?

38:35You know, I'm a very good believer in agents. I'm an agent maximalist, if you will. but I do think that I think sometimes the PR gets a little too far out from some of the reality so here's what I believe I believe that what's happening with agents is very similar to what happened with the internet in 94 OpenAI and Anthropic are the Netscape navigator of this moment And they like unlocked all of this innovation. And so now we're seeing it all happening in real time. It's happening very, very, I think by all metrics happening about twice as fast and twice as big as the Internet boom. But. And so I think it's going to radically change our lives in every way.

39:28Right. I look at my kids already. My 14 year old daughter gets upset when she sees me typing, calls me a dinosaur, yanks the phone from my hands. hits the dictate button and talks to the phone. I use my Android and I won't let go of it because the AI assistant is so far superior to Siri and only going to get better once the Gemini models officially hit the assistant level. And so I no longer interact with my phone as much with my thumbs. I talk to it. And so all of that natural language interface is super powerful because it captures intent. The best business in history was Google. And it had one input box.

40:18The entire business model was one input box. And it was so powerful because it captured user intent. If you go look at something like salesforce.com, man, you've got to go through three months of software, of training just to use a damn thing because it's so complicated. all of that's going to go away when you can just say hey give me the latest user record from you know from my meeting with craig nope that's the where all this stuff is going i i believe but i don't i i i typically i personally bristle when people personify agents because i think in five years the conversation is going to be really boring like it's going to be so powerful and so valuable but it's also going to look really boring in hindsight just like the internet looks boring in hindsight today what what it's going to feel like is really good workflow automation yeah and the people building uh with arcade are they primarily building uh agents for use within an organization or are there people building agents for uh for sale to consumers uh you know you you want an agent to read your and respond to your emails i mean yeah you could go up here and go through some supposedly simple steps that are not as simple as they sound like they're going to be, or you could just pay a few bucks, download this agent.

41:57Yeah, we see all kinds. We see everything. And I'll give you a few examples. So one of our customers is this great product. Everyone should use it. I use it called shortwave and they're building an email agent. And so, you know, it'll help you organize your inbox. It'll help clear out stuff you don't need to respond to. It'll help do a bunch of descriptions. that help you auto reply to things you don't have to type as much um it's great i love it shortwave yeah like shortwave radio shortwave yeah yeah totally look it up and uh big fan they use us uh to expand capabilities and so um as if as as you know you reply to an email for example you might want to pull context from the crm or from a notion document or your drive And so we make that easier and more possible for them.

42:48We have an agent builder, Relevance AI. They're using us to extend their agent building capabilities so that they can all be secure and very consistent and reliable. There's a large financial services organization that's using us for internal productivity. So they're building a Slack bot that integrates to all of the messaging and productivity systems that any individual employee would have. Sneak, which is a big security company, they're using this for a social media app that they built. They started off in one team. It was so successful, they're now rolling it out like wall to wall in the organization.

43:27And this social media agent connects to Twitter and LinkedIn. in, you know, you give it a topic and it will go do the, you know, go prepare everything and research it and, and, and, and read your old, your old posts to keep it in, in your, in your style and tone and then generate the content. So we're doing all of the integrations to the social media platforms. And then there's a very large wealth management department at one of the top, you know, financial services banks, you know, top fortune 50. And they are trying to modernize the wealth management system for their clients. And they want it to be more agentic where clients can really ask complex questions about their portfolios and make decisions and have it all connect to secure systems.

44:15Because it's very sensitive information. And so we see all kinds. I would say the majority of what we see are technology companies building consumer or B2B facing software and then financial services. I think if I were to predict what's coming, I think e-commerce and retail is going to be the next domino to fall. We are part of a partnership with Visa trying to get, you know, agentic commerce working. There's a lot of complexity there. And I think once things like that start to get released, I think we're going to see a revolution in e-commerce as well. Yeah. Yeah, it's fascinating. And just going by a sneak, this social media management agent, is that going to be available to consumers?

45:12or that's for their internal use? Yeah, so they built it for themselves. So they use it for internal use. Langchain, one of our friends, they built a open source publicly facing social media agent that also uses us. And anyone can use that. That's fully open source. It uses Langchain's LangGraph agent framework and Arcade under the hood. So that can be a reference implementation for somebody who wants to do something similar. And that's simple enough for a consumer to use or is that for companies? I think that one is for developers to turn it into whatever they want to expose. And so an intrepid developer could go package that up and release it as a consumer facing product.

45:58But I think it's really designed for developers to repackage. Yeah. Have you seen as people are developing these agents, are there marketplaces of agents or agent stores, you know, as there have been for a lot of other? Yeah, there are a lot of people trying. I think what the first iteration of it's looking like are these directories of agents. um there are many um and um i don't know that i've yet seen one where it's a marketplace where i can legitimately just like pay for things uh i'm sure that's coming i don't know who will own that category um but yeah i don't i don't know that an app store has yet come out for agents yeah uh and maybe it will be the app store i mean right um and for you guys when did you start arcade we started arcade a little over a year ago okay and uh it originally started as us trying to build an agent um you know it's trying to build an agent that could diagnose production software issues.

47:20So your Netflix and for whatever reason, the videos aren't loading fast enough or the servers are crashing for some reason. And traditionally a human has to get involved to go figure out what's going on. And we were building an agent that could go automatically do some of that work. And it was really hard. The hardest part of it was we had a very hard time getting the agent to go connect to all these sensitive systems and be authorized and authenticated properly and be really consistent in its polls of data. And so we had to reinvent how we were building an agent. And that's ultimately what led us to the insights and the innovation that we pivoted into, which is Arcade.

48:00We ultimately took that underlying platform and turned that into its own product. Yeah. And your work with Anthropic and was it Microsoft on MCP? is that because you guys came out of octa and our authentication specialists that that you got involved uh what what was the relationship there yeah so uh mcp mcp is very new as a protocol yeah and um and and anthropic got a lot of things right uh but they didn't get everything right And so how Auth is handled was one of those places that was still something that needed a lot of work. And to Anthropik's credit, instead of just trying to muscle through it themselves, they opened it up to the community to help.

48:54They opened it up to all the experts. And today, the Auth community is not terribly large. and all the experts are either from Microsoft or Okta alumni. And so we have three of the best off people from Okta on our team, and Microsoft with their Entra, formerly known as Active Directory team, are very expert on this. And so we've been involved as part of the community effort with Anthropic, And we're actually really excited as to where that protocol is going and in particular where the off with it is going. I think it's going to be a really nice developer experience. Is there anything I haven't talked about that you want listeners to know?

49:45Yeah. I mean, I would say that the biggest ask, if you will, that I have of people, especially either developers themselves or leaders in organizations, is to think past a chatbot. So many people envision an agent and they think chat CPT. Right. But all the biggest places where AI can really have a big impact are really around automating parts of our lives and parts of our work. And many of those use cases are going to look a lot different than what a chat to PT-like interface looks like. And once people start to realize the art of the possible that, oh, wait a second, I can build an agent. I can go interact with this and connect to that.

50:39that there's so much power in what can happen and so um i hope people think bigger and when they think bigger i hope they think of us as well yeah and and just one last thing on on you build an agent but but i mean oftentimes in a workflow um it's it's better to to uh uh make things composable or or so you may have an agent rather than having an agent that can do 10 things break it up uh so you have 10 agents that that work together uh do you does uh arcade account for that i mean can you yes yeah actually uh it's a well i mean that's like a whole that's whole podcast on its own concept of, of, of, you know, um, of multi-agent systems.

51:31Um, yeah, we are very big believers in multi-agent systems. We're, our product is ultimately agnostic. Um, but, but we are, we're very big believers. And when we build agents for ourselves or sample applications, we're increasingly showing off, uh, multi-agent systems. Our sponsor for this episode is Xtreme Networks, the company radically improving customer experiences with AI-powered automation for networking. Xtreme is driving the convergence of AI networking and security to transform the way businesses connect and protect their networks to deliver faster performance, stronger security, and a seamless user experience.

52:20Visit extremenetworks.com to learn more. That's extremenetworks, all run together, dot com to learn more.

From the publisher

In this episode of Eye on AI, host Craig Smith sits down with Alex Salazar, co-founder and CEO of Arcade.dev, to explore what it really takes to build secure, scalable AI agents that can take real-world actions.

While everyone's talking about the future of autonomous agents, most never make it past the demo stage. Why? Because agents today lack secure infrastructure to connect with real tools like Gmail, Slack, Notion, GitHub—and do so on behalf of users without breaking authentication protocols.

Alex shares how Arcade solves the missing layer in AI agent development: secure tool execution, user-specific authorization, OAuth flows, and production-ready consistency.

Whether you're building with GPT‑4, Claude, or open-source models, Arcade handles the hard part—making agent actions actually work.


Stay Updated:
Craig Smith on X:https://x.com/craigss
Eye on A.I. on X: https://x.com/EyeOn_AI


(00:00) Why AI Agents Can't Take Action (Yet)
(01:27) Meet Alex Salazar: From Okta to Arcade
(03:39) What Arcade.dev Actually Does
(05:16) Agent Protocols: MCP, ACP & Where Arcade Fits
(07:36) Arcade Demo: Building a Multi-Tool AI Agent
(11:16) Handling Secure Authentication with OAuth
(14:40) Why Agents Need User-Tied Authorization
(19:25) Tools vs APIs: The Real Interface for LLMs
(23:41) How Arcade Ensures Agents Go Beyond Demos
(25:48) Why Arcade Focuses on Developers, Not Consumers
(27:55) The Roadblocks to Production-Ready Agents
(31:15) How Arcade Integrates Into Agent Workflows
(33:16) Tool Calling & Model Compatibility Challenges
(34:49) Arcade's Pricing Model Explained
(36:20) Competing with Big Tech: IBM, AWS & Others
(38:38) Future of Agents: From Hype to Workflow Automation
(41:58) Real Use Cases: Email Agents, Slack Bots, Finance & More
(46:17) Agent Marketplaces & The Arcade Origin Story

More from Eye On A.I.

All 266 episodes
#277 Alex Salazar: Arcade's Vision to Make AI Agents Secure and ScalableEye On A.I. · 53 min
Listen in VO