Image source: Public Domain
Nylas, the communications data layer powering core product experiences and agentic AI workflows, announced the general availability of Nylas IAM. With IAM, developers can issue a unique API key for each service that calls Nylas, scoped to the actions that service needs and to the account, workspace, application or organization it works in. Nylas verifies every request against the key's scope before it reaches the email or calendar provider, and records every call, including the ones it refuses. IAM is included on every Nylas plan at no additional cost.
Teams building on email and calendar data once connected a single service to Nylas. Today they often run several, and increasingly an AI agent alongside them. Security teams are paying attention: 81% of security leaders say they are concerned about excessive AI access, according to Okta's Global CISO Insights 2026 survey of 306 security leaders across six countries.
Each IAM key comes from a principal, which holds three things:
For teams building AI agents, IAM settles in advance what an agent can reach. An agent whose key holds only read access can read a customer's thread and prepare a suggested reply for a person to approve, but if it tries to send, the call is refused and logged. The Nylas MCP server also filters the tools it exposes based on the permissions of the key it uses.
IAM works alongside the identity platforms enterprises already use to manage which applications and agents hold access. Because Nylas checks each request before it reaches the provider, a key can be limited to an individual mailbox or calendar and to specific actions within it.
"Teams used to connect one service to Nylas. Now they run several, and many are adding an agent next to them," said Hazik Afzal, VP of Product at Nylas. "IAM lets them decide what each one can reach once, in one place, and we enforce it on every request. When a security reviewer asks what a service can access, the answer fits on one line."
Existing Nylas API keys continue to work exactly as they do today, and Nylas is not deprecating them. Customers can move one service at a time by creating a principal, issuing a key, and replacing the key in that service's configuration, with no code changes.