K.A
Kurt Axcel's Blog
PortfolioBlog
PortfolioBlog

V1.2.0

K.A

Kurt Axcel Peñano

Built to bridge the gap between imagination and operation.

Resources

Portfolio AssetsStrategyMy BlogYouTube Channel

Links & Legals

Book a CallContactPrivacy Policy

© 2026 Kurt Axcel Peñano. All rights reserved.

V1.2.0

Registry Index
Security / AI
Apr 08, 2026

The ApplyAgent Story: Bridging the "Trust Gap" in the Agentic Era

Context: This post chronicles the engineering journey of ApplyAgent, a secure AI career assistant built for the Auth0 Hackathon. It explores the intersection of autonomous automation and zero-trust identity, proving that we can empower AI without compromising security.

Context: This post chronicles the engineering journey of ApplyAgent, a secure AI career assistant built for the Auth0 Hackathon. It explores the intersection of autonomous automation and zero-trust identity, proving that we can empower AI without compromising security.

The Spark: Solving the "Trust Gap"

Job hunting has always felt like a second full-time job. While the hype around "AI Agents" promised to apply for roles while we sleep, as a developer, I couldn't ignore the hidden cost: Security.

I refused to hand over raw passwords or long-lived API keys to an LLM. I realized the biggest barrier to AI adoption isn't intelligence—it’s Trust. I set out to architect a world where I could grant an AI agent the authority to represent me, without ever giving it the secrets to compromise me.

This is how ApplyAgent was born—the career assistant built on the "Authorized to Act" principle.

The Mission: The "Agentic Hub"

I engineered ApplyAgent to be more than just a form-filler; I wanted a secure Agentic Hub.

The system ingests my resume and a target job description, performs a multi-dimensional compatibility analysis, and drafts a hyper-personalized pitch. But the true magic happens at the point of action: when it's time to hit "Send," my agent never touches a saved password.

Instead, it leverages the Auth0 Token Vault to securely exchange a scoped "Token of Authority." The email is dispatched from my actual Gmail account, but the AI agent never sees my raw credentials. It’s the convenience of elite automation with the security of a global bank vault.

The Build: Premium Tech Stack

For ApplyAgent, I didn't want a simple MVP; I wanted a Premium Experience.

  • Frontend: `Next.js 16 (Turbopack)` for lightning-fast responsiveness.
  • Styling: `Tailwind CSS 4` + `Framer Motion` for a sleek, "living" visual language.
  • Security: The brand-new `Auth0 v4 SDK` to implement identity-first patterns.
  • Intelligence: `Gemini 2.5 Flash Lite` via the `Vercel AI SDK`—selected for its high-velocity context window and nuanced professional understanding.

The Auth0 Token Vault was the absolute game-changer, allowing me to close the zero-trust loop and ensure a "cryptographically safe" reasoning trace within the AI's internal logs.

The Battle: Overcoming the Edge

Engineering on the "bleeding edge" always comes with thorns.

Integrating the early-stage Auth0 v4 SDK required mastering new proxy-based conventions in real-time. But the biggest challenge was the "Hand-off": how do I show a user that an agent is acting for them while ensuring they feel 100% in control?

I solved this through a "Human-in-the-Loop" Review Hub. Every drafted email must be visually approved by the user before the "Token of Authority" is even requested. The agent is the architect, but the human is always the supervisor.

The Triumph: Identity as the Perimeter

I am incredibly proud to have built a truly redundant-free, zero-trust workflow.

Seeing the agent successfully send its first authorized email—and verifying that no sensitive tokens were leaked in the AI's reasoning traces—was the "aha" moment. I knew I had found the future of AI safety.

The UI also reflects this "Agentic" energy; vibrant emerald flows and smooth transitions make the application feel alive and responsive, bridging the gap between cold automation and human-centric design.

NEXUS REGISTRY: APPLYAGENT (AUTH0 HACKATHON)

ApplyAgent is a high-fidelity proof-of-concept for secure agentic automation, demonstrating how zero-trust identity architectures can safely enable AI representation.

Core Outcomes:

  • Zero-Trust Identity — implementing Auth0 Token Vault for scoped, passwordless agent authority.
  • Agentic Orchestration — multi-stage reasoning for resume-job compatibility and drafting.
  • Human-in-the-Loop — designing the Review Hub to ensure human oversight in autonomous workflows.

Primary Identity: Security / AI / Auth0 Ecosystem

The future isn't just smart; it's secure. Welcome to the Agentic Era.

#AI #ApplyAgent #Auth0 #Hackathon #Security #NextJS #GeminiAI #BuildInPublic #TechStudent

Connection Established

BUILDING SOMETHING SIMILAR?

Back to Central Registry