This paper prescribes an approach for authenticating and protecting mobile agent in a client-server type authentication system. By combining biometric information and shared secret information, a robust one-time key can be created to protect mobile agents and guarantees that they are totally belong to the agent’s owner. The created pseudo-biometric key doesn’t contain FAR ( false accept rate) or FRR (false reject rate).