| ▲ | Identity Management for Agentic AI [pdf] (2025)(openid.net) | ||||||||||||||||||||||
| 58 points by cgeier 5 hours ago | 17 comments | |||||||||||||||||||||||
| ▲ | iamjake648 an hour ago | parent | next [-] | ||||||||||||||||||||||
How does this releate (or not) to Okta/Auth0's XAA, Identity Assertion JWT Authorization Grant? I'm struggling to follow. https://auth0.com/docs/ai-agents-mcp/cross-app-access https://datatracker.ietf.org/doc/draft-ietf-oauth-identity-a... | |||||||||||||||||||||||
| ▲ | juanre an hour ago | parent | prev | next [-] | ||||||||||||||||||||||
I wrote a solution for this, and it has been working across several organizations for some months now. I run it as a public service at https://awid.ai but I would love to offload it to a foundation. - OSS (https://github.com/awebai/aweb/tree/main/awid) - Trust rooted in the DNS. - Multiple registries supported. - did, verifiable stable identities. - Certificate-based teams. It is being a very interesting project so far. It's at the core of my https://aweb.ai which enables agents to communicate globally, and it makes it possible to build really simple agent-first tools where auth is just a matter of validating a certificate. | |||||||||||||||||||||||
| ▲ | bob1029 an hour ago | parent | prev | next [-] | ||||||||||||||||||||||
> agent-native identity I think this is the cursed part of the mission. What are we actually arguing for here? Something like a limited liability corporation? "Agent-native identity" reads to me the same way that "unaccountable" does. Creating a "MyAiRobot" account in GitHub and then rejecting ownership over that account is where this starts to turn into a problem. We need to make a human responsible for these things at all times. Any human will do, as long as they agree to the consequences of this ownership. The overall goal here is for the responsible party to be strongly incentivized to encourage good behavior down the org chart. In much the same way the compliance team at a bank tends to pull strings in such in a way that the operations staff won't piss off the FDIC. We already have extensive means to pin AI activity to specific user principals. We do not need an entire revolution in authn protocols. There are more than enough existing tools to solve this problem. | |||||||||||||||||||||||
| |||||||||||||||||||||||
| ▲ | x401throaway 3 hours ago | parent | prev | next [-] | ||||||||||||||||||||||
I work at Proof, and we're working on x401 as a means for agentic authorization https://x401.proof.com/spec/latest/#abstract in a nutshell: * a website that wants to authorize who you are (say, to book a flight or sign a waiver for go kart rental) * the endpoint returns 401 and defines in a header what info it needs about you (over 18? you're actually John Doe? etc.) on the proof side specifically, we're putting IAL2 verification in front of this https://pages.nist.gov/800-63-3-Implementation-Resources/63A... pretty cool stuff, its early days but its a strong way to ensure there's a human authorizing sensitive actions an agent is taking on your behalf | |||||||||||||||||||||||
| |||||||||||||||||||||||
| ▲ | ChrisArchitect 4 hours ago | parent | prev | next [-] | ||||||||||||||||||||||
Blog post with context: https://openid.net/new-whitepaper-tackles-ai-agent-identity-... | |||||||||||||||||||||||
| ▲ | cgeier 5 hours ago | parent | prev | next [-] | ||||||||||||||||||||||
Sorry for the heavy edit of the title, the original "Identity Management for Agentic AI: The new frontier of authorization, authentication, and security for an AI agent world" is much too long. | |||||||||||||||||||||||
| |||||||||||||||||||||||
| ▲ | canadiantim 5 hours ago | parent | prev | next [-] | ||||||||||||||||||||||
Executive Summary (from the linked pdf) The rapid rise of AI agents presents urgent challenges in authentication, authorization, and identity management. Current agent-centric protocols (like MCP) highlight the demand for clarified best practices in authentication and authorization. Looking ahead, ambitions for highly autonomous agents raise complex long-term questions regarding scalable access control, agent-centric identities, AI workload differentiation, and delegated authority. This whitepaper is for stakeholders at the intersection of AI agents and access management. It outlines the resources already available for securing today’s agents and presents a strategic agenda to address the foundational authentication, authorization, and identity problems pivotal for tomorrow’s widespread autonomous systems. | |||||||||||||||||||||||
| ▲ | nephihaha 5 hours ago | parent | prev [-] | ||||||||||||||||||||||
Is the OpenID Foundation connected to the Open Society group? | |||||||||||||||||||||||
| |||||||||||||||||||||||