AgentPassport
A managed issuer and verifier for open agent credentials, bounded delegation and revocation with enterprise-owned policy and keys.
The supplied research confirms a maintained open agent-trust protocol with software libraries and a draft specification, plus well-funded proprietary agent-identity products. It finds no reviewed commercial managed issuer for the open protocol, but adoption, interoperability and demand for an independent trust anchor remain unproven.
AgentPassport registers an organization, verifies an authorized issuer administrator, mints a signed credential for an agent and records bounded delegation, expiry and revocation. Downstream verifiers receive cryptographic validity and policy context; they still decide whether a particular action is permitted.
Organization verification, issuer authorization, key custody, agent registration, credential issuance, delegation, presentation, verification, policy evaluation, action approval, execution and revocation readback remain separate. A valid signature proves control of a key under the recorded scheme, not who operated the agent or whether its request is safe.
The first release should pilot verifier-only interoperability and short-lived sandbox credentials. It excludes global identity claims, financial authorization, autonomous key recovery and production trust-anchor status before independent security review.
Identity, platform-security or agent-governance leader at an enterprise that needs verifiable machine delegation across independently operated tools
Issuance and verification can scale through software once governance and trust are established.
Portable identity can improve accountability, while a central issuer can become a concentrated trust and surveillance risk.
The record contains three cross-references and six inbound links but no supplied cross-vertical cluster.
A maintained open protocol exists, commercial agent-identity demand is validated and managed lifecycle operations can scale.
Delivery is ULTRA, protocol adoption is unproven, trust-anchor and key-custody risk are severe, and proprietary competitors can define alternate standards.
Discussion
No comments yet — be the first to weigh in.
