Agent identity
Agent identity is the verifiable answer to which software agent is making a request, which organization operates it, and on whose behalf it acts.
Agent identity is the set of verifiable facts that tells a counterparty which software agent is making a request, which organization operates it, and which person or business it is acting for.
Three questions. Identity for agents splits into separate claims, and each needs its own evidence:
| Question | Typical evidence |
|---|---|
| Which agent is this? | A key the agent signs or authenticates with; its Agent Card |
| Who operates it? | The card’s provider field, a signature from the provider’s key, the domain that serves the card |
| Whom does it act for? | A delegated credential, such as an OAuth token or a mandate |
In A2A. The Agent Card names the agent and its provider (organization and url). Those fields are self-asserted. A card may carry JWS signatures over its canonical form, which proves that the holder of the signing key published it, and HTTPS shows which domain served it. For the connection itself, clients should validate the server’s TLS certificate. Servers must authenticate every request using the schemes the card declares in securitySchemes: API key, HTTP authentication, OAuth 2.0, OpenID Connect or mutual TLS. The client obtains those credentials out of band. The specification keeps identity in these standard web layers and does not define identity fields inside A2A messages.
Delegation. When an agent needs authorization partway through a task, it can move the task to TASK_STATE_AUTH_REQUIRED. The specification says that this state change is not itself authorization, and it leaves the scope, format, validity and revocation of the resulting credential to implementations and extensions. For credentials passed in-band along a chain of agents, it recommends binding each credential to the agent that requested it, so other agents in the chain cannot reuse it.
On the wider web. The IETF Web Bot Auth working group is standardizing cryptographic authentication for automated clients that visit sites built for people, using HTTP Message Signatures. Its charter leaves out agent-to-agent interfaces and authentication of the end user. Those parts of agent identity still depend on implementations and extensions.
Neighbouring terms. Know Your Agent (KYA) is the business process that checks these facts before acting. A signed Agent Card is the main identity artifact A2A itself defines.
Sources
- A2A Protocol Specification, section 7: Authentication and Authorization (accessed )
- A2A Protocol Specification, section 8.4: Agent Card Signing (accessed )
- A2A protocol definition (a2a.proto): AgentCard, AgentProvider, SecurityScheme (accessed )
- IETF Web Bot Auth (webbotauth) working group charter (accessed )
- IETF draft: HTTP Message Signatures for automated traffic (draft-ietf-webbotauth-httpsig-protocol) (accessed )