Glossary · Identity and trust

Agent provider

The organization that builds or operates an AI agent. A2A Agent Cards name it in the provider field, but only keys and domains can back that claim.

An agent provider is the organization that builds or operates an AI agent and is accountable for how that agent behaves.

In A2A. The Agent Card has an optional provider object, AgentProvider in a2a.proto. When present it must carry two fields: organization, the provider’s name, and url, a link to its website or documentation. Emissar’s own published card declares:

{"provider": {"organization": "Emissar", "url": "https://emissar.ai"}}

The field is self-asserted. Anyone can type any organization name into a card. A2A gives clients two ways to test the claim. HTTPS shows which domain served the card, and a signed Agent Card proves that the holder of a particular key published it. The specification lets clients keep a trusted key store for known agent providers, but it does not define how a key is bound to an organization. Linking a signature to the named provider stays a trust decision for the client.

Provider and principal. The provider operates the agent. The principal is the person or business the agent acts for in a given task. Illustrative: a travel company’s booking assistant has one provider, the travel company, and acts for thousands of different travellers. A check on the provider says nothing about whether a particular traveller approved a particular booking.

Providers in other standards. AP2’s agent authorization model describes a “Trusted Agent Provider” approach, in which the verifier trusts the agent’s provider to vouch that the user approved a mandate. The AP2 documentation notes the cost: the verifier has to establish trust with every provider separately. The IETF Web Bot Auth draft proposes that automated clients sign every request with a private key owned by their provider, so a website can identify the operator behind the traffic.

Neighbouring terms. Agent identity combines three facts: the agent, its provider and its principal. Know Your Agent (KYA) is the business process that checks a provider before its agent is trusted.

Sources

  1. A2A protocol definition (a2a.proto): AgentCard, AgentProvider (accessed )
  2. A2A Protocol Specification, section 8.4: Agent Card Signing (accessed )
  3. AP2 documentation: Agent Authorization (accessed )
  4. IETF draft: HTTP Message Signatures for automated traffic (draft-ietf-webbotauth-httpsig-protocol) (accessed )