Glossary · Identity and trust

Credential revocation

Ending a credential's validity before it expires, and the ways verifiers find out: revocation lists, status queries, token revocation and status lists.

Credential revocation is the act of declaring a credential invalid before its scheduled expiry, together with the mechanisms verifiers use to learn that it happened.

Why it exists. A credential is issued expecting to last until it expires, but circumstances change. RFC 5280 lists the classic reasons a certificate is revoked early: a change of name, a change in the relationship between subject and issuer, such as an employee leaving, and a compromised or suspected compromised private key. For agents, a common case is a principal withdrawing authority it gave an agent.

How verifiers find out.

Credential Mechanism
X.509 certificates Certificate revocation lists (CRLs), time-stamped and signed by the issuer (RFC 5280); online status queries through OCSP (RFC 6960)
OAuth tokens A revocation endpoint the client calls (RFC 7009); token introspection returns "active": false for a token that is no longer valid (RFC 7662)
W3C verifiable credentials A credentialStatus entry pointing into a published bitstring, one bit per credential (Bitstring Status List v1.0)

Freshness. Revocation only protects a verifier that checks. RFC 5280 notes that CRL-based revocation is only as current as the CRL issue period, which may be an hour, a day or a week. Online checks shorten that window at the cost of a network call per verification. The W3C status list format publishes many credentials’ status in one compressed list, which its specification describes as privacy-preserving. Short lifetimes reduce how much rests on revocation: AP2, for example, recommends setting a mandate’s expiry to the shortest time that lets the agent finish its task.

In A2A. The specification says agents should implement credential revocation mechanisms, and that clients must not use expired or revoked keys to verify Agent Card signatures. It leaves the revocation of credentials obtained through TASK_STATE_AUTH_REQUIRED to implementations, credential issuers and extensions.

Neighbouring terms. Key rotation replaces keys on a planned schedule; revocation withdraws a credential early because it should no longer be trusted.

Sources

  1. RFC 5280: Internet X.509 PKI Certificate and CRL Profile, section 3.3: Revocation (accessed )
  2. RFC 6960: X.509 Internet PKI Online Certificate Status Protocol (OCSP) (accessed )
  3. RFC 7009: OAuth 2.0 Token Revocation (accessed )
  4. RFC 7662: OAuth 2.0 Token Introspection (accessed )
  5. W3C Bitstring Status List v1.0 (W3C Recommendation, 15 May 2025) (accessed )
  6. A2A Protocol Specification, section 13.4: General Security Best Practices (accessed )
  7. A2A Protocol Specification, section 8.4.3: Signature Verification (accessed )
  8. AP2 specification v0.2 (accessed )