Glossary · Identity and trust

Reputation scoring (agents)

Rating how far to trust an agent or its provider from observed behaviour and history. No standard defines it, so each service builds its own model.

Reputation scoring is the practice of rating how far to trust an agent, or the provider behind it, based on how it has behaved over time.

Inputs. A score is built from what a service can observe about an identity: past requests and their outcomes, request rates and patterns, failed authentication, and abuse reports. The A2A specification asks agents to log security-relevant events such as authentication failures and authorization denials, and to monitor for unusual patterns such as rapid task creation or excessive cancellations. Those logs are the raw material for a score.

An existing example from the web. Bot management services already score traffic. Cloudflare assigns each request a bot score from 1 to 99, where 1 means the request is almost certainly automated and 99 means it almost certainly came from a person. Sites use the score in firewall rules to block, challenge or allow requests. That score answers “is this automated?” Agent reputation asks a different question: given that this is an identified agent, does it tend to behave well?

Identity comes first. A score is only useful if it sticks to something the agent cannot shed. The Web Bot Auth draft notes that User-Agent strings can be spoofed, and that cloud IP addresses pass through layers of ownership and may carry earlier reputation history, so they bind poorly to any one operator. Cryptographic identity, such as requests signed with HTTP Message Signatures or a signed Agent Card, gives a score a stable key to attach to. The IETF Web Bot Auth working group standardizes that authentication step, but its charter lists tracking or assigning reputation to bots as out of scope. Reputation is left to each service.

How a score is used. A score is an input to a policy decision, typically allow, ask for more proof, or refuse, and a service should be able to explain which signals drove it. Emissar’s Verify module plans to combine card signatures, provider identity and request history into that kind of verdict. Status: In development.

Neighbouring terms. Know Your Agent (KYA) is the wider check that reputation feeds. Bot detection scores whether traffic is automated at all.

Sources

  1. A2A Protocol Specification, section 13.4: General Security Best Practices (accessed )
  2. Cloudflare documentation: Bot scores (accessed )
  3. IETF Web Bot Auth (webbotauth) working group charter (accessed )
  4. IETF draft: HTTP Message Signatures for automated traffic (draft-ietf-webbotauth-httpsig-protocol) (accessed )