Skip to main content

NIST SP 800-63-4 Digital Identity Guidelines

The United States identity baseline sets assurance levels for enrolment, authentication and federation across online services. It is the document an agent identity scheme has to build on, and it is also the document that explains why agents do not fit: it says that for this publication person refers only to natural persons, and it excludes machine to machine authentication from its scope.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AAL-2026-0003
Kind
Standard or protocol
Jurisdiction
United States
Last verified
Added
  • The guidelines apply to all online services for which some level of assurance in a digital identity is required, regardless of the constituency.
  • The publication states that for this publication, person refers only to natural persons.
  • It says it does not address machine to machine authentication, interconnected devices such as Internet of Things devices, or access to Application Programming Interfaces.
  • AI agents are not named anywhere in the guidelines.

Dimension by dimension

2 dimensions, each one stated, silent or open

Identity, Delegation. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

IdentityStated
It defines identity assurance, authenticator assurance and federation assurance levels for people, which is the vocabulary any agent scheme will be measured against.NIST SP 800-63-4, primary source, 26 August 2025.
DelegationSilent
The guidelines do not cover a non human actor holding or exercising a person's authority, and they exclude machine to machine authentication from scope.NIST SP 800-63-4, primary source, 26 August 2025.

What it changes

For a team deploying an agent

If somebody tells you their agent is compliant with the federal identity guidelines, ask which clause. The guidelines govern how a person proves who they are, not how software acts for that person, so the assurance level of your human sign in says nothing about what the agent it launched is allowed to do.

Sources

What this record was verified against

  1. NIST SP 800-63-4Primary · 26 August 2025

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AAL-2026-0003 is permanent and is never reused.

In a sentence
According to the GAGE Agent Authority Ledger (as of 15 September 2026), nist sp 800-63-4 digital identity guidelines.
APA
GAGE (Global Academy of Generative-AI Education). (2026). NIST SP 800-63-4 Digital Identity Guidelines. Agent Authority Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0003-nist-sp-800-63-4-digital-identity-guidelines
MLA
"NIST SP 800-63-4 Digital Identity Guidelines." Agent Authority Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0003-nist-sp-800-63-4-digital-identity-guidelines.
Chicago
GAGE (Global Academy of Generative-AI Education). "NIST SP 800-63-4 Digital Identity Guidelines." Agent Authority Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0003-nist-sp-800-63-4-digital-identity-guidelines.
Permalink
https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0003-nist-sp-800-63-4-digital-identity-guidelines

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any NIST, IETF or MCP publication.

Back to the full ledger, or every record for United States and every standard or protocol record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.