Agent Passport System, an IETF Internet-Draft
This individual Internet-Draft proposes what no adopted standard yet provides: a cryptographic identity for an agent, a signed binding to the principal it acts for, and delegation chains that can only narrow. It defines bindings for Model Context Protocol tool calls. It is an individual submission, not a working group product, so it binds nobody.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AAL-2026-0013
- Kind
- Draft in progress
- Jurisdiction
- Global
- Last verified
- Added
- The draft defines Ed25519 agent passports and separately signed principal bindings.
- It defines delegation chains that cannot widen across scope, spend, depth, time, reputation, values or reversibility.
- It defines bindings for Model Context Protocol tool calls and imported OAuth identity assertion authorization grants.
- The version checked is draft-pidlisnyi-aps-03, dated 18 July 2026.
Dimension by dimension
4 dimensions, each one stated, silent or open
Identity, Delegation, Limits, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- IdentityStated
- An agent holds its own signing key and a passport, rather than borrowing a user's session.IETF Datatracker, draft-pidlisnyi-aps-03, primary source, 18 July 2026.
- DelegationStated
- Authority passes down a chain that may only narrow, which is the attenuation property missing from OAuth.IETF Datatracker, draft-pidlisnyi-aps-03, primary source, 18 July 2026.
- LimitsStated
- Spend, depth, time and reversibility are first class constraints carried in the chain rather than enforced by each tool separately.IETF Datatracker, draft-pidlisnyi-aps-03, primary source, 18 July 2026.
- AccountabilityStated
- Signed action receipts are proposed as evidence produced at policy enforcement boundaries.IETF Datatracker, draft-pidlisnyi-aps-03, primary source, 18 July 2026.
Figures
Every number, with who measured it and when
- 7 dimensions
Constraint dimensions a delegation chain may not widen across
IETF Datatracker, draft-pidlisnyi-aps-03, primary source, as of .
What it changes
For a team deploying an agent
Do not implement this as a standard. Read it as the clearest published statement of what a complete agent authority record would contain, and use its seven dimensions as a checklist against whatever you built. If your agent's authority cannot be narrowed when it hands work to another agent, this draft explains the gap you have.
Sources
What this record was verified against
- IETF Datatracker, draft-pidlisnyi-aps-03Primary · 18 July 2026
Related
Records that sit beside this one
RFC 8693, OAuth 2.0 token exchange
Global · verified 15 September 2026
The specification defines how to request and obtain security tokens from OAuth 2.0 authorization servers, including tokens employing impersonation and delegation.
How does a sub agent's authority attenuate
Global · verified 15 September 2026
RFC 8693 lets a token record that one party is acting for another, but does not require the exchanged token to be narrower.
Who is liable when a delegated agent exceeds its mandate
Global · verified 15 September 2026
The EU AI Act allocates duties to providers and deployers, and does not address an agent acting beyond its instructions.
Does a spending limit belong to the agent or to the principal
Global · verified 15 September 2026
The Visa Trusted Agent Protocol addresses recognising an approved agent and its intent, and does not itself carry a spending ceiling.
Can an agent hold a credential of its own
Global · verified 15 September 2026
NIST SP 800-63-4 states that for that publication, person refers only to natural persons.
No international standard governs revoking an agent's authority
Global · verified 15 September 2026
The Model Context Protocol relies on short lived access tokens and audience validation rather than on any revocation mechanism for an agent.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AAL-2026-0013 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Authority Ledger (as of 15 September 2026), agent passport system, an ietf internet-draft.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). Agent Passport System, an IETF Internet-Draft. Agent Authority Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0013-agent-passport-system-internet-draft
- MLA
- "Agent Passport System, an IETF Internet-Draft." Agent Authority Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0013-agent-passport-system-internet-draft.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "Agent Passport System, an IETF Internet-Draft." Agent Authority Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0013-agent-passport-system-internet-draft.
- Permalink
- https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0013-agent-passport-system-internet-draft
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any NIST, IETF or MCP publication.
Back to the full ledger, or every record for Global and every draft in progress record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.