Skip to main content

No international standard governs revoking an agent's authority

Nothing published as a standard says how to withdraw an agent's authority once it has been granted, or how a withdrawal propagates to work the agent has already handed on. What exists is expiry, token lifetimes and certificate revocation lists, all of which were designed for services rather than for a chain of delegated agents.

The verdict

Absent

The ledger searched and found no instrument. The record says where it looked and when.

Where the ledger looked: Checked on 15 September 2026. Read the Model Context Protocol authorization sections of 18 June 2025 and 28 July 2026, which require token validation and short lifetimes but define no revocation endpoint or propagation rule for agents. Read the OAuth 2.1 Internet-Draft and RFC 8693 token exchange, neither of which defines withdrawal of a delegated actor's authority. Read the SPIFFE overview, where withdrawal is expiry of a short lived document. Searched the IETF Datatracker for agent revocation work and found only individual Internet-Drafts, no working group output. ISO's own catalogue pages refused automated requests, so ISO material was checked through the IEC catalogue entry for ISO/IEC 42001, which is a management system standard and names no agent revocation control.

Key facts

What the sources say

Record ID
AAL-2026-0030
Kind
Standard or protocol
Jurisdiction
Global
Last verified
Added
  • The Model Context Protocol relies on short lived access tokens and audience validation rather than on any revocation mechanism for an agent.
  • SPIFFE withdraws authority by letting a short lived identity document expire, which cannot stop work already delegated onward.
  • RFC 8693 defines how authority is exchanged but not how an exchanged authority is withdrawn.
  • The Agent Passport System Internet-Draft is an individual submission and not an adopted standard, so its chain semantics bind nobody.
  • Regulators name stopping an agent as a control, but none points at a standard that implements it.

Dimension by dimension

2 dimensions, each one stated, silent or open

Revocation, Delegation. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

RevocationSilent
No published standard defines how an agent's authority is withdrawn, or how a withdrawal reaches sub agents and tools that already hold a delegated grant.Model Context Protocol specification 2026-07-28, Authorization, primary source, 28 July 2026.
DelegationSilent
Delegation is standardised in one hop only, which is why revocation across a chain has nothing to attach to.RFC Editor, RFC 8693, primary source, 1 January 2020.

What it changes

For a team deploying an agent

Assume you cannot recall an agent's authority and design so you do not need to. Short token lifetimes, narrow audiences and a kill path you have actually tested are the whole answer today, and any vendor claiming standards based agent revocation should be asked which standard, by number.

Sources

What this record was verified against

  1. Model Context Protocol specification 2026-07-28, AuthorizationPrimary · 28 July 2026
  2. RFC Editor, RFC 8693Primary · 1 January 2020
  3. SPIFFE documentationPrimary · 15 September 2026

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AAL-2026-0030 is permanent and is never reused.

In a sentence
According to the GAGE Agent Authority Ledger (as of 15 September 2026), no international standard governs revoking an agent's authority.
APA
GAGE (Global Academy of Generative-AI Education). (2026). No international standard governs revoking an agent's authority. Agent Authority Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0030-no-international-standard-for-agent-revocation
MLA
"No international standard governs revoking an agent's authority." Agent Authority Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0030-no-international-standard-for-agent-revocation.
Chicago
GAGE (Global Academy of Generative-AI Education). "No international standard governs revoking an agent's authority." Agent Authority Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0030-no-international-standard-for-agent-revocation.
Permalink
https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0030-no-international-standard-for-agent-revocation

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any NIST, IETF or MCP publication.

Back to the full ledger, or every record for Global and every standard or protocol record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.