I-D Action: draft-prakash-aip-01.txt
| Newsgroups | gmane.ietf.announce |
|---|---|
| Message-ID | <178714257018.768978.2000879627260571261@dt-datatracker-7c6ddbc678-86d5j> |
Internet-Draft draft-prakash-aip-01.txt is now available. Title: Agent Identity Protocol (AIP): Verifiable Delegation for AI Agent Systems Author: Sunil Prakash Name: draft-prakash-aip-01.txt Pages: 22 Dates: 2026-08-19 Abstract: This document specifies the Agent Identity Protocol (AIP), a protocol for verifiable, delegable identity for AI agent systems. AIP introduces Invocation-Bound Capability Tokens (IBCTs) that bind identity, authorization, scope constraints, and provenance into a single cryptographic artifact. Two token modes are defined: a compact mode using JSON Web Tokens (JWT) with Ed25519 signatures for single-hop interactions, and a chained mode using Biscuit tokens with append-only blocks and Datalog policy evaluation for multi-hop delegation chains. Protocol bindings are specified for the Model Context Protocol (MCP), Agent-to-Agent Protocol (A2A), and generic HTTP APIs. The protocol addresses authentication gaps in current AI agent infrastructure where a survey of approximately 2,000 MCP servers found all lacked authentication. This revision specifies a normative verification algorithm, defines the canonical policy encoding for chained mode, describes how AIP composes with workload identity systems such as SPIFFE, and maps AIP against the cross- organization delegation requirements enumerated in [I-D.reece-wimse-cross-org-delegation]. The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-prakash-aip/ There is also an HTML version available at: https://www.ietf.org/archive/id/draft-prakash-aip-01.html A diff from the previous version is available at: https://author-tools.ietf.org/iddiff?url2=draft-prakash-aip-01 Internet-Drafts are also available by rsync at: rsync.ietf.org::internet-drafts _______________________________________________ I-D-Announce mailing list -- [email protected] To unsubscribe send an email to [email protected]