Credentials for Code: Identity Infrastructure for Non-Human Actors
Okta, Microsoft, Visa, Mastercard and NIST are racing to give software agents a verifiable passport, and the breach record explains why AI agent identity has become the most urgent layer of the stack.
Is the agent actually what the agent claims to be?
By the numbers
- Organizations applying equal security controls to agents and humans
- 34%
- Okta 'AI Agents at Work 2026' report, cited in the Agent SSO release · [1] Okta newsroom
- Machine identities per human employee in financial services
- 96:1
- Sean Neville via a16z crypto; single-source assertion · [3] a16z crypto
- ERC-8004 agents registered, Jan. 29 to April 9, 2026
- 10,000
- 67 carried service records; 628 had reputation feedback · [7] arXiv (2606.12128)
- Conditional Access templates shipped with Entra Agent ID
- 4
- Two block high-risk agents or their user accounts; two govern autonomous and on-behalf-of flows · [4] Big Hat Group
34% of organizations apply the same security controls to AI agents as they do to human workers, Okta said in an Aug. 24, 2026, press release citing its “AI Agents at Work 2026” report. Two-thirds of enterprises, in other words, hold software that reads mail, moves money and writes code to a looser standard than the intern it replaced. Mastercard chief executive Michael Miebach compressed the AI agent identity problem into nine words on June 9, 2026, in a TheStreet account of his Yahoo Finance “Opening Bid” interview: “Is the agent actually what the agent claims to be?” His question holds the whole discipline in miniature. Authentication answers who is calling. Authorization answers what the caller may do. Delegation answers on whose behalf, under which constraints and for how long, and delegation is the part the current stack handles worst.
AI Agent Identity by the Numbers: 96 Machines per Human
Machine identities already outnumber people inside the institutions agents most want to enter. Sean Neville, the Circle co-founder who now runs Catena Labs, said in a16z crypto’s Jan. 7, 2026, trends essay that non-human identities in financial services outnumber human employees 96 to one. The essay presents the ratio as assertion, from an executive whose company sells agent banking, and a supporting study remains to be produced, so the figure stands as a single-source claim. Its direction is plausible. Service accounts, API keys and workload identities have exceeded headcount at large banks for years; agents add a class of identity that also reasons, negotiates and spends.
Sequoia had made identity the first pillar a year before. “The Agent Economy,” published May 14, 2025, in the firm’s Inference newsletter, named persistent identity as the foundation of an agent economy and pointed to decentralized identifiers and verifiable credentials as candidate primitives. Nine months later the federal standards body agreed. NIST’s Center for AI Standards and Innovation announced the AI Agent Standards Initiative on Feb. 17, 2026, with three pillars: industry-led standards development with U.S. leadership in international bodies; community-led open-source protocol stewardship; and research on agent security and identity. Two requests for information anchored the launch, a CAISI RFI on agent security due March 9 and an Information Technology Laboratory concept paper on agent identity and authorization due April 2, with listening sessions on sector-specific adoption barriers beginning in April. Identity, in this framing, is the precondition for interoperability. A protocol can route a request between agents; a credential decides whether the recipient should act on it.
Okta Agent SSO and Microsoft Entra Agent ID: The Enterprise Passports
Two vendors now sell the passport. Okta made Agent SSO generally available Aug. 24, 2026, three months after “Okta for AI Agents” reached general availability in May, and built it on Cross App Access, which the company describes as “an open, vendor-neutral protocol that allows identity security to follow agents dynamically across applications.” The design intent is portability: an agent authenticated once by the identity provider carries a verifiable session into every downstream application, and the provider keeps the power to revoke it centrally across a base Okta puts at more than 20,000 customers. Microsoft reached general availability with Entra Agent ID in April 2026. A May 10, 2026, analysis by the consultancy Big Hat Group describes Agent Identity Blueprints as reusable templates that fix owners, sponsors, access envelopes, audit and lifecycle controls for each agent; two OAuth 2.0 patterns, on-behalf-of for agents that act as a user and autonomous for agents that act as themselves; four Conditional Access templates, including policies that block high-risk agent identities and high-risk sponsoring user accounts; and a federation pattern for agents hosted on Amazon Bedrock or Google Cloud. Billing meters for agent governance, the same post notes, have run since the first quarter of 2026. Developer-facing platforms such as WorkOS compete for the same workloads at the API layer. The strategic question is which of them becomes the policy decision point. Whoever holds the agent’s credential holds the kill switch.
| Mechanism | Owner | Scope | Date | Evidence of use |
|---|---|---|---|---|
| Agent SSO with Cross App Access | Okta | Enterprise single sign-on for agents across SaaS applications | GA Aug. 24, 2026 | 20,000+ customers eligible (vendor figure) |
| Entra Agent ID | Microsoft | Blueprints, on-behalf-of and autonomous OAuth, Conditional Access | GA April 2026 | Four policy templates; billing meters since Q1 2026 (Big Hat Group) |
| Trusted Agent Protocol | Visa | Merchant-side recognition of authorized agents at checkout | October 2025 | 10+ partners; “hundreds” of agentic transactions by Dec. 18, 2025 |
| Agent Pay for Machines | Mastercard | Verifiable Intent credentials, spend limits, multi-rail settlement | June 10, 2026 | 30+ initial participants |
| Know Your Agent (KYA) | Skyfire | Agent identity bound to funded wallets and per-agent budgets | Funding Oct. 24, 2024 | Visa pilot partner; Agent Pay for Machines participant |
| ERC-8004 registries | Ethereum community (EIP authors from MetaMask, Ethereum Foundation, Google, Coinbase) | On-chain identity, reputation and validation registries | Mainnet Jan. 29, 2026 | 10,000 registrations; 67 with service records (arXiv, June 10, 2026) |
| cloudflare.pay handles | Cloudflare | Agent identity handles paired with Cloudflare Wallets | Aug. 4, 2026 | Reported by Search Engine Journal, Aug. 12, 2026 |
Delegation Chains and Scoped Mandates: Agent Authorization in Practice
The hard problem sits between the user and the tool. Consider the chain: a person authorizes an assistant, the assistant spawns a sub-agent, and the sub-agent calls a tool that holds its own credential to a database. Each hop should attenuate scope. In practice each hop inherits it. Microsoft’s split between on-behalf-of and autonomous flows is the first vendor acknowledgment that these are different legal objects: an OBO token binds the agent’s action to a human principal and that principal’s entitlements, while an autonomous token makes the agent itself the accountable party, sponsored by a human owner recorded in the blueprint. Payment networks reached the same conclusion from the merchant’s side. Visa introduced its Trusted Agent Protocol in October 2025 with more than 10 partners so that merchants could recognize an authorized agent at checkout, and reported on Dec. 18, 2025, that partners had completed “hundreds” of controlled real-world agentic transactions across a program of more than 100 participants. Mastercard’s Agent Pay for Machines, launched June 10, 2026, in Purchase, New York, with more than 30 initial participants, credentials agents with what the company calls Verifiable Intent, attaches programmatic spend limits, and settles across cards, accounts and stablecoins. Cloudflare supplied an address book on Aug. 4, 2026, pairing its Wallets product with cloudflare.pay identity handles, according to Search Engine Journal’s Aug. 12 report. Four properties define a usable mandate: a named principal, an enumerated scope, a spending or action ceiling, and an expiry. Revocation must reach every hop. Audit must reconstruct the chain afterward.
Know Your Agent: NIST, KYA and the Standards Track
Banking compliance lent the phrase its name; public-key cryptography lent its mechanics. The a16z crypto essay of Jan. 7 defines the requirement as cryptographically signed credentials that link an agent to its principal, its constraints and its liability, the way a credit score links a borrower to a repayment history. Skyfire, which had raised $9.5 million in total by Oct. 24, 2024, according to The Block, with Circle, Ripple, Coinbase Ventures and a16z CSX among its backers, sells KYA as a bundle: an agent identity, a wallet funded by card, ACH, wire or USDC, and a per-agent budget. Visa named Skyfire among its U.S. pilot partners on Dec. 18, 2025, and Mastercard listed it among the launch participants of Agent Pay for Machines. The federal track runs slower and wider. NIST’s concept paper on identity and authorization closed for comment April 2, 2026, and the initiative’s second pillar commits the agency to stewarding open-source protocols, which places the OAuth extensions now being drafted by identity vendors inside a standards process with a public record. Standards take years. Breaches take days.
On-Chain Registries: ERC-8004 and the Shallow-Adoption Problem
Ethereum’s answer is a registry. EIP-8004, titled “Trustless Agents,” was created Aug. 13, 2025, by Marco De Rossi of MetaMask, Davide Crapis of the Ethereum Foundation, Jordan Ellis of Google and Erik Reppel of Coinbase, and it specifies three registries: an identity registry built on ERC-721 tokens, a reputation registry and a validation registry. Mainnet launch targeted Jan. 29, 2026. Ten weeks of on-chain data then produced the first audit. Mafrur and Khusumanegara, in a paper posted to arXiv on June 10, 2026, counted 10,000 registered agents between Jan. 29 and April 9, 2026, of which 67 carried service records, 628 had received reputation feedback and 19 combined full metadata, services, feedback and cross-chain presence. Concentration was severe: 394 wallets owned every agent, the top 10 wallets held 51.40% of registrations, and a single client supplied 65.82% of all feedback. Their verdict, that early adoption is “registration-heavy but operationally shallow,” is the most precise sentence yet written about on-chain agent identity. A registry proves that someone minted a token. It proves little about who stands behind the agent or what the agent may do. Reputation systems fed by one client measure that client.
Salesloft Drift: The Cautionary Case for Revocation
The breach identity architects cite most often began with a chatbot’s OAuth tokens. Between Aug. 8 and Aug. 18, 2025, the actor Google tracks as UNC6395 used stolen Salesloft Drift OAuth tokens to bulk-export Cases, Accounts, Opportunities and Users objects from Salesforce instances and then to harvest AWS access keys, Snowflake tokens and passwords from the exported text, Google’s Threat Intelligence Group reported Aug. 26, 2025. Salesloft revoked the tokens Aug. 20. Salesforce removed Drift from AppExchange. Google revoked Drift Email integration tokens Aug. 28 and advised customers to treat every authentication token connected to Drift as potentially compromised. Three lessons transfer directly to agent identity. Bearer tokens with long lifetimes and broad scope turn a single integration into a master key, and scope attenuation at each hop would have confined the export. Twelve days separated first abuse from first revocation, so the credential lifecycle, meaning expiry, rotation and the kill switch, is the control that matters most. Audit logs, in this case Salesforce’s, were what surfaced the export and what let victims size it.
What to Watch
Four signals will show whether AI agent identity matures or stalls. First, adoption of Cross App Access beyond Okta’s own customer base, since a vendor-neutral protocol earns that adjective through rival implementations. Second, what NIST publishes from the identity and authorization concept paper and the listening sessions that began in April 2026; a reference architecture for delegation chains would be the initiative’s most valuable output. Third, the ratio of ERC-8004 agents with service records to agents registered, which stood at 67 to 10,000 on April 9, 2026; a registry that stays near that ratio is a vanity metric. Fourth, whether payment networks and identity providers converge on a shared credential format or fork into card-side and enterprise-side passports. Miebach’s question will be answered by whichever layer can prove an agent’s principal, scope and expiry at the moment of action. The layer that answers fastest wins the workloads.
Sources
13 cited · AP style
- “Okta Brings First-Class Identity to AI Agents With Agent SSO”, Okta newsroom, Aug. 24, 2026. okta.com
- Damilola Esebame, “Mastercard CEO Voices Concerns Over AI Agentic Commerce”, TheStreet, June 9, 2026. thestreet.com
- a16z crypto editorial team, “AI in 2026: 3 Trends”, a16z crypto, Jan. 7, 2026. a16zcrypto.com
- “Microsoft Entra Agent ID Reaches GA”, Big Hat Group, May 10, 2026. bighatgroup.com
- “Announcing the AI Agent Standards Initiative”, NIST, Feb. 17, 2026. nist.gov
- “The Agent Economy: Building the Foundations”, Inference by Sequoia, May 14, 2025. inferencebysequoia.substack.com
- Mafrur and Khusumanegara, “Measuring Early ERC-8004 Adoption on Ethereum”, arXiv (2606.12128), June 10, 2026. arxiv.org
- Marco De Rossi, Davide Crapis, Jordan Ellis and Erik Reppel, “EIP-8004: Trustless Agents”, Ethereum Improvement Proposals, Aug. 13, 2025. eips.ethereum.org
- Google Threat Intelligence Group, “Widespread Data Theft Targets Salesforce Instances via Salesloft Drift”, Google Cloud blog, Aug. 26, 2025. cloud.google.com
- “Visa and Partners Complete Secure AI Transactions, Setting the Stage for Mainstream Adoption in 2026”, Visa Investor Relations, Dec. 18, 2025. investor.visa.com
- “Mastercard Launches Agent Pay for Machines”, Mastercard newsroom, June 10, 2026. mastercard.com
- “Cloudflare Gives AI Agents Wallets That Pay for What They Access”, Search Engine Journal, Aug. 12, 2026. searchenginejournal.com
- “Coinbase Ventures and a16z's CSX Bring Skyfire's Total Funding to $9.5 Million”, The Block, Oct. 24, 2024. theblock.co
Related reading
Hijack and Hazard: OWASP's Agentic Top 10, Mapped to the Stack
OWASP's Top 10 for Agentic Applications reads as a map of the agent stack, and AI agent security spending, breach data and the EchoLeak flaw show which layer owes which control.
8 min · 14 sources
Breaches by Bot: What 2026's Evaluation Escapes Teach Infrastructure Builders
The OpenAI Hugging Face incident, Anthropic's three evaluation breaches and Meta's disclosure turned the summer of 2026 into a curriculum on agent containment, credential hygiene and monitoring.
7 min · 10 sources
Mandates and Machines: AP2, ACP, x402 and the Payment Protocol Contest
Six agent payment protocols launched in twelve months; this comparison dates each one, tabulates scope, settlement rails and governance, and argues that the signed mandate is the primitive that decides the contest.
8 min · 14 sources
Rules for Robots: The EU AI Act, NIST's Agent Initiative and the Governance Gap
AI agent regulation trails the technology: the EU AI Act's Digital Omnibus pushed high-risk duties to 2027 and 2028, NIST chose standards over statute, and enterprise governance frameworks are filling the gap.
7 min · 13 sources