Identity Brief

Issue 01 · 2 October 2026

Issue 01

Most access should come with an expiry.

That’s the short version. Agents need names of their own, passkeys finally have a spec you can cite, and a lot of access still never gets taken back.

Identity programs were built for a person. They join, they get a role, they leave. People still do that. They’re just not most of the accounts anymore, and they’re not the only thing that can click a button.

Passkeys are finally in a place where you can put them in a contract. On 25 August 2026 the W3C published Web Authentication Level 3 as a Recommendation. That’s the stable spec. Browsers had already been shipping most of it. Level 4 opened as a first public draft on 15 September, so if a vendor waves “Level 4 support” at you, smile and ask for Level 3.

OAuth 2.1 is what I’d build to, and it’s still an Internet-Draft. Draft 16, dated 3 September 2026, is pretty clear: PKCE with S256, no implicit grant, no password grant, redirect URIs matched exactly, and the authorization server has to send iss back on the redirect. The working group hopes to hand it to the IESG in December. I wouldn’t wait for an RFC number before turning implicit off.

Then there’s the agent problem. NIST’s Center for AI Standards and Innovation opened an AI Agent Standards Initiative on 17 February 2026, and the National Cybersecurity Center of Excellence published a concept paper and a project on using the identity standards we already have. It’s a demo, which is useful, and it isn’t a new protocol with a compliance date. What they’re pointing at is familiar: OAuth, OpenID Connect, SCIM, workload identity, and a record of which person asked and which piece of software did the thing.

Put those next to each other and the pattern is ordinary. A grant, for one API, held by a key, with an end. The rest of this site is the news around that, and some diagrams for when the acronyms pile up.

Person session
hours
Workload token
minutes
Agent grant
a task

On the wire

As of this issue. Where there’s a real source, it’s linked.

Standards

OAuth 2.1 reaches draft 16

Draft 16, out on 3 September, drops the plain PKCE method and makes the authorization server send iss on the redirect. There’s a new note on consent phishing too. Still a working-group draft, aimed at the IESG in December 2026. Not an RFC. The short list of what to actually do is on oauth.net/2.1: code flow, S256, exact redirects, and none of the old grants that put a token in the browser.

Walk the authorization-code flow

Standards

WebAuthn Level 4 enters public review

First public draft, 15 September 2026. The charter from a few days earlier doesn’t expect a Recommendation until late 2028. Worth skimming if you care about remote-desktop sign-in, or about hardening the PRF extension. I wouldn’t put it in a contract.

Agents

NIST is showing how to name an agent

The NCCoE hub is a lab project: take the identity standards we already have and apply them to software and AI agents. The February concept paper pulled in more than 600 comments, which mostly tells you people have opinions. CAISI’s initiative, announced 17 February, is the umbrella over that. Nothing new to comply with. Use OAuth, OpenID Connect, SCIM, workload identity, and write down who delegated to what.

Walk an agent delegation

Agents

MCP clients pick up DPoP

The 28 July 2026 MCP spec is the current one. Auth is still optional. If a server turns it on, that server is an OAuth resource server, and the client has to check iss when the authorization server sends it. The week of 25 September, the TypeScript SDK 2.1.0 release added DPoP on the client. Turn that on and a token lifted out of a log isn’t enough by itself.

Access

Machine identities are the population

Write-ups of ManageEngine’s 2026 PAM360 outlook put machine identities well ahead of people, about 25:1 in a lot of the survey and higher in some industries, and say almost nobody has the offboarding automated. I’d treat the exact ratios as a vendor survey. The direction is hard to argue with. The SCIM client, the cloud role, and the agent need an owner and a way to be turned off, same as a person.

Walk a workload token

Authenticators

Passkeys move from an option to the default path

Read CIAM changelogs from the first half of 2026 and passkeys stop looking like an advanced checkbox. A few products now start there and keep the password as the fallback. What’s left is the unglamorous part: getting people enrolled, a lost device, recovery, and the workforce apps where a synced passkey is the wrong answer.

Walk sign-in

Walk a flow

Seven diagrams. Step through them. The samples on the side are the shape of a call, not something you can replay.

Standards at a glance

The full board has the same dates, with a note on what I’d actually do with each one.

SpecStatus on 2 Oct 2026Use it for
OAuth 2.1 Draft 16 · 3 Sep 2026 Getting a token. Code flow, S256 PKCE, exact redirects.
OpenID Connect Final · widely deployed Turning the OAuth exchange into a login. That’s the ID token.
WebAuthn Level 3 Recommendation · 25 Aug 2026 Passkeys. The one to name in a contract.
DPoP · RFC 9449 RFC · Sep 2023 Sticking an access token to the client’s key.
SCIM · RFC 7644 RFC Creating accounts in SaaS, and disabling them when someone leaves.
NIST agent initiative Program · no standard yet A nudge to use the rows above for agents, too.