Identity Brief

Issue 01 · 2 October 2026

Flow 05 · Delegation

Give the agent its own name.

The person signs in. The software that acts for them gets a different credential: one API, a scope, an actor claim, a key, and an end. NIST’s 2026 work on this is a demo of that idea. I wouldn’t wait on it to invent a new protocol.

Watch for

  • sub is the person. act.sub is the agent. A log that keeps only one of those is missing half the story.
  • DPoP (RFC 9449) means a copied bearer token fails the next call, because the caller also has to prove they hold the key.
  • When a remote MCP server requires auth, it’s the resource server. The thing hosting the agent is the OAuth client.

Failure modes

  • Pasting the person’s refresh token, session cookie, or API key into the agent. Then you can’t tell them apart, and you can’t revoke one without the other.
  • A token aimed at every API you own, living for days.
  • An agent with no owner. When it should be turned off, nobody’s name is on it.