Agent identity is a verifiable, ideally cryptographic or attested identifier for a software agent — a way to recognise the agent and bind it to the code it runs, the principal it serves, and the credentials it holds.
Why it matters
You cannot authorise, audit, or revoke what you cannot identify. Agent identity is the anchor for the rest of KYA: delegation, scoped credentials, and revocation all reference the agent’s identity. Agents are also a distinct identity category that legacy non-human identity models were not built to handle, because they are ephemeral, delegate authority across trust boundaries, and act without a human present.
It relates to, but is not the same as, neighbouring concepts:
- Digital identity (NIST SP 800-63) covers identity proofing and authentication, largely for people and their authenticators. Agents need the analogous assurance, applied to a running system.
- Workload identity (SPIFFE) gives services cryptographic identities derived from what and where they are. This is a strong foundation for agent identity, though a workload ID alone does not express a principal or a mandate.
- Verifiable credentials (W3C) can express claims about an agent — who issued its identity, what it is, what it may do — in a tamper-evident form.
- Signed agent traffic (e.g. Cloudflare Web Bot Auth) lets a previously unknown agent prove cryptographically that it is a registered bot or agent.
Properties of a good agent identity
- Bound to code or configuration — not just a bearer secret, so impersonation is harder.
- Verifiable by a third party — the relying service can check it without trusting the agent’s assertion.
- Linked to a principal — resolves to an accountable party.
- Revocable — can be invalidated quickly.
- Narrowly scoped — identifies the agent, not a whole fleet, where possible.
How it works in practice
Modern agent identity reuses workload-identity machinery. SPIFFE issues a Verifiable Identity Document (SVID) that can be proven authentic and proven to belong to its presenter, with keys that are short-lived and rotated automatically — so the agent holds no static secret. Major identity providers now extend the idea to agents directly: Google Cloud’s agent identity is based on the SPIFFE standard, and Microsoft Entra Agent ID gives agents the same identity-driven protections as users and workloads.
The practical test is whether the identity binds the agent to a principal and a mandate, not just to a machine. A SPIFFE ID says what the workload is; KYA needs the whose and the what-may-it-do as well. See Why agent identity is a new problem and the verification guide; What is Know Your Agent? puts the term in context.
Related terms
Sources
- NIST, SP 800-63-4, Digital Identity Guidelines (accessed 2026-10-03)
- SPIFFE, SPIFFE Concepts (accessed 2026-10-03)
- W3C, Verifiable Credentials Data Model v2.0 (accessed 2026-10-03)
- Cloudflare, Web Bot Auth (accessed 2026-10-03)
- Google Cloud, Agent Identity overview (accessed 2026-10-03)
- Microsoft, What is Microsoft Entra Agent ID? (accessed 2026-10-03)
- Cloud Security Alliance, Agentic Identity: Emerging Standards and Security Guidance (accessed 2026-10-03)
Know Your Agent (KYA) explains agent identity, verification and accountability. This is an explainer, not legal or compliance advice — see our Sources & methodology. New to KYA? Start with What is Know Your Agent? and the glossary.