An agent registry is a directory of known agents and their principals — a place to look up whether an agent is registered, who issued its identity, and who is accountable for it.
Why it matters
Verification assumes there is something to verify against. A registry supplies the reference: an issuer’s public keys, a trust list, or a record binding an agent to a principal. Without one, a relying party can only check internal consistency, not legitimacy.
There is no single ratified “KYA registry” as of October 2026. Real, adjacent building blocks exist:
- Decentralized identifiers (W3C DID Core) can be resolved through registries without a central operator.
- Trust lists and frameworks (eIDAS 2.0 / EUDI) provide authoritative lists of trusted participants for digital identity — a model agent registries can borrow.
- Federation (NIST SP 800-63) shows how one party can accept another’s assertions via a federation authority, without direct pairwise trust.
- Zero trust (NIST SP 800-207) emphasises authoritative, up-to-date policy and identity sources at decision time.
Design questions
- Who operates it, and who is accountable for its accuracy?
- What it stores — identity keys, principal links, status.
- How relying parties refresh — cache lifetime vs freshness.
- Privacy — a global registry of agents is also a target and a surveillance surface.
Status
Treat “agent registry” as an emerging concept. Vendor or protocol registries today are usually scoped to one ecosystem, not global.
How it works in practice
Two models are in play. A resolution model (DIDs) turns an identifier into a document with keys and service endpoints, checked by the relying party. A trust-list model (as in EUDI) publishes an authoritative set of trusted participants that others accept by policy. Federation sits between them: a relying party accepts assertions because a federation authority is trusted to vouch for its members.
For KYA the registry’s job is narrow: given an agent identity, find the issuer’s keys and the principal record, and check whether the identity is still valid. Keeping that lookup fresh is the hard part — a stale cache is an outdated trust decision. See Why agent identity is a new problem, What is Know Your Agent? and the verification guide.
Related terms
Sources
- W3C, Decentralized Identifiers (DIDs) v1.0 (accessed 2026-10-03)
- European Commission, EUDI Regulation (EU) 2024/1183 (accessed 2026-10-03)
- NIST, SP 800-63-4, Digital Identity Guidelines (accessed 2026-10-03)
- NIST, SP 800-207, Zero Trust Architecture (accessed 2026-10-03)
Know Your Agent (KYA) explains agent identity, verification and accountability. This is an explainer, not legal or compliance advice — see our Sources & methodology. New to KYA? Start with What is Know Your Agent? and the glossary.