Revocation is withdrawing an agent’s authority and credentials — quickly, precisely, and verifiably. It is the safety valve of KYA: a compromised or misaligned agent must be stoppable in seconds, without dismantling unrelated integrations.
Why it matters
Authority that cannot be withdrawn is not really authority; it is a permanent grant. Agents make this urgent because they can be compromised or manipulated instantly, and because their credentials are often long-lived bearer secrets.
Revocation is a solved problem in adjacent fields:
- OAuth token revocation (RFC 7009) lets a client tell the authorization server a token is no longer needed, invalidating it and related tokens.
- X.509 certificate status (RFC 5280) uses revocation lists, and OCSP for online checks, to mark certificates invalid before expiry.
- Verifiable credential status (W3C VC Data Model) provides a mechanism to check whether a credential has been suspended or revoked (status lists).
- Authenticator revocation (NIST SP 800-63) covers invalidating a lost or compromised authenticator.
Design considerations
- Latency — how fast does revocation take effect at every relying service?
- Granularity — can you revoke one agent or one mandate, not a whole tenant?
- Discoverability — do relying parties check status, or only validate at issuance?
- Auditability — is the revocation recorded, with who and why?
Common failure
Issuing short-lived credentials and relying on expiry is not revocation; it leaves a window of exposure. Prefer both: short expiry and an active revocation path.
How it works in practice
Revocation is a check, not just an API call. A token can be invalidated at the authorization server (RFC 7009), but if a service only validates the token’s signature and expiry it may never learn. Certificates have the same shape: a CRL or an OCSP lookup is only useful if the relying party performs it. Verifiable credentials add status lists for the same purpose.
The pair that works is short-lived credentials and an active revocation path. SPIFFE leans on short lifetimes with automatic rotation to shrink the exposure window, but that is a reduction, not a substitute for being able to withdraw authority on demand. See What is Know Your Agent? and the verification guide, with lifecycle code in the examples.
Related terms
Sources
- IETF, RFC 7009, OAuth 2.0 Token Revocation (accessed 2026-10-03)
- IETF, RFC 5280, Internet X.509 Public Key Infrastructure Certificate and CRL Profile (accessed 2026-10-03)
- W3C, Verifiable Credentials Data Model v2.0 (accessed 2026-10-03)
- NIST, SP 800-63-4, Digital Identity Guidelines (accessed 2026-10-03)
- SPIFFE, SPIFFE Concepts (accessed 2026-10-03)
Know Your Agent (KYA) explains agent identity, verification and accountability. This is an explainer, not legal or compliance advice — see our Sources & methodology. New to KYA? Start with What is Know Your Agent? and the glossary.