Revocation — KYA Glossary

Revocation is withdrawing an agent’s authority and credentials — quickly, precisely, and verifiably. It is the safety valve of KYA: a compromised or misaligned agent must be stoppable in seconds, without dismantling unrelated integrations.

Why it matters

Authority that cannot be withdrawn is not really authority; it is a permanent grant. Agents make this urgent because they can be compromised or manipulated instantly, and because their credentials are often long-lived bearer secrets.

Revocation is a solved problem in adjacent fields:

  • OAuth token revocation (RFC 7009) lets a client tell the authorization server a token is no longer needed, invalidating it and related tokens.
  • X.509 certificate status (RFC 5280) uses revocation lists, and OCSP for online checks, to mark certificates invalid before expiry.
  • Verifiable credential status (W3C VC Data Model) provides a mechanism to check whether a credential has been suspended or revoked (status lists).
  • Authenticator revocation (NIST SP 800-63) covers invalidating a lost or compromised authenticator.

Design considerations

  • Latency — how fast does revocation take effect at every relying service?
  • Granularity — can you revoke one agent or one mandate, not a whole tenant?
  • Discoverability — do relying parties check status, or only validate at issuance?
  • Auditability — is the revocation recorded, with who and why?

Common failure

Issuing short-lived credentials and relying on expiry is not revocation; it leaves a window of exposure. Prefer both: short expiry and an active revocation path.

How it works in practice

Revocation is a check, not just an API call. A token can be invalidated at the authorization server (RFC 7009), but if a service only validates the token’s signature and expiry it may never learn. Certificates have the same shape: a CRL or an OCSP lookup is only useful if the relying party performs it. Verifiable credentials add status lists for the same purpose.

The pair that works is short-lived credentials and an active revocation path. SPIFFE leans on short lifetimes with automatic rotation to shrink the exposure window, but that is a reduction, not a substitute for being able to withdraw authority on demand. See What is Know Your Agent? and the verification guide, with lifecycle code in the examples.

Related terms

Sources

  1. IETF, RFC 7009, OAuth 2.0 Token Revocation (accessed 2026-10-03)
  2. IETF, RFC 5280, Internet X.509 Public Key Infrastructure Certificate and CRL Profile (accessed 2026-10-03)
  3. W3C, Verifiable Credentials Data Model v2.0 (accessed 2026-10-03)
  4. NIST, SP 800-63-4, Digital Identity Guidelines (accessed 2026-10-03)
  5. SPIFFE, SPIFFE Concepts (accessed 2026-10-03)

Know Your Agent (KYA) explains agent identity, verification and accountability. This is an explainer, not legal or compliance advice — see our Sources & methodology. New to KYA? Start with What is Know Your Agent? and the glossary.