Agent attestation is evidence that an agent is what it claims to be and runs what it claims to run — for example, that it executes approved code on a trusted platform under a known configuration.
Why it matters
A credential proves possession; attestation proves provenance. If an attacker can run their own code under a legitimate agent’s identity, a valid credential is worthless. Attestation closes that gap by measuring and signing what the agent actually is.
It borrows from mature practice:
- Zero trust (NIST SP 800-207) treats device and workload attestation as inputs to access decisions rather than trusting a network location.
- Workload attestation (SPIRE) authenticates a node’s identity automatically and issues identities to workloads based on selectors — the platform attests what the workload is, rather than trusting a shared secret.
- Authenticator binding (NIST SP 800-63) ensures a credential is bound to the specific authenticator that a subject holds.
- Verifiable credentials (W3C) can carry attestation results as tamper-evident claims a relying party can check.
Common forms
- Platform/node attestation — the infrastructure proves the environment (e.g. a TPM-backed measurement).
- Code/config attestation — a signed hash of the agent’s code or container image.
- Runtime attestation — evidence of the state at the moment an action is taken.
Limits
Attestation is only as strong as the trusted platform and the measurement. It does not prove the agent is aligned, only that it is the expected artefact. Combine it with scoped authority and audit.
Related
Sources
- NIST, SP 800-207 — https://csrc.nist.gov/pubs/sp/800/207/final (accessed 2026-10-03)
- SPIFFE, SPIRE Concepts — https://spiffe.io/docs/latest/spire-about/spire-concepts/ (accessed 2026-10-03)
- NIST, SP 800-63-4 — https://pages.nist.gov/800-63-4/ (accessed 2026-10-03)
- W3C, Verifiable Credentials Data Model v2.0 — https://www.w3.org/TR/vc-data-model-2.0/ (accessed 2026-10-03)