Agent Passport / Agent Credential — KYA Glossary

An agent passport (or agent credential) is a portable, verifiable credential describing an agent’s identity and authorisations — who it is, who issued it, what it may do, and until when — that the agent can present to a service it has no prior relationship with.

Why it matters

Agents increasingly interact with strangers: they browse, book, buy, and call APIs across organisational boundaries. There is no shared directory to look the agent up in. A verifiable credential lets the agent carry its own proof, and lets the relying service check it without a prior trust relationship.

The building blocks are standard:

  • W3C Verifiable Credentials Data Model 2.0 defines the issuer/holder/verifier roles and a tamper-evident data model for exactly this kind of claim.
  • OpenID for Verifiable Credential Issuance (OID4VCI) defines how such credentials are issued to a wallet or holder.
  • eIDAS 2.0 / EUDI wallets (Regulation (EU) 2024/1183) make verifiable credentials part of mainstream EU digital identity, a likely carrier for agent credentials.
  • Payment protocols such as Google’s AP2 use signed mandates carried as verifiable credentials so an agent can prove the user’s intent to a merchant.

The “passport” metaphor is informal and not a standard term. What matters is that the credential is verifiable by a third party and scoped to a purpose.

What a useful agent credential expresses

  • Issuer (who vouches for the agent).
  • The agent’s identity and its principal.
  • Authorised actions, limits, and data scope.
  • Validity window and status/revocation reference.

Related

Sources

  1. W3C, Verifiable Credentials Data Model v2.0 — https://www.w3.org/TR/vc-data-model-2.0/ (accessed 2026-10-03)
  2. OpenID Foundation, OpenID for Verifiable Credential Issuance — https://openid.net/sg/openid4vc/specifications/ (accessed 2026-10-03)
  3. European Commission, EUDI Regulation (EU) 2024/1183 — https://digital-strategy.ec.europa.eu/en/policies/eudi-regulation (accessed 2026-10-03)
  4. Google, Agent Payments Protocol (AP2) — https://ap2-protocol.org/ (accessed 2026-10-03)