Agent Registry — KYA Glossary

An agent registry is a directory of known agents and their principals — a place to look up whether an agent is registered, who issued its identity, and who is accountable for it.

Why it matters

Verification assumes there is something to verify against. A registry supplies the reference: an issuer’s public keys, a trust list, or a record binding an agent to a principal. Without one, a relying party can only check internal consistency, not legitimacy.

There is no single ratified “KYA registry” as of October 2026. Real, adjacent building blocks exist:

  • Decentralized identifiers (W3C DID Core) can be resolved through registries without a central operator.
  • Trust lists and frameworks (eIDAS 2.0 / EUDI) provide authoritative lists of trusted participants for digital identity — a model agent registries can borrow.
  • Federation (NIST SP 800-63) shows how one party can accept another’s assertions via a federation authority, without direct pairwise trust.
  • Zero trust (NIST SP 800-207) emphasises authoritative, up-to-date policy and identity sources at decision time.

Design questions

  • Who operates it, and who is accountable for its accuracy?
  • What it stores — identity keys, principal links, status.
  • How relying parties refresh — cache lifetime vs freshness.
  • Privacy — a global registry of agents is also a target and a surveillance surface.

Status

Treat “agent registry” as an emerging concept. Vendor or protocol registries today are usually scoped to one ecosystem, not global.

Related

Sources

  1. W3C, Decentralized Identifiers (DIDs) v1.0 — https://www.w3.org/TR/did-core/ (accessed 2026-10-03)
  2. European Commission, EUDI Regulation (EU) 2024/1183 — https://digital-strategy.ec.europa.eu/en/policies/eudi-regulation (accessed 2026-10-03)
  3. NIST, SP 800-63-4 — https://pages.nist.gov/800-63-4/ (accessed 2026-10-03)
  4. NIST, SP 800-207 — https://csrc.nist.gov/pubs/sp/800/207/final (accessed 2026-10-03)