An agent registry is a directory of known agents and their principals — a place to look up whether an agent is registered, who issued its identity, and who is accountable for it.
Why it matters
Verification assumes there is something to verify against. A registry supplies the reference: an issuer’s public keys, a trust list, or a record binding an agent to a principal. Without one, a relying party can only check internal consistency, not legitimacy.
There is no single ratified “KYA registry” as of October 2026. Real, adjacent building blocks exist:
- Decentralized identifiers (W3C DID Core) can be resolved through registries without a central operator.
- Trust lists and frameworks (eIDAS 2.0 / EUDI) provide authoritative lists of trusted participants for digital identity — a model agent registries can borrow.
- Federation (NIST SP 800-63) shows how one party can accept another’s assertions via a federation authority, without direct pairwise trust.
- Zero trust (NIST SP 800-207) emphasises authoritative, up-to-date policy and identity sources at decision time.
Design questions
- Who operates it, and who is accountable for its accuracy?
- What it stores — identity keys, principal links, status.
- How relying parties refresh — cache lifetime vs freshness.
- Privacy — a global registry of agents is also a target and a surveillance surface.
Status
Treat “agent registry” as an emerging concept. Vendor or protocol registries today are usually scoped to one ecosystem, not global.
Related
Sources
- W3C, Decentralized Identifiers (DIDs) v1.0 — https://www.w3.org/TR/did-core/ (accessed 2026-10-03)
- European Commission, EUDI Regulation (EU) 2024/1183 — https://digital-strategy.ec.europa.eu/en/policies/eudi-regulation (accessed 2026-10-03)
- NIST, SP 800-63-4 — https://pages.nist.gov/800-63-4/ (accessed 2026-10-03)
- NIST, SP 800-207 — https://csrc.nist.gov/pubs/sp/800/207/final (accessed 2026-10-03)