Revocation is withdrawing an agent’s authority and credentials — quickly, precisely, and verifiably. It is the safety valve of KYA: a compromised or misaligned agent must be stoppable in seconds, without dismantling unrelated integrations.
Why it matters
Authority that cannot be withdrawn is not really authority; it is a permanent grant. Agents make this urgent because they can be compromised or manipulated instantly, and because their credentials are often long-lived bearer secrets.
Revocation is a solved problem in adjacent fields:
- OAuth token revocation (RFC 7009) lets a client tell the authorization server a token is no longer needed, invalidating it and related tokens.
- X.509 certificate status (RFC 5280) uses revocation lists, and OCSP for online checks, to mark certificates invalid before expiry.
- Verifiable credential status (W3C VC Data Model) provides a mechanism to check whether a credential has been suspended or revoked (status lists).
- Authenticator revocation (NIST SP 800-63) covers invalidating a lost or compromised authenticator.
Design considerations
- Latency — how fast does revocation take effect at every relying service?
- Granularity — can you revoke one agent or one mandate, not a whole tenant?
- Discoverability — do relying parties check status, or only validate at issuance?
- Auditability — is the revocation recorded, with who and why?
Common failure
Issuing short-lived credentials and relying on expiry is not revocation; it leaves a window of exposure. Prefer both: short expiry and an active revocation path.
Related
Sources
- IETF, RFC 7009, OAuth 2.0 Token Revocation — https://www.rfc-editor.org/info/rfc7009/ (accessed 2026-10-03)
- IETF, RFC 5280 — https://www.rfc-editor.org/info/rfc5280/ (accessed 2026-10-03)
- W3C, Verifiable Credentials Data Model v2.0 — https://www.w3.org/TR/vc-data-model-2.0/ (accessed 2026-10-03)
- NIST, SP 800-63-4 — https://pages.nist.gov/800-63-4/ (accessed 2026-10-03)