Revocation — KYA Glossary

Revocation is withdrawing an agent’s authority and credentials — quickly, precisely, and verifiably. It is the safety valve of KYA: a compromised or misaligned agent must be stoppable in seconds, without dismantling unrelated integrations.

Why it matters

Authority that cannot be withdrawn is not really authority; it is a permanent grant. Agents make this urgent because they can be compromised or manipulated instantly, and because their credentials are often long-lived bearer secrets.

Revocation is a solved problem in adjacent fields:

  • OAuth token revocation (RFC 7009) lets a client tell the authorization server a token is no longer needed, invalidating it and related tokens.
  • X.509 certificate status (RFC 5280) uses revocation lists, and OCSP for online checks, to mark certificates invalid before expiry.
  • Verifiable credential status (W3C VC Data Model) provides a mechanism to check whether a credential has been suspended or revoked (status lists).
  • Authenticator revocation (NIST SP 800-63) covers invalidating a lost or compromised authenticator.

Design considerations

  • Latency — how fast does revocation take effect at every relying service?
  • Granularity — can you revoke one agent or one mandate, not a whole tenant?
  • Discoverability — do relying parties check status, or only validate at issuance?
  • Auditability — is the revocation recorded, with who and why?

Common failure

Issuing short-lived credentials and relying on expiry is not revocation; it leaves a window of exposure. Prefer both: short expiry and an active revocation path.

Related

Sources

  1. IETF, RFC 7009, OAuth 2.0 Token Revocation — https://www.rfc-editor.org/info/rfc7009/ (accessed 2026-10-03)
  2. IETF, RFC 5280 — https://www.rfc-editor.org/info/rfc5280/ (accessed 2026-10-03)
  3. W3C, Verifiable Credentials Data Model v2.0 — https://www.w3.org/TR/vc-data-model-2.0/ (accessed 2026-10-03)
  4. NIST, SP 800-63-4 — https://pages.nist.gov/800-63-4/ (accessed 2026-10-03)