The Agent Identity Tracker
Every announced framework, protocol, standard, and regulation for AI agent identity, delegation, and know-your-agent (KYA) verification: who is building the layer that answers “whose agent is this, and what may it do?” Dated, sourced, and strictly factual.
19 entries · 7 live · 7 specs published · 3 in development · 1 announced · 1 mandated
- 2026-09-09announcedNetwork program
Know-Your-Agent (KYA) Interoperability Framework
Ant International + Mastercard + VisaAnt International, Mastercard, and Visa announced a collaboration on a Know-Your-Agent interoperability framework intended to streamline AI agent onboarding and identification across card networks, wallet ecosystems, agent platforms, and marketplaces while each network retains its own verification and decisioning processes.
Source - 2026-07-29spec-publishedProtocol spec
KYA-OS (Know Your Agent Operating System)
Decentralized Identity Foundation (donated by Vouched)Vouched and the Decentralized Identity Foundation released KYA-OS Protocol Specification v1.0.0, an open specification using DIDs and verifiable credentials so any service an AI agent contacts can cryptographically verify who authorized the agent and what it is permitted to do; Vouched donated the original MCP-I framework to DIF in March 2026.
Source - 2026-06-24liveInfrastructure
Claude Tag Agent Identity Model
AnthropicAnthropic introduced an agent identity access model for Claude Tag under which AI agents hold their own accounts, permissions, and access scopes in shared team workspaces rather than impersonating individual users.
Source - 2026-04-28liveProtocol spec
Agentic Mobile Protocol (AMP)
Ant InternationalAnt International launched the open-sourced Agentic Mobile Protocol, an agentic payment framework for digital wallets, super apps, and wearable devices that embeds a Know-Your-Agent digital-identity framework, with a 2026 Phase I rollout across 10 Alipay+ wallets and seven acquirers including Adyen, Checkout.com, Fiserv, and Worldline.
Source - 2026-03-05spec-publishedProtocol spec
Mastercard Verifiable Intent
Mastercard + GoogleMastercard and Google announced Verifiable Intent, an open, standards-based framework (v0.1 draft specification dated February 18, 2026, with a Python reference implementation) that links a consumer's identity, their instructions to an agent, and the transaction outcome into a tamper-resistant cryptographic record.
Source - 2026-02-17in-developmentStandard
NIST AI Agent Standards Initiative
NIST Center for AI Standards and Innovation (CAISI)NIST's CAISI launched the AI Agent Standards Initiative supporting industry-led standards for agent interoperability and security, accompanied by an NCCoE concept paper (February 5, 2026) on adapting identity and authorization frameworks to software and AI agents, covering authentication, authorization, auditing, and non-repudiation.
Source - 2026-01-11spec-publishedProtocol spec
Universal Commerce Protocol (UCP) Identity Linking
Google (developed with Shopify, Etsy, Wayfair, Target, Walmart, and others)Google announced UCP at NRF 2026, an open-source agentic commerce standard whose Identity Linking capability (expanded March 19, 2026) lets shoppers connect retailer accounts to UCP platforms via OAuth 2.0 so agents transact with the user's authenticated merchant identity and loyalty benefits.
Source - 2025-10-23in-developmentStandard
IETF Web Bot Auth Working Group (webbotauth)
IETFThe IESG approved the charter of the webbotauth working group to standardize cryptographic authentication of automated clients (including AI agents acting for end users) and conveyance of operator information to websites, with standards-track specifications targeted to the IESG by April 30, 2026.
Source - 2025-10-14spec-publishedProtocol spec
Visa Trusted Agent Protocol (TAP)
Visa (co-developed with Cloudflare)Visa introduced the Trusted Agent Protocol, a framework enabling AI agents to cryptographically identify themselves to merchants during agentic commerce transactions, developed with Cloudflare and with partners including Adyen, Ant International, Checkout.com, Coinbase, Fiserv, Microsoft, Shopify, Stripe, and Worldpay.
Source - 2025-09-29liveProtocol spec
Agentic Commerce Protocol (ACP)
OpenAI + StripeStripe and OpenAI released the Agentic Commerce Protocol, the open standard behind Instant Checkout in ChatGPT, in which the agent passes a Shared Payment Token to the merchant via API so the merchant can identify the agent-originated order and accept or decline it without receiving raw card credentials.
Source - 2025-09-16spec-publishedProtocol spec
Agent Payments Protocol (AP2)
Google (with 60+ payments and technology partners)Google announced AP2, an open protocol for agent-led payments in which each purchase is represented by cryptographically signed, tamper-evident Mandates (Intent, Cart, and Payment) built on verifiable credentials, with partners including PayPal, Mastercard, American Express, Adyen, Coinbase, and Worldpay.
Source - 2025-08-28liveInfrastructure
Cloudflare Signed Agents
CloudflareCloudflare launched a signed-agents classification and registry that uses Web Bot Auth cryptographic signatures to let websites distinguish user-directed AI agents from other bot traffic, with a founding cohort including ChatGPT agent, Block's Goose, Browserbase, and Anchor Browser.
Source - 2025-08-13in-developmentStandard
ERC-8004: Trustless Agents
Ethereum communityERC-8004, a draft Ethereum standards-track proposal created August 13, 2025, defines on-chain identity, reputation, and validation registries so blockchain-based AI agents can be discovered and trusted across organizational boundaries.
Source - 2025-05-19liveInfrastructure
Microsoft Entra Agent ID
MicrosoftMicrosoft announced Entra Agent ID at Build 2025, assigning each AI agent created in Azure AI Foundry or Copilot Studio a unique directory identity with access controls, role-based permissions, lifecycle management, and audit trails; it underpins Microsoft Agent 365, generally available May 1, 2026.
Source - 2025-05-15spec-publishedStandard
W3C Verifiable Credentials 2.0
W3C Verifiable Credentials Working GroupW3C published the Verifiable Credentials 2.0 family (Data Model v2.0, Data Integrity 1.0, Bitstring Status List, JOSE/COSE securing, Controlled Identifiers 1.0) as W3C Recommendations, the credential format used by agent-identity efforts including Google AP2 mandates and DIF KYA-OS.
Source - 2025-05-15liveProtocol spec
Web Bot Auth
Cloudflare (proposed; now under IETF standardization)Cloudflare proposed Web Bot Auth, a mechanism using HTTP Message Signatures and well-known key directories so bots and AI agents cryptographically identify themselves to origins instead of relying on IP addresses or user-agent strings, and later integrated it into its Verified Bots program.
Source - 2025-04-29liveNetwork program
Mastercard Agent Pay
MastercardMastercard unveiled Agent Pay, an agentic payments program that registers and verifies AI agents and uses Agentic Tokens (an extension of Mastercard's tokenization service) to bind a card credential to a specific agent, merchant scope, and consent, with Microsoft and IBM among launch partners.
Source - 2024-05-20mandatedRegulation
eIDAS 2.0 / EU Digital Identity Wallet
European Union (Regulation (EU) 2024/1183)Regulation (EU) 2024/1183 (eIDAS 2.0), in force since May 20, 2024, requires every EU member state to offer citizens a certified European Digital Identity Wallet by December 24, 2026, establishing verified principal identity infrastructure that agent-delegation frameworks can bind to.
Source - 2022-07-19spec-publishedStandard
W3C Decentralized Identifiers (DID) 1.0
W3C DID Working GroupW3C published Decentralized Identifiers (DIDs) v1.0 as a W3C Recommendation, defining cryptographically verifiable identifiers without centralized registries that agent-identity frameworks such as KYA-OS use to identify agents and their delegating principals.
Source
An entry is a publicly announced framework, protocol, standard, regulation, or production infrastructure whose stated purpose includes identifying an AI agent, verifying who authorized it, or binding its actions to a principal. Single-vendor point products, payment rails without an identity layer, and agent-to-agent communication protocols are excluded. Entries are factual records of announcements, not endorsements or assessments. Corrections and submissions via GitHub issues.
Machine-readable: the full dataset is served as JSON at /kya/feed (CC-BY-4.0). Cite as: Major Labs, Agent Identity Tracker, majorlabs.co/kya, retrieved [date].