The IETF Published a Draft for Agent Identity. The Market Already Shipped.

Posted

On April 3, 2026, Martin Besozzi of TwoGenIdentity submitted draft-embesozzi-oauth-agent-native-authorization-00 to the IETF. As of today, October 4, this document is set to expire in less than 24 hours. While the window for this specific individual submission is closing, the proposal highlights a critical tension in the development of agentic infrastructure: the attempt by standards bodies to formalize protocols for a market that has already moved to production.

The Besozzi draft proposes an extension to the OAuth 2.0 First-Party Applications (FiPA) specification. Its primary function is to make agent authorization challenges machine-readable. By introducing an “elicitations” array into the Authorization Challenge Response, the draft provides a standardized metadata format for authenticator challenges – such as TOTP codes or passkeys. Crucially, the protocol uses the Model Context Protocol (MCP) as its normative reference, mapping the elicitations array directly to MCP’s elicitation/create parameters. This creates a just-in-time authorization flow for Human-to-Agent (H2A) interactions: when an agent hits a sensitive operation, it pauses, surfaces a structured challenge to the user, collects the response, and secures an OAuth token to proceed.

However, the IETF landscape remains fragmented. There is no adopted working group for agent-specific identity. Instead, the space is crowded with competing individual drafts, including the Agent Identity Protocol by Singla et al., SAIP by Jovancevic, AAuth by Dick Hardt (the co-author of OAuth 2.0), AI-Auth, and the Delegated AI Agent Authorization Profile by Mishra. Even the FiPA parent specification, while closer to adoption than the Besozzi extension, is still in the “Waiting for Write-Up” stage within the OAuth Working Group. The agentproto proposed working group held a WG-forming BoF at IETF 126 in Vienna on July 23, 2026, aiming to define an Agentic Dialog Management Protocol – but it is not yet chartered.

This regulatory lag stands in stark contrast to the market, which has already shipped functional solutions. Okta’s XAA protocol has onboarded over 25 partners, including TrueFoundry, Cloudflare, and Scalekit, with a general availability target for fiscal year 2027. Meanwhile, MCP has integrated OAuth 2.1 with PKCE and dynamic client registration since late 2025, and Dick Hardt’s AAuth has moved toward replacing bearer tokens with signed requests from per-agent keypairs. According to Okta research cited by TrueFoundry, 88 percent of organizations report confirmed or suspected AI agent security incidents. The industry is not waiting for a consensus-driven standard to secure its deployments.

To understand where this fits, we must view it as a specific layer in the stack. The Besozzi draft operates at the protocol layer, distinct from the other security measures Forkast has tracked. It sits below the identity provider layer, where Okta XAA manages broad access, and above the container-level isolation provided by K8s Agent Sandboxes. It is also distinct from the OS-level restrictions recently introduced by Apple’s macOS FDA. While these layers – from Aembit‘s workload identity to the Harness Pattern and Execution-Layer Gateways – address different vectors, the Besozzi draft attempts to standardize the “handshake” between the agent and the human user.

The limitation of this approach is its scope. The draft is strictly confined to H2A flows, leaving Agent-to-Agent (A2A) authorization entirely out of scope. As the industry moves toward more complex, multi-hop agentic workflows, the need for a unified standard becomes more acute. The upcoming agentproto proposed working group aims to address this by defining a broader Agentic Dialog Management Protocol, covering verifiable agent identity distinct from user identity, cross-domain federation, and protocol-level attribution for security incidents. Whether the IETF can catch up to the rapid pace of the commodity SKU-driven market remains the central question for infrastructure builders. For now, the Besozzi draft serves as a snapshot of a moment where the protocol layer is still struggling to catch up to the reality of deployed agentic systems.

Infrastructure