Identity · CA
Agent identity splits into layers, not one big standard
This week gave a clean illustration of where agent identity infrastructure is actually heading: not one unified protocol, but separate layers built by separate parties that snap together. Biometric Update reported on three developments landing at once from 1Password, Dai Nippon Printing (DNP), and the Linux Foundation, each solving a different piece of the same problem — an AI agent acting as your proxy without becoming you.
1Password's approach for Anthropic's Claude keeps credentials out of the model entirely. The company describes a zero-exposure design where Claude can complete logins and one-time-passcode flows, but "the credentials never enter the model or its memory," with 1Password remaining "the source of truth for the secret" and access granted only at runtime. When Claude needs to sign in, the user sees which credential is being requested and why, approves biometrically, and 1Password injects the credential directly into the page — Claude never sees the vault item. CTO Nancy Wang frames the shift plainly: the fix isn't handing agents your secrets, it's letting a user grant permission to use a credential without letting the agent see it.
DNP is attacking a different piece: proving whose agent is acting and with what authority. Its CATRINA identity platform now issues verifiable credentials so that, in the company's words, only AI agents authorized by the user can conduct transactions based on the user's will and authority — aimed specifically at agentic proxy purchases in online shopping, where the open question has been confirming whose proxy an agent is and under what scope.
The third piece is the transaction layer itself. The Linux Foundation announced the operational launch of the x402 Foundation, an open-governance body created by Coinbase to steward x402, a protocol that embeds payment capability directly into HTTP so agents, APIs, and applications can exchange payments the way they exchange data — spanning traditional cards to stablecoins. The foundation already counts roughly 40 member organizations, including AWS, Google, Mastercard, Stripe, and Visa, with the Linux Foundation providing neutral governance for the standard.
None of these three groups is solving the whole problem, and none claims to. Taken together, they map onto a division of labor: DNP addresses an agent's authority to act, 1Password addresses its authority to access the credential needed to act, and x402 addresses the transaction that results. That separation — identity, access, and settlement as distinct, independently governed layers — looks less like an accident and more like the shape the agent-economy stack is settling into, months before anyone converges on a single end-to-end standard.
The gap this doesn't close: interoperability between these layers still depends on each vendor and standards body choosing to integrate rather than compete for control of the stack.