Identity · CA
Four Vendors, One Draft: AWS, Zscaler, Ping, and Defakto Write an Agent Auth Spec Together
A new IETF Internet-Draft, "AI Agent Authentication and Authorization," quietly moved past its first revision this year, and its author list is the interesting part. Pieter Kasselman (Defakto Security), Jeff Lombardo (AWS), Yaroslav Rosomakho (Zscaler), and Brian Campbell (Ping Identity) are co-authoring it as a Network Working Group submission, first published March 2, 2026, now on its third revision.
The draft's stated approach is deliberately unglamorous. It leverages existing standards such as the Workload Identity in Multi-System Environments (WIMSE) architecture and OAuth 2.0 family of specifications, rather than inventing a parallel AI-specific identity system. The document frames its own goal as providing a framework within which to use existing standards, identify gaps and guide future standardization efforts for agent authentication and authorization.
That framing matters because it's a direct answer to a real fragmentation problem. Separate reporting this year has tracked competing agent-identity approaches from payment networks (tokenized identities from Mastercard, attestation headers from Visa), Google's Verifiable-Credential-based AP2, and W3C DIDs for crypto-native agents — four different trust anchors solving overlapping problems in incompatible ways. A companion Cloud Security Alliance discussion paper has separately flagged agent identity and delegation schemes as an architecturally unresolved gap and called for standardized identity protocols as a research priority.
What makes the IETF draft notable isn't novelty — it's who signed on. Getting engineers from a cloud provider, a security-service-edge vendor, and an identity platform to co-author the same informational draft is a small but real signal that the industry wants agent auth to converge on WIMSE and OAuth extensions rather than fragment into four vendor-specific stacks, each with its own trust anchor and none of them talking to the others.
The draft is still informational, not a standards-track RFC, and it expires September 3, 2026, meaning it will need a fresh revision or working-group adoption to stay alive. Its actual technical content — how delegation chains are represented, how scopes propagate from human to agent to sub-agent — is less important right now than the fact that competing vendors chose to write it as one document instead of four competing whitepapers. Whether the IETF eventually adopts this into a working group, or whether it withers as an individual submission, will say a lot about whether agent authentication converges or keeps fragmenting.