Identity · CA
MCP's Identity Extension Gets a New Home at the Decentralized Identity Foundation
A concrete piece of agent identity infrastructure changed hands this spring, and it's worth flagging now because the fork it created is still working through standards bodies. In March 2026, Vouched formally donated the Model Context Protocol - Identity (MCP-I) framework to the Decentralized Identity Foundation, where it's now stewarded by the DIF Trusted AI Agents Working Group. The spec has since been renamed KYA-OS (Know Your Agent Operating System) to reflect that its scope now extends beyond MCP alone.
The technical substance matters more than the rename. KYA-OS uses Decentralized Identifiers and Verifiable Credentials to let two parties cryptographically verify each other's agents and human principals without any prior coordination between them. The framework organizes this around four questions every service should be able to answer before letting an agent act: who the agent is, who authorized it, what it's allowed to do, and what the scope of that delegation is. That's a cleaner decomposition than most of what's floated around agent identity so far, because it separates the agent's own identity from the human or organizational authority behind it — a distinction that self-declared Agent Cards never made explicit.
This is happening against a backdrop of real governance consolidation. MCP itself moved from an Anthropic side project to the Agentic AI Foundation under the Linux Foundation, and within four months that foundation grew to 170 member organizations — more than double CNCF's membership at the same stage of its life. Parallel to that, the A2A protocol shipped its v1.0.0 stable spec in March, which formalizes Agent Card signature verification using JWS and JSON Canonicalization and drops legacy OAuth implicit and password flows in favor of Device Code and PKCE support.
None of this closes the identity gap on its own. The same reporting on KYA-OS notes that MCP's own 2026 roadmap flagged audit trail infrastructure and SSO-integrated auth as top enterprise requests that remain unsolved — the roadmap is a commitment, not a delivery. But the pattern is legible: what was ad hoc, self-declared agent metadata a year ago is being routed into standards bodies with working groups, DID-based credential formats, and explicit authorization-chain semantics. That's the actual work of building an identity layer, distinct from any single vendor's product announcement.
Given the pace of change here, this is a specification worth tracking as it moves through DIF's process rather than a settled outcome.