Identity · CA
The Delegated Agent Identity Stack Is Splitting Into Layers
Three separate announcements this week point at the same underlying shift: the identity problem for AI agents is being unbundled into distinct, non-overlapping layers rather than solved by one company or protocol.
1Password published its architecture for letting Claude complete browser tasks that require logins. The company's design keeps credentials out of the model's reach entirely: after biometric approval from the user, 1Password injects the credential directly into the page, and the agent never sees the vault item, password, or one-time code. 1Password's CTO frames the goal as letting a user grant permission to use a credential without letting the agent see it, since that's where trust in agents actually starts.
Separately, Dai Nippon Printing rolled out a digital identity management function for AI agents making proxy purchases, built on its CATRINA distributed ID platform and using verifiable credentials. The stated aim is to create an environment where only AI agents authorized by the user can conduct transactions based on the user's will and authority — addressing the question of whose proxy an agent is acting as and under what authority, a question ordinary online shopping infrastructure was never built to answer.
And the Linux Foundation announced the operational launch of the x402 Foundation, a Coinbase-created open-governance body for the x402 protocol, an open standard for internet-native payments over HTTP so that agents, APIs, and applications can send and receive payments as seamlessly as they exchange data. The Foundation already counts roughly 40 member organizations, including Amazon Web Services, Google, Mastercard, Stripe, and Visa.
None of these three fully solves agent identity on its own. But laid side by side, they cleanly separate what used to be one tangled problem into three: DNP's system establishes an agent's authority to buy, 1Password governs its authority to access the account needed to buy, and x402 handles the transaction mechanics itself. That division of labor — person, agent, delegated authority, credential, transaction — is what a workable identity stack for delegated agency actually looks like, and it's arriving as separate, interoperable pieces rather than a single unified standard.