Agent Identity Protocol (AIP) AIP
Identify The Agent Identity Protocol (AIP) is a proposed decentralized identity, delegation, and authorization framework for autonomous AI agents. It combines W3C Decentralized Identifiers (DIDs), capability-based authorization, cryptographic delegation chains, and deterministic validation, explicitly aiming to let multi-agent workflows be secure and auditable without depending on a centralized identity provider [1].
Overview
It targets the "identity gap" the author identifies: when an autonomous agent — which may send emails, book appointments, make purchases, access file systems, spawn child agents, or act across multiple platforms without per-action human approval — presents itself to an API, a payment processor, or another agent, there is today no standard way to establish the agent's persistent identity across interactions, which human or organization it acts on behalf of, or exactly which actions it is authorized to take [1]. AIP is not a working, deployed system: this pass reviewed the draft's abstract and introduction and did not verify the full delegation-chain wire format, so claims about a specific probeable endpoint or resolvable path cannot be made honestly at this time.
Current state: draft-singla-agent-identity-protocol-03, published 2026-06-10, a sole-author IETF Internet-Draft under the Network Working Group umbrella (not a chartered WG) [2]. The author lists "Standards Track" as the intended status, but this is the author's own stated intent, not an indication of IETF working-group consensus or adoption — no WG has taken up this document as far as this check found [2].
Who implements it: no implementation, reference library, or deployment was located in this pass.
Disputed or unknown: whether AIP will be picked up by any chartered WG or remain an individual proposal; how it relates to, competes with, or could compose with ERC-8004's onchain identity model or ANS's DNS-anchored model (both also in this Identify layer) is not addressed in the reviewed text. The AIP acronym also collides with other unrelated agent-interaction proposals circulating in the same space, so readers should confirm they mean this specific draft.
Discovery and probe
W3C Decentralized Identifier (DID) resolution plus cryptographic delegation-chain verification · none
n/a n/a (client-side protocol; no fixed origin artifact) parse: n/a on absent: Absence of a site artifact means nothing; AIP is negotiated between agents.
History
- 2026-09-05 — seeded from Exa Agent research run
- 2026-09-06 — verified against draft-singla-agent-identity-protocol-03's abstract, introduction and document header; flagged limited depth of review and the AIP acronym collision
Instances
- aip-agents (Sunil Prakash) · Observed 2026-04-02 · service
See also
- Not to be confused with: Agent Interaction Protocol (unrelated proposals sometimes use the same AIP initialism)
References
- AIP defines a decentralized identity, delegation and authorization framework for autonomous AI agents combining W3C DIDs, capability-based authorization, cryptographic delegation chains and deterministic validation, aiming to avoid reliance on centralized identity providers; it is a sole-author Internet-Draft (Paras Singla, Independent) with Standards Track as the author's intended status, and no working-group sponsorship, as shown on its ietf.org archive header — https://www.ietf.org/archive/id/draft-singla-agent-identity-protocol-03.html (2026-06-10) REPORTED
- The IETF Datatracker's document page for draft-singla-agent-identity-protocol shows Document Type 'Active Internet-Draft (individual)', RFC stream '(None)', Intended RFC status '(None)', and last updated 2026-06-09 -- confirming no working-group has taken up the draft. — https://datatracker.ietf.org/doc/draft-singla-agent-identity-protocol/ (2026-06-09) REPORTED
Disputed: This is a single-author draft with an author-stated Standards Track intent but no WG sponsorship and no located implementation; the acronym AIP is also used elsewhere for unrelated agent-interaction proposals, which is a collision worth flagging to readers.