agenticweb.wiki

Workload Identity in Multi System Environments (WIMSE) Architecture WIMSE

Identify WIMSE (Workload Identity in Multi System Environments) is an IETF architecture for how software workloads authenticate to each other and to services when they span multiple platforms, cloud providers, or trust domains — a scope broader than SPIFFE's original single-organization workload identity model [1]. It is relevant to the Identify layer of this map because a separate IETF individual draft on AI-agent authentication explicitly proposes using WIMSE (together with SPIFFE and OAuth 2.0) as the basis for how an agent authenticates, rather than inventing a new agent-specific protocol [2].

Overview

It solves cross-domain workload authentication architecture: defining the roles, trust relationships and token-exchange flows needed when a workload in one organization's environment needs to prove its identity to a service in another's. It does not itself define a single concrete wire protocol usable end to end — as an architecture document, its concrete mechanics (issuance formats, token exchange endpoints) are specified in sibling documents produced by the same WIMSE Working Group, which this pass did not review in depth. It also makes no agent-specific claims on its own; "AI agent" does not appear to be native vocabulary of the WIMSE WG's charter as reviewed here — the agent application again comes from the outside aiagent-auth draft.

Current state: this is a genuine chartered IETF Working Group document — draft-ietf-wimse-arch, currently at revision -08, last updated 2026-07-06, on the IETF RFC stream — which gives it firmer standards-track footing than several of the individual-submission drafts elsewhere in this map [1]. It replaces the authors' earlier individual submission, draft-salowey-wimse-arch, first published in March 2024 [1].

Who implements it: no concrete implementation was verified in this pass; the wimse WG maintains its work in a public GitHub organization (ietf-wg-wimse) referenced from the datatracker page [1], but this check did not survey deployed implementations.

Disputed or unknown: whether or when WIMSE will produce a companion document specifically profiling AI agents (as opposed to the outside aiagent-auth draft doing so unofficially), and what concrete, probeable endpoint the architecture resolves to in practice, are both open.

Discovery and probe

Workload identity issuance and cross-trust-domain token exchange (architecture defines roles and flows; concrete wire mechanics are in sibling WIMSE WG documents) · none

n/a n/a (workload identity architecture; no fixed origin artifact)
parse:     n/a
on absent: Absence of a site artifact means nothing; WIMSE governs workload-to-workload identity, not a site-facing endpoint.

Not probed live: not-http. WIMSE is an architecture for workload identity with no origin artefact.

History

Instances

No instances recorded yet.

See also

References

  1. WIMSE architecture draft-ietf-wimse-arch is an active WG Document of the IETF wimse Working Group, RFC stream IETF, currently at revision -08 (last updated 2026-07-06), replacing the earlier individual draft-salowey-wimse-arch — https://datatracker.ietf.org/doc/draft-ietf-wimse-arch/08/ (2026-07-06) REPORTED
  2. The IETF individual draft on AI-agent authentication (draft-klrc-aiagent-auth-03) explicitly proposes using the WIMSE architecture, alongside SPIFFE and OAuth 2.0, as the basis for agent authentication rather than defining new protocols — https://www.ietf.org/ietf-ftp/internet-drafts/draft-klrc-aiagent-auth-03.html (2026-07-06) VERIFIED

Disputed: Like SPIFFE, WIMSE is a general workload-identity architecture; its relevance to agent identity comes from a separate, unaffiliated IETF individual draft that proposes applying it to AI agents. Unlike the Signature Agent Card, WIMSE IS a chartered-WG document, giving it a firmer governance footing than several other records in this step.

JSON · Markdown