How Should AI Agents Authenticate?

An AI agent should authenticate with a verifiable credential that names who it acts for and what it was authorised to do — not with a shared, long-lived API key that says nothing about accountability. Authentication proves identity; it must be paired with authorization, which proves what the agent may do. The strongest pattern binds a request to a delegation chain that a service can verify back to an accountable human.

Prove
Which agent, acting for whom
Avoid
Shared, long-lived bearer keys
Pair with
Authorization (what it may do)
Verify
The delegation chain, at use time

Authentication is not authorization

Proving an agent is who it claims does not tell a service what the agent is allowed to do. Authentication answers identity; authorization answers permission. An API key blurs the two and carries no accountability — anyone holding it is indistinguishable. A credential tied to a verifiable delegation chain answers both and names who is responsible.

Questions

Can agents use OAuth?

OAuth-style flows can grant an agent scoped access, which is a step up from a shared key. The key addition for agents is a verifiable chain back to the human who delegated the authority.

Why not just give an agent an API key?

A key authenticates a request but carries no identity or accountability — it cannot say which agent holds it or who authorised it, which is what a counterparty needs to know.

Where this lives in the estate

flashyID — verifiable identity and delegated authority

Keep reading

related
What Is AI Agent Identity?
related
Delegated Authority for AI Agents
related
AI Agent Governance and Accountability
related
What Is an A2A Agent Card?
referenced by
Decentralized Identifiers (DIDs) for AI Agents
referenced by
OAuth for AI Agents
referenced by
Key Management for AI Agents
Identity & Authority
Verifiable Credentials for AI Agents
Identity & Authority
How Delegation Chains Work for Agents

By Michael Gord · published 2026-09-29 · part of the Agentic Encyclopedia. Dates are the day of publication; events are cited at their own dates.