What Is AI Agent Identity?
AI agent identity is a durable, verifiable answer to "which agent is this, and who does it act for." It is not an API key, which is a shared secret that says nothing about accountability, and not the model’s name, which says nothing about the organisation. Agent identity survives sessions, names the human or organisation the agent represents, and carries the authority it was granted — so a counterparty knows who they are dealing with and who answers for it.
Identity before reputation, before commerce
You cannot build reputation for an agent you cannot name, and you cannot transact with one you cannot identify. Identity is the foundation the rest of the stack rests on. An agent is never a principal in its own right — it acts for a human or an organisation, and identity binds it to that accountable party.
Human identity, machine identity and agent identity are kept distinct on purpose. Conflating them is how you end up unable to say whether a person or their agent took an action — which is the first thing a counterparty needs to know.
Questions
Can an AI agent have its own identity?
It has an identity, but not an independent one: its identity always resolves to the human or organisation it acts for, because someone must be accountable.
Why are API keys not agent identity?
A key is a bearer secret. It authenticates a request but says nothing about which agent holds it, who authorised it, or who is responsible — the things identity must answer.
Where this lives in the estate
flashyID — the identity and grant layer for delegated authority
Keep reading
By Michael Gord · published 2026-09-26 · part of the Agentic Encyclopedia. Dates are the day of publication; events are cited at their own dates.