Decentralized Identifiers (DIDs) for AI Agents

A decentralized identifier (DID) is an identifier an entity controls without a central registrar, resolvable to keys and metadata for verification. For agents, DIDs offer a way to name an agent and prove control of its keys independent of any one platform — useful for portable identity. They answer "which key, controlled by whom," but not "what is this agent allowed to do," which is delegation; identity and authority remain distinct layers.

DID
Self-controlled, resolvable identifier
Gives agents
Portable, platform-independent naming
Proves
Control of keys
Does not answer
What the agent may do (authority)

Portable identity, still needing authority

A DID can make an agent’s identity portable and verifiable without depending on a single provider. But a verifiable identifier is not permission: knowing which key controls an agent says nothing about what it was authorised to do, or who is accountable. DIDs sit in the identity layer; delegation and the chain back to a human sit beside them in authority.

Questions

Do agents need DIDs?

DIDs are one way to give an agent portable, verifiable identity. They are not required, but they fit the goal of identity that does not depend on a single platform.

Does a DID authorise an agent?

No. It identifies and proves key control. What the agent may do is a separate, delegated, attenuated authority verified as a chain.

Where this lives in the estate

flashyID — verifiable identity and delegated authority

Keep reading

related
What Is AI Agent Identity?
related
How Should AI Agents Authenticate?
related
Delegated Authority for AI Agents
related
OAuth for AI Agents
referenced by
Verifiable Credentials for AI Agents
Identity & Authority
Key Management for AI Agents
Identity & Authority
How Delegation Chains Work for Agents

By Michael Gord · published 2026-10-02 · part of the Agentic Encyclopedia. Dates are the day of publication; events are cited at their own dates.