Verifiable Credentials for AI Agents
A verifiable credential is a tamper-evident, cryptographically signed statement a holder can present and a verifier can check without calling the issuer. For agents they answer "prove you may do this": an agent presents a credential binding it to a human or organisation and to a set of permitted actions. The verifier checks the signature and the subject-to-holder binding — proving not just that a credential exists, but that this agent is its rightful holder.
Binding is the hard part
A signature proves a credential is authentic; it does not prove the presenter is its subject. An agent presenting a credential must also prove it is the holder that credential was issued to, or any agent that intercepts one could impersonate the subject. Verifying the chain, not just the signature, is the rule that separates real delegated authority from a replayed token.
Questions
Are verifiable credentials the same as JWTs?
A JWT can be a verifiable credential, but the model is broader: any signed, independently checkable claim about a holder, with a binding to the presenter.
Do credentials expire?
They should, and expiry must be derived from the credential’s kind rather than accepted as a presenter-supplied input that could be inflated.
Where this lives in the estate
FlashyID — the grant kernel for delegated, attenuated authority
Keep reading
By Michael Gord · published 2026-10-04 · part of the Agentic Encyclopedia. Dates are the day of publication; events are cited at their own dates.