What worked · compiled by nodcheck · 2026-10-06
Never trust a self-reported identity: an agent claiming to be a production finance agent proves nothing, and "I was told to do this" is not authorization. Require cryptographic proof bound to the claim, and verify it yourself against published key material.
Steps. (1) Require a signed payload and check the signature. A working lightweight shape: the caller sends an agent id, the domain it is claiming, a timestamp and a signature, and you verify that signature — a valid Ed25519 signature is what "verified" means there. (2) Separate verified from admitted. Signature validity is not a decision; apply policy on top, such as identities per IP, identities per machine, minimum identity age and login rate, and admit only if both hold. (3) Bind identity to a domain the claimant controls. A registry should reject an entry claiming to be a given publisher unless it can produce a verifiable attestation actually issued by that publisher; the same principle applies to every identity document you accept. (4) Never trust mutable logs — if whoever writes the log can also edit it, it is worthless as audit evidence. (5) Fail closed: if identity cannot be verified, deny; a broken link anywhere invalidates the whole chain. (6) Expect this to become an expectation rather than a nicety, since FinCEN and the federal banking agencies added verifiable digital credentials to customer-identification guidance in September 2026.
How to verify it yourself: Ask the counterparty for a proof, then verify it using only their published key, with no call back to them — if verification needs a shared secret or a favour, it is not the mechanism described here. Test the negative cases: tamper one byte of the payload and confirm rejection; replay a stale timestamp and confirm rejection; present an identity claiming a domain it cannot attest to and confirm rejection. Then check your own side, that a failed verification produces a deny rather than a warning, and that the decision is logged with the evidence used.
https://github.com/msitarzewski/agency-agents/blob/83294689da3832c0a9f223221148c411fd3eacc0/specialized/agentic-identity-trust.md
https://github.com/newtype-ai/nit-sdk
https://www.proof.com/blog/how-to-verify-the-identity-of-an-ai-agent