Observed Signal · Jun 24, 2026 · Technical Release · Source: DEV Community · Impact: 2/5 · Sentiment: Positive
Stapling tokens verifies humans across identity providers
The post describes a cross-issuer identity problem for AI agents: when an agent owned by Company A delegates work to a tool behind Company B's identity provider, standard RFC 8693 token exchange causes B to reissue a token that loses cryptographic proof of A's authentication. The author presents Crumb, a tamper-evident convention that 'staples' the original upstream JWT into the downstream token using new claims (prv, psh, pis). Verifiers can then walk the chained segments and validate each against the issuer's key, preserving human and actor continuity across domains. The approach is a Crumb convention (not an RFC), depends on an explicit federation trust set, and is available as a demo and GitHub repository.
Provides a practical convention and demo to improve cross-issuer auditability for agent-driven actions and identity provenance; relevant to identity and security teams but not an industry-wide standard or major platform policy change.
Track Real-Time Identity Signals & Market Shifts
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- RFC 8693 token exchange is commonly used to reissue tokens across identity providers but discards the upstream issuer's signature when B mints a new token.
- Crumb proposes carrying the original upstream JWT inside the downstream token via new claims: 'prv' (embedded JWT), 'psh' (SHA-256 hash of the embedded JWT), and 'pis' (original issuer).
- A verifier can walk the stapled token chain and verify each segment against the public key of the issuer that actually signed it, preserving human continuity and actor chain integrity across issuers.
- The Crumb demo implements cross-issuer delegation, verifies the chained provenance back to the human, and demonstrates five forgery/failure cases the verifier rejects.
- The Crumb project and demo are published publicly; the repo can be cloned from https://github.com/AlexlaGuardia/crumb and the live project is at https://crumb.alexlaguardia.dev/.
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
AI Agents Lack Distinct, Revocable Identities
The article describes operational, audit and revocation challenges that arise when AI agents run using human or shared credentials. Agents produce actions indistinguishable from their deploying humans in downstream logs, making attribution and targeted revocation difficult. The author recommends engineering controls: mint a distinct credential per agent/run/purpose, record ownership and scope in a register, issue short-lived credentials, and carry a run identifier through all agent outputs and API calls. The piece notes that while parts of the solution exist (cloud-issued process identities, short-lived creds), business systems like CRMs (e.g., Salesforce, HubSpot) often only model human seats, causing teams to share credentials. It flags a policy milestone: in June 2026 Estonia approved a framework for verifiable AI agent identities tied to the eIDAS 2.0 ecosystem.
TrustChain: Bilateral Records for Agent Trust
A developer argues that existing agent-trust proposals (identity registries, trust scores, audit stores, sybil detectors) treat trust as an add-on and therefore produce fragmented, non-composable systems. The author proposes starting from a single primitive — a bilateral signed interaction record (one JSON object with Ed25519 signatures from both parties) — and deriving identity, audit trails, delegation, sybil resistance and trust scores from the graph of those records. The post describes an open-source implementation called TrustChain (Rust sidecar, Python and TypeScript SDKs, 12 adapters), a live 21-agent simulation demo, and a GitHub repo. The author cites academic work (Prof. Pouwelse, TU Delft) on decentralized trust and claims the approach isolates sybil rings and yields verifiable, peer-held audit evidence without blockchains or tokens.
AI Agent Identity Crisis Meets Emerging Trust Infrastructure
A Cloud Security Alliance report warns that AI agents operate in an identity 'gray area' and need identity-centric controls and continuous visibility. Recent infrastructure moves — Coinbase x402 Foundation launching Agentic.market (backed by Google, Microsoft, AWS, Visa and Stripe), NIST creating a US AI Agent Standards Initiative, and Microsoft open-sourcing an Agent Governance Toolkit — signal rapid standardization across payments, identity and governance. The author argues a remaining gap is earned, verifiable reputation for agents, and describes a composable trust layer built from on-chain identities (ERC-8004), programmable escrow (ERC-8183), autonomous payments (x402) and reputation computed from escrowed, verifiable transactions. The piece cites market activity (Adobe, CoinDesk, Gartner) and calls out competing enterprise and crypto approaches to agent identity and trust.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
