OpenID Foundation: Identity Management for Agentic AI [pdf] (2025)
Pangram verdict · v3.3
We believe that this text is a mix of AI and human-written content.
AI likelihood · overall
MixedArticle text · 426 words · 2 segments analyzed
Identity Management for Agentic AI The new frontier of authorization, authentication, and security for an AI agent world Lead Editor: Tobin South October 2025 Executive Summary The rapid rise of AI agents presents urgent challenges in authentication, authorization, and identity management. Current agent-centric protocols (like MCP) highlight the demand for clarified best practices in authentication and authorization. Looking ahead, ambitions for highly autonomous agents raise complex long-term questions regarding scalable access control, agent-centric identities, AI workload differentiation, and delegated authority. This whitepaper is for stakeholders at the intersection of AI agents and access management. It outlines the resources already available for securing today’s agents and presents a strategic agenda to address the foundational authentication, authorization, and identity problems pivotal for tomorrow’s widespread autonomous systems. Today’s frameworks handle simple AI agent scenarios: • AI agents differ fundamentally from traditional software; they take au- tonomous actions on external services, exhibiting non-deterministic, flexible behavior that adapts in real-time, rather than simply executing predetermined instructions. • Existing OAuth 2.1 frameworks, when used with AI agents, work well within single trust domains with synchronous agent operations (e.g., enterprise agents accessing internal tools, consumers accessing their services through AI tools), but may fall short in scenarios that are cross-domain, highly autonomous, or asyn- chronous, as well as those which require the agent to use or enforce delegated per- missions on behalf of multiple human users at the same time. • The Model Context Protocol (MCP) is leading in adoption as the key frame- work for connecting language models to external data sources and tools when building agents. Other approaches exist and should be supported, including function calling (tool use) and agent-to-agent (e.g., A2A) communication protocols. • Enterprise SSO and SCIM provisioning can help enable the use of en- terprise agents and facilitate centralized agent lifecycle management, as well as governance of permissions and access for various AI agent use cases. • Enterprise security profiles provide the baseline for safe AI adoption. To mitigate risks, this paper recommends that AI agents conform to rigorous, interop- erable profiles of existing identity standards. Working groups, such as the Interoper- ability Profiling for Secure Identity in the Enterprise (IPSIE), can provide guidance on this, giving organizations the confidence to adopt AI by ensuring robust controls are in place. • User-centric consent models are the foundation for consumer agents.
For agents connecting to third-party consumer services (e.g., email, social media, financial data), the established OAuth 2.1 user consent flow is the primary mechanism for granting delegated authority, making transparency and clear scope definition critical for user trust.