Data as of Aug 25, 2026 · Based on 42 AI responses from ChatGPT Search and Google AI Mode · See how Parse measures this
Your brand can be here too.
As autonomous AI agents shift from chatting to executing multi-step workflows, calling tools, and transacting on our behalf, the traditional security perimeter is breaking down . We are moving from a web of human-authenticated sessions to an agentic web , where software acts as the primary user.
Securing this shift requires solving three core pillars: Identity (who/what is this agent?), Trust (is it authorized and bound to a verified human/organization?), and Authentication (how does it securely access APIs and data without leaking secrets?).
Several specialized startups and emerging platforms are defining this space:
If you're exploring this space for a specific use case, let me know:
I can dive deeper into the specific architecture you might need.
Yes. The interesting market is emerging around a shift from “authenticate the human” to “authenticate the agent, its principal, its authority, and the action.”
I’d divide the startups into roughly five layers:
These are probably the closest to what you mean by “agents are users.”
A useful way to think about this category is:
Human → authorizes agent → agent receives bounded authority → service verifies agent + principal + scope → action is auditable. That is fundamentally different from giving an LLM a user's API key.
This is a more nascent category, and potentially the most interesting if you're thinking about an open Internet of agents rather than enterprise IAM.
The missing primitive here is something like:
Agent passport = identity + owner + provenance + capabilities + reputation + current authorization.
That's much closer to a driver's license / business registration than today's API token.
This becomes crucial when an agent crosses into the real economy.
The key question these companies answer isn't merely:
“Is this agent legitimate?”
It's:
“Is there a real, verified entity behind this agent, and did that entity authorize this action?”
This is the enterprise-security version of the problem.
Some of the startups here are less “agent identity companies” and more machine identity / workload identity companies being pulled toward agents.
The underlying realization is that an AI agent isn't just another application. It can dynamically acquire credentials, call APIs, delegate to other agents and potentially operate for hours without a human watching it.
So credential lifecycle becomes agent lifecycle.
This may ultimately be the biggest commercial manifestation.
The emerging stack looks something like:
Person → Agent → Verified identity → Authorization → Payment credential → Merchant → Settlement
That's why companies like Stripe, Visa, Mastercard and Cloudflare are suddenly building agent-specific payment/identity primitives. The core problem isn't technically “can an agent buy something?”—it's how does the merchant know which person authorized the purchase and what the agent was permitted to do?
Cloudflare's move is particularly interesting because it combines agent identity + wallet + spending controls, effectively treating the agent as an economic actor with bounded financial authority.
If I were making a 2026 watchlist specifically for “the web where agents are users,” I'd start with:
And I'd put Stripe, Visa, Mastercard, Cloudflare and Okta in a separate category: not startups, but potentially the biggest infrastructure incumbents competing to own pieces of this layer.
I think the eventual identity stack looks less like today's:
User → login → session and more like:
Principal → agent identity → delegation → capability → transaction → cryptographic evidence The really valuable primitive is therefore not simply “agent authentication.”
It's verifiable agency:
Who is responsible for this agent? What exactly was it authorized to do? Who delegated that authority? What did it actually do? And can another party independently verify all of that? That's why Proof's x401 is particularly notable: it is attacking the authorization provenance problem rather than merely putting OAuth in front of an LLM.
And the research literature is converging on essentially the same missing pieces: persistent agent identity, capability verification, delegation, trust negotiation and accountability.
If you're evaluating this as a startup/investment landscape, I'd actually map these companies on a 2×2 of human↔agent identity vs. agent↔agent trust, because there is a surprisingly large white space in the upper-right quadrant.
If by “the web where agents are users” you mean a world in which an AI agent can log in, delegate authority, buy things, access data, call APIs, and act on behalf of a person or company, I’d split the startup landscape into a few layers.
The interesting shift is that authentication (“who are you?”) is becoming only one piece. The harder questions are: who authorized you, what are you allowed to do, what are you allowed to spend, and can the relying party verify all of that? Recent industry work is explicitly converging on those questions.
I'd distinguish agent identity from agent trust.
A useful architecture looks something like:
Human / organization ↓ delegates authority ↓ Agent identity ↓ verifiable capabilities + permissions ↓ specific transaction/action ↓ audit trail + reputation
The startups above occupy different points on that stack.
The really valuable primitive may ultimately be a portable, verifiable delegation credential: “Agent X is acting for Principal Y, under authorization Z, with these constraints, and this authorization hasn't been revoked.”
That is substantially more useful than simply giving an agent an OAuth token.
Proof is particularly interesting here because x401 is explicitly attacking the missing link between an agent and the authority behind that agent.
Astrasync is interesting from the complementary direction: what is this agent, has it been verified, and should I trust it?
And Stytch is attacking the practical application layer: how does my website authenticate, authorize, consent, throttle and revoke these agents?
That gives you a rough emerging stack:
| Layer | Question | Companies to watch |
|---|---|---|
| Human identity | Who is the principal? | Proof, traditional identity vendors |
| Agent identity | Which agent is this? | Astrasync, Stytch |
| Delegation | Who authorized it? | Proof |
| Authorization | What may it do? | Stytch, Saviynt, Token Security |
| Agent security | Is it behaving safely? | Token Security, Obsidian |
| Trust/reputation | Should I trust this agent? | Astrasync + emerging protocols |
| Commerce authorization | May it transact/spend? | Stripe, Visa, Mastercard + startups |
| Human/agent distinction | Is there actually a human behind this? | Tools for Humanity, Proof |
One important wrinkle: the biggest winners may not look like identity startups today. Payments companies, browsers, API gateways, cloud IAM vendors and commerce platforms all have a natural claim on this layer. The emerging agentic-commerce battle is already being framed around authorization, agent-specific credentials and proof of user intent.
If I were building a 2026 landscape map and wanted the 5 names most worth studying deeply, I'd start with:
And I'd keep Saviynt in the “large incumbent that could become enormous in this category” bucket.
The underlying startup opportunity is bigger than “AI auth.” It is arguably the identity layer for machine-to-machine society: persistent identity, delegation, capability, reputation, payment authority and accountability for software that can act without a human clicking every button. Recent research is independently converging on persistent agent identity and verifiable capability as missing infrastructure, which is a good signal that this is becoming a real protocol layer rather than merely an IAM feature.
That is substantially more useful than simply giving an agent an OAuth token.
Proof is particularly interesting here because x401 is explicitly attacking the missing link between an agent and the authority behind that agent.
Astrasync is interesting from the complementary direction: what is this agent, has it been verified, and should I trust it?
And Stytch is attacking the practical application layer: how does my website authenticate, authorize, consent, throttle and revoke these agents?
That gives you a rough emerging stack:
| Layer | Question | Companies to watch |
|---|---|---|
| Human identity | Who is the principal? | Proof, traditional identity vendors |
| Agent identity | Which agent is this? | Astrasync, Stytch |
| Delegation | Who authorized it? | Proof |
| Authorization | What may it do? | Stytch, Saviynt, Token Security |
| Agent security | Is it behaving safely? | Token Security, Obsidian |
| Trust/reputation | Should I trust this agent? | Astrasync + emerging protocols |
| Commerce authorization | May it transact/spend? | Stripe, Visa, Mastercard + startups |
| Human/agent distinction | Is there actually a human behind this? | Tools for Humanity, Proof |
One important wrinkle: the biggest winners may not look like identity startups today. Payments companies, browsers, API gateways, cloud IAM vendors and commerce platforms all have a natural claim on this layer. The emerging agentic-commerce battle is already being framed around authorization, agent-specific credentials and proof of user intent.
If I were building a 2026 landscape map and wanted the 5 names most worth studying deeply, I'd start with:
As autonomous and semi-autonomous AI agents transition from chat-based assistants to active digital workers—reading emails, querying production databases, executing code, and transacting via APIs —the traditional web identity stack is breaking down.
Human identity models (OAuth tied to a person, session cookies, passwords) and static machine identities (hardcoded API keys, over-privileged service accounts) cannot handle workflows where an agent dynamically chains tools at machine speed.
A specialized ecosystem of startups and platforms has emerged to define Agentic Identity and Access Governance (AIAG) , treating AI agents as first-class, accountable actors on the web.
These startups focus specifically on giving non-human agents a cryptographic or managed identity, scoping their permissions, and acting as a runtime proxy for verification.
Because AI agents interface with internal resources via Non-Human Identities (tokens, MCP servers, OAuth grants), specialized NHI security startups have rapidly expanded their scopes to cover agentic trust.
While identity answers "who is this agent and what is it allowed to touch?" , runtime posture startups ensure the agent isn't being manipulated or going rogue mid-task.
Key Architectural Shifts Defining the Space
If you are looking at how these startups are architecting trust for an agent-led web, they generally reject traditional boundaries in favor of three principles:
If you're exploring this space technically or commercially, would you like to dive deeper into how Model Context Protocol (MCP) impacts agent authentication , or look at how legacy IAM providers (like Okta or Microsoft Entra) are responding to these startups?
As AI agents transition from experimental chat interfaces to autonomous actors that browse the web, invoke tools via the Model Context Protocol (MCP), execute APIs, and complete financial transactions, the foundational assumption of the internet breaks: traditional IAM (Identity and Access Management) was built for static machines or authenticated humans, not continuous, reasoning software.
Securing this "agentic web" requires new primitives—moving away from static API keys and over-privileged service accounts toward delegated authority chains, ephemeral runtime tokens , and verified human-owner binding.
A distinct group of startups and specialized platforms are defining this new stack for identity, trust, and authentication:
These companies focus on discovering, mapping, and issuing dynamic, short-lived credentials to autonomous software agents and preventing credential abuse or lateral movement across toolchains.
- [Aembit](https://aembit.io/blog/10-identity-security-vendors-for-ai-agents-strengths-tradeoffs-and-how-they-fit/) : Provides workload IAM and cryptographic identity for agents, issuing short-lived, scoped credentials on-demand to replace hardcoded secrets and standing access when agents call backend systems.[](https://aembit.io/blog/a-catch-up-guide-to-authentication-for-agentic-ai/) [[1]](https://aembit.io/blog/a-catch-up-guide-to-authentication-for-agentic-ai/)
- [Entro Security](https://entro.security/) : Focuses on Non-Human Identity Detection and Response (NHIDR), tracking secrets, mapping agent lineages to cloud and SaaS tools, and continuously monitoring agent behaviors for anomalies.[](https://entro.security/) [[1]](https://entro.security/)
- [Agentic Fabriq](https://www.ycombinator.com/companies/industry/identity) : A YC-backed startup providing a dedicated control framework to manage what AI agents can access across business tools, applying per-agent identities, scoped permissions, and audit logs.[](https://www.ycombinator.com/companies/industry/identity) [[1]](https://www.ycombinator.com/companies/industry/identity)
For high-stakes actions, e-commerce, or financial transactions, knowing an agent's technical signature isn't enough; systems need to verify the intent and identity of the human owner standing behind the autonomous workflow.
- [Incode](https://www.incode.com/use-cases/agentic-identity/) : Pioneered dedicated *Agentic Identity* capabilities that bind an autonomous agent to a verified human owner via deepfake-resistant biometrics, issuing cryptographic intent tokens with programmable expirations.[](https://www.incode.com/press/incode-launches-agentic-identity-to-verify-and-secure-ai-agents) [[1]](https://www.incode.com/press/incode-launches-agentic-identity-to-verify-and-secure-ai-agents)[[2]](https://www.incode.com/blog/incode-launches-agentic-identity)
- [Vouched](https://www.vouched.id/learn/agentic-ai-identity-verification-startup-vouched-gets-17m-to-build-trust-in-autonomous-agents) : Builds proprietary heuristics and detection layers (such as *Agent Shield* ) to help website and application operators differentiate between human users and autonomous agents, assigning session visibility and tracking what actions agents perform on consumer surfaces.[](https://www.vouched.id/learn/agentic-ai-identity-verification-startup-vouched-gets-17m-to-build-trust-in-autonomous-agents) [[1]](https://www.vouched.id/learn/agentic-ai-identity-verification-startup-vouched-gets-17m-to-build-trust-in-autonomous-agents)
These platforms act as real-time policy enforcers, intercepting tool execution and API calls to ensure agents do not drift outside designated business or security parameters.
- [SecureAuth](https://secureauth.com/newsroom/govern-ai-agent-identities-real-time) : Launched the *Agent Authority Platform* alongside its public *Agent Trust Registry* , providing real-time zero-trust runtime control over agent actions, intent-scoped delegation limits, and instant quarantine protocols if an agent behaves anomalously.[](https://www.humansecurity.com/learn/blog/agentictrust-govern-ai-agents/) [[1]](https://www.humansecurity.com/learn/blog/agentictrust-govern-ai-agents/)[[2]](https://secureauth.com/newsroom/govern-ai-agent-identities-real-time)[[3]](https://secureauth.com/products/agent)
- Enterprise giants and developer platforms like [Auth0 for AI Agents](https://auth0.com/ai) and [Teleport](https://goteleport.com/) are aggressively extending their ecosystems with features like *Token Vault* for managed OAuth tool delegation, *Async Authorization* for human-in-the-loop approvals, and hardware-rooted ephemeral privileges for MCP tooling.[](https://goteleport.com/) [[1]](https://goteleport.com/)[[2]](https://auth0.com/blog/introducing-auth0-for-ai-agents/)
Would you like to explore how these platforms handle a specific protocol like Model Context Protocol (MCP) security, or are you looking at this from an inbound consumer-facing vs. internal enterprise perspective?
Yes. The interesting thing in 2026 is that “agent identity” is splitting into several different markets. The winners may not be the companies building another login system; they may be the ones that establish the primitives for delegation, provenance, runtime authorization, and counterparty trust.
My current map:
| Startup | What it is trying to own | Why it matters |
|---|---|---|
| Proof | Human → agent delegation + verifiable identity | Its x401 protocol lets a website/API challenge an agent for cryptographic proof of the human behind it and the authority delegated to it. This is the closest thing I've seen to an emerging “identity layer for the agentic Web.” www.proof.com |
| Keycard | Agent IAM / runtime authorization | Treats the agent as a first-class identity, then issues short-lived, task-scoped credentials and evaluates policy at each tool call. It has raised $38M across seed + Series A. www.keycard.aitechcrunch.com |
| NewCore | Identity provider for the human + agent workforce | Emerged from stealth with $66M and is explicitly building a new IdP model where humans, delegated agents, autonomous workloads and machine identities share one governance layer. techcrunch.comnewcore.com |
| Oak | Identity operating system / identity graph | Rather than another point solution, Oak wants one live graph covering humans, machines and agents, with discovery and governance across the whole identity estate. www.oak.id |
| Clerk | Developer-facing agent identity | Clerk recognized early that agents need to act on behalf of users with granular permissions and auditability, and has made “Agent Identity” a major product direction. clerk.com |
| Skyfire | Know Your Agent + agent commerce | Takes the counterparty's perspective: “I don't know this agent, so prove what it is.” Its KYA system gives agents verified identities and histories, coupled to autonomous payments. skyfire.xyz |
| Arcade.dev | Agent authorization | Focuses less on “who are you?” and more on “what exactly may you do?” It raised $60M Series A in June 2026 and explicitly separates agent reasoning from the authorization of actions. www.wsj.com |
| Willow | Enterprise agent access | Gives every enterprise agent an identity, scoped access, runtime guardrails and an audit trail tied back to a human. Raised $7M seed in June. withwillow.ai |
| Archestra | Agent security gateway | More security/control-plane than identity provider: sits between agents and tools, enforcing access and preventing prompt-injection/data-exfiltration paths. Raised $10M seed in June. synaptic.com |
| t54 Labs | Trust/risk layer for autonomous economic actors | Raised $5M to tackle identity, risk assessment and accountability specifically when agents start moving money and making economic decisions. www.t54.ai |
1. Proof — if you mean “identity for the open Web.”
This is the most conceptually ambitious. Its x401 protocol is analogous to x402's role for payments: an HTTP-native challenge in which a server can say, essentially, “prove the identity/authority behind this agent before I let you proceed.”
The interesting primitive isn't authentication by itself. It's the chain:
human → authorization mandate → agent → action → verifiable record
Proof's implementation uses Verifiable Credentials, OpenID4VP and scoped delegation.
If x401—or something structurally similar—becomes ubiquitous, it could become a fundamental Web primitive rather than merely another IAM product.
2. Keycard — if you mean “identity + authorization inside enterprises.”
Keycard's thesis is that the unit of authorization isn't:
user → application
but:
user + device + agent + task → specific action
It then issues ephemeral credentials for that action and records the result. That's a very strong model for coding agents, MCP servers and multi-agent systems.
3. NewCore / Oak — if you mean “the next enterprise IAM.”
These two are attacking the bigger organizational problem.
NewCore says essentially: stop treating agents as weird service accounts; make them first-class identities alongside employees.
Oak is taking an even broader “identity operating system” position, building a graph across human, machine and AI-agent identities.
The enormous funding going into this category is a signal: NewCore alone emerged with $66M, while Keycard has $38M and Oak has reportedly raised $60M.
I wouldn't analyze this market as “startups versus Okta.” The existing identity vendors are moving very quickly.
So the startup opportunity is increasingly not “build OAuth again.”
I think the emerging stack looks something like this:
1. Agent identity
What software is this? What runtime/operator does it belong to?
→ Keycard, NewCore, Oak, Clerk
2. Principal/delegation identity
Which human or organization is ultimately responsible for it?
→ Proof, Clerk, NewCore
3. Authentication / attestation
Can I cryptographically establish that this really is that agent/runtime?
→ workload identity, mTLS, Web Bot Auth, OAuth extensions
4. Authorization
What is this agent allowed to do right now?
→ Keycard, Arcade, NewCore, Willow
5. Counterparty trust
Should my website/business trust this particular agent?
→ Proof, Skyfire, KYA systems
6. Accountability / provenance
Can I prove who authorized an action after the fact?
→ Proof, Keycard, enterprise IAM platforms
7. Economic identity
Who is allowed to spend, receive money, sign contracts, or incur liability?
→ Skyfire, t54, payment networks
And this is why I think authorization is ultimately more important than authentication. An authenticated agent with excessive authority is still dangerous. The hard problem is preserving a chain of authority as an agent delegates to sub-agents, invokes tools, crosses organizational boundaries, and acts autonomously.
That's also where the emerging protocols matter. MCP is largely about agent ↔ tool, A2A about agent ↔ agent, while emerging identity work is trying to answer “who is behind this agent and what authority travels with it?” The OpenID Foundation's agent-identity work explicitly frames authentication, authorization, workload identity and delegated authority as the unresolved architectural questions.
If I were building an investment/competitive landscape today, I'd put these in the highest-conviction watch bucket:
Proof → Keycard → NewCore → Oak → Clerk → Skyfire → Arcade
with very different theses:
The really interesting question is which of these becomes a protocol/network rather than a SaaS product. That distinction could determine who actually defines the “trust layer” of the agent Web.
The transition from a web of human-driven clicks to an ecosystem where autonomous AI agents act as primary users has broken traditional Identity and Access Management (IAM). Standard IAM expects static user logins, predictable request-response cycles, and single-tenant boundaries . Agents, by contrast, operate continuously, make non-deterministic runtime decisions, jump across third-party APIs via protocols like the Model Context Protocol (MCP), and chain multi-agent workflows.
A dedicated class of startups and infrastructure providers has emerged to solve this Agentic Identity Crisis by building specialized control planes, authentication brokers, and delegation frameworks.
These companies sit in the middle of agent-to-tool interactions, transforming chaotic N -to- N tool integrations into a unified hub-and-spoke control plane that handles delegated OAuth and short-lived tokens.
Unlike human users, an AI agent might touch an LLM via an API key, an internal microservice via mTLS, a cloud database via a managed identity, and a SaaS app via an MCP token—all within a single execution step. These startups treat agents as complex, multi-protocol workloads.
Because agents authenticate using machine credentials, they function as non-human identities (NHIs). These platforms discover "shadow agents" and govern their lifecycles.
The Emerging Architectural Playbook
These startups are actively helping the ecosystem converge around open standards to handle "On-Behalf-Of" (OBO) delegation:
auth.md allow agents to dynamically discover how to register, authenticate, and request token scopes cleanly within autonomous loops.Would you like to explore how these startups handle multi-agent delegation chains (e.g., a primary orchestrator delegating sub-tasks to specialized worker agents), or are you looking at this from a developer integration vs. enterprise governance perspective?
If you mean “who is building the identity/authentication layer for an Internet where software agents—not just humans—are principals?”, I’d watch a fairly small group. The important distinction is that this is broader than “AI security”: the emerging stack needs to answer who is the agent, who authorized it, what is it allowed to do, and can the counterparty verify all of that?
| Company | What it is defining | Why it matters |
|---|---|---|
| Proof | Delegated identity / proof of authority | Probably the clearest bet on an agentic Internet identity protocol. Its x401 lets a website/API challenge an agent for cryptographic proof of the human behind it, the scope of authorization, and the relevant claims. www.proof.comstytch.comarchestra.aiworkos.comsynaptic.com |
| Keycard | Agent identity + authorization control plane | Treats identity as user + device + agent + task, then issues short-lived, scoped credentials for individual tool calls. This is particularly compelling for enterprise agents and MCP. docs.keycard.aiwww.proof.com |
| Aembit | Workload / non-human identity | Extends workload identity to agents: its “blended identity” combines the human principal and the agent identity, with policy-based, short-lived access rather than secrets embedded in agents. docs.aembit.iodocs.keycard.ai |
| Stytch | Application authentication for humans + agents | The most obvious developer-platform play: authentication, authorization, consent, MCP auth and agent fraud/abuse detection packaged into the identity layer developers already use. stytch.com |
| Archestra | Agent gateway / runtime trust | More security gateway than pure identity, but important because identity only becomes meaningful if every tool/API action passes through an enforceable policy boundary. Its open-source gateway sits between agents and tools. archestra.ai |
| Astrasync AI | Portable agent identity + reputation | Interesting “agent passport” direction: registration, verification and trust scoring for agents operating inside an ecosystem. synaptic.com |
And then there are incumbent-adjacent startups/platforms worth watching, especially WorkOS, which is working through the credential question for agents acting on behalf of users, and Descope/Curity/Frontegg, which are adapting conventional identity primitives to agents.
I wouldn't think of this as one “agent authentication” market. I think there are four layers emerging:
1. Identity — “Who/what is this agent?”
Agent identity, workload attestation, persistent identifiers.
2. Delegation — “Who is behind it?”
A cryptographically verifiable chain:
human → authorization → agent → action
This is where Proof/x401 is particularly differentiated.
3. Authorization — “What may it do?”
Task-, resource-, user-, time-, amount- and context-scoped permissions. Keycard and Aembit are especially interesting here.
4. Trust / accountability — “Should I accept this action?”
Reputation, verified claims, audit trails, behavioral signals, fraud detection and ultimately cryptographic evidence.
That last distinction is important: authentication alone doesn't solve the agent problem. An authenticated agent can still be compromised, manipulated, or overprivileged. Recent research is already finding attacks that can manipulate web agents into initiating login flows, illustrating why “who are you?” and “should I trust this particular action?” have to be separate questions.
I think the biggest strategic question is whether the winning primitive looks like:
OAuth token:
user → agent → API
or something more like:
Verifiable delegation:
verified human → signed mandate → identified agent → scoped action → verifiable receipt
The second model is much closer to a web where agents are first-class economic actors. Proof is explicitly betting there, while Keycard/Aembit are attacking the enterprise execution side of the same problem.
And that's why x401 is particularly interesting: it attempts to turn identity from something established during login into something that travels with the agent's individual transaction.
If I were making a 2026 “agent identity infrastructure” watchlist, my top tier would therefore be Proof, Keycard, Aembit, and Stytch, with Archestra as the runtime-security wildcard and Astrasync as the more speculative portable-identity/reputation play.
If you mean startups building the identity/trust primitives for an Internet where an AI agent—not a human browser—is the principal, I’d watch a fairly tight group. The important distinction is between “AI security” broadly and companies actually solving who is this agent, who authorized it, what may it do, and can the counterparty verify that?
| Startup | Core bet | Why it matters |
|---|---|---|
| Proof | Cryptographic human→agent delegation | Probably the clearest bet on an Internet-native identity layer. Its x401 protocol lets a website/API challenge an agent for verifiable proof of the human or organization behind it and the scope of authorization. www.proof.comwww.proof.com |
| Skyfire | Agent identity + economic identity | Gives agents verified identity and payment credentials so they can transact across the open Internet. This is especially interesting because it treats identity and ability to pay as one trust stack. skyfire.xyz |
| Stytch | Auth infrastructure for agents | Taking conventional identity primitives—OAuth, sessions, consent, authentication—and adapting them for agents/MCP. It is arguably the strongest developer-infrastructure play rather than a new identity standard. stytch.com |
| Arcade.dev | Agent authorization | Less about proving who the agent is and more about proving what it is allowed to do. Its separation of reasoning from action and fine-grained permissions is an important missing layer. It raised a $60M Series A in 2026. www.wsj.com |
| Token Security | Non-human identity governance | Treats agents as part of the broader NHI universe—discovering agents, mapping them to humans/secrets/permissions, governing their lifecycle and continuously controlling them. www.token.security |
| Pomerium | Zero-trust access for agents | Applies identity-aware, per-request authorization to agents and MCP rather than handing them persistent credentials. Strong enterprise-infrastructure angle. www.pomerium.com |
| t54 | “Know Your Agent” + transaction trust | Focuses on identifying agents, assessing transaction risk and providing controls around autonomous financial activity. It raised a $5M seed backed by Ripple and others. www.t54.ai |
| Persona | Human↔agent identity verification | Extends KYC/KYB infrastructure into agentic commerce: verify the person behind the agent and the agent itself. Particularly relevant to regulated commerce. withpersona.com |
| Kite | Agent identity + wallet | Its Agent Passport combines an agent identity with programmable spending authority, giving autonomous agents a way to transact while retaining user-defined limits. www.globenewswire.com |
1. “Who is behind this agent?” — Proof, Persona, Skyfire
This is the most fundamental change. A normal web request says, essentially, “here are my cookies/API credentials.” An agentic request needs to say:
This agent represents Alice / Acme Corp; Alice authorized it to do X; authorization is still valid; and here is cryptographic evidence.
Proof's x401 is particularly notable because it tries to make that a protocol-level property of HTTP, analogous to how x402 makes payment a protocol-level property.
2. “What is this agent allowed to do?” — Arcade, Stytch, Pomerium
This is authorization rather than authentication.
The interesting primitive isn't merely:
Agent = Alice
but:
Agent = Alice + shopping-agent + <$500 + Amazon/Delta + expires 6pm
That distinction is becoming critical. Microsoft describes the agent identity problem similarly in terms of authentication, delegation, scoped permissions, policy enforcement and auditing.
3. “Can I trust this agent/counterparty?” — Skyfire, t54, Token Security
This is where identity becomes reputation and risk.
A future service may not merely ask “is this agent authenticated?” It may ask:
That is much closer to a credit bureau / certificate authority / fraud network for agents than today's login infrastructure.
4. “Can the identity travel with the agent?” — open protocols
This is the really consequential layer.
The Linux Foundation announced the Agent Name Service (ANS) in June 2026, explicitly aimed at portable identity, verification and discovery for agents across the Internet.
And Proof's x401 is explicitly issuer-neutral: the idea is that a service can request a credential and accept compatible proofs rather than forcing every agent onto one identity provider.
That suggests the eventual stack may look something like:
Human / organization
↓
verifiable identity
↓
delegation mandate
↓
agent identity
↓
scoped capabilities
↓
runtime / behavioral trust
↓
signed action
↓
merchant / API / another agent
If I were tracking this as an investment/technology landscape rather than simply compiling vendors:
Tier 1 — potentially foundational
Tier 2 — enterprise control plane 5. Token Security 6. Pomerium 7. Persona
Tier 3 — agentic commerce / financial trust 8. t54 9. Kite
And I'd watch the standards layer at least as closely as the startups. OAuth-for-agents, OpenID4VC, FIDO's agentic-authentication work, x401, x402, Google's AP2, Visa's agent protocols, and the Linux Foundation's ANS are competing to define the interfaces these companies ultimately have to plug into. The Linux Foundation's ANS announcement is especially significant because it frames agent identity as Internet infrastructure rather than another SaaS IAM feature.
The deepest startup opportunity, in my view, isn't simply “Okta for AI agents.” It's a new trust fabric where an agent can carry portable evidence of identity + authority + provenance + reputation, and where a counterparty can make an instantaneous decision about whether to let that agent act.
That's a substantially bigger category than authentication.
Okta
okta.com
As autonomous AI agents shift from novelty chatbots to active economic and operational actors, traditional Identity and Access Management (IAM)—built for humans clicking "Sign in with Google" or typing passwords—is breaking down . Startups and specialized platforms are rushing to build an Agentic Identity Access Platform (AIAP) layer.
The primary startups and infrastructure players defining identity, trust, and authentication for a web where agents are users span several key categories:
How the Technical Paradigm is Changing
These startups operate on a consensus model distinct from traditional IAM:
Would you like to explore how these agent identity frameworks integrate with protocols like OAuth 2.1/OIDC or how they handle human-in-the-loop approval workflows for high-stakes agent actions?