> Markdown version of [/videos/100076-beyond-authentication-an-open-source-trust-model-for-the-agentic-web](https://www.wearedevelopers.com/videos/100076-beyond-authentication-an-open-source-trust-model-for-the-agentic-web). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Beyond authentication: an open-source trust model for the agentic web How do you safely scale AI agents across organizational boundaries? Learn how the open-source TSAI protocol moves beyond basic authentication using verifiable credentials and dynamic reputation. - **Speakers:** [Alexander Günsche](https://www.wearedevelopers.com/@alexander-gunsche), [Sabrina Engling](https://www.wearedevelopers.com/@sabrina-engling) - **Event:** World Congress 2026 Europe - **Published:** July 9, 2026 - **Duration:** 10:31 - **URL:** https://www.wearedevelopers.com/videos/100076-beyond-authentication-an-open-source-trust-model-for-the-agentic-web ## Summary As autonomous AI agents increasingly operate across organizational boundaries, relying on basic authentication falls short—it verifies identity but fails to establish transactional trust. This forces systems into an unscalable binary choice: blindly accept or unilaterally block agent traffic. The open-source TSAI (Trust Signals for Agentic Interactions) protocol bridges this gap by layering verifiable trust signals—such as reputation and economic stake—on top of identity. Built leveraging W3C Verifiable Credentials and Decentralized Identifiers (DIDs), TSAI equips agents with cryptographically signed credentials issued by impartial, independent trust authorities. A cornerstone of TSAI's architecture is its dynamic reputation system, which operates on a bidirectional feedback loop where agents and service providers regularly rate each other. This dual-rating strategy effectively mitigates bias and manipulation, establishing an objective behavioral track record over time. Because these credentials target the software agent rather than an individual user, the protocol preserves user privacy without demanding overhauls to existing authentication workflows. Through a flexible four-tier model, verifying systems can execute scaleable, offline validations for low-risk actions, while elevating to real-time verification checks for high-stakes transactions. To ensure robust security in widespread deployments, TSAI utilizes rapid credential lifecycles—often valid for just one hour—paired with a direct revocation registry to swiftly neutralize compromised agents. Furthermore, the architecture accommodates sub-agent multi-agent workflows by strictly requiring independent structural identities rather than loosely overlapping token delegations, retaining a highly auditable chain of trust. Grounded in accepted standards like IETF's RFC 9901 (SD-JWT), TSAI lays the foundational ecosystem for safely managing complex, cross-boundary machine-to-machine interactions. **Keywords:** tsai protocol, trust signals, agentic web, w3c verifiable credentials, decentralized identifiers, dynamic reputation system, two-sided feedback loop, cryptographic trust credentials, agent infrastructure, offline credential verification, rfc 9901, sd-jwt, agent marketplace authorization, autonomous agent authentication, sub-agent identity, credential revocation registry ## Chapters 1. **Mechanism of bidirectional trust and reputation building** (00:00) — How trust authorities mitigate bias through dynamic feedback between agents and service providers. 1. **Expanding the trust landscape to additional stakeholders** (02:13) — The role of observability tools, firewalls, and marketplaces in enforcing and scaling trust metrics. 1. **Handling stolen agents and credential revocation mechanisms** (04:35) — Methods for mitigating risk when using short-lived credentials and distributing verification statuses. 1. **Standardization bodies and verifiable credential protocol adoption** (06:36) — The collaboration between open-source protocols and established standard boards like IETF and W3C. 1. **Managing credential delegation in multi-agent application architectures** (07:56) — How identity operates when passing signing keys among service providers and sub-agents. 1. **Formatting conventions and ASCII usage in RFC 9901** (09:54) — The rationale behind syntax conventions standard to verifiable credential documentation. ## Related Moments - [Transitioning toward autonomous agentic commerce](https://www.wearedevelopers.com/videos/100002-the-new-financial-stack-ai-agents-and-trust) (from "The New Financial Stack: AI, Agents and Trust") - [Integrating artificial intelligence into user agentic commerce](https://www.wearedevelopers.com/videos/1381-402-payment-required) (from "402 - Payment Required") - [Mitigating excessive agency through scoped tool access](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) (from "Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue") - [Applying the TRUST framework to AI product architecture](https://www.wearedevelopers.com/videos/2098-why-most-ai-features-fail-after-the-demo) (from "Why Most AI Features Fail After the Demo") - [Current state of security in AI applications](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) (from "Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue") - [Managing autonomous agent trust and cloud permission gaps](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) (from "No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents") ## Related Articles - [WebMCP: Empowering Agents as First-Class Citizens of the Web](https://www.wearedevelopers.com/magazine/696-webmcp-empowering-agents-as-first-class-citizens-of-the-web) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Never delegate the understanding](https://www.wearedevelopers.com/magazine/749-never-delegate-the-understanding) - [The Web We Broke (And Why AI Agents Are Paying the Price) - AgentCon Berlin](https://www.wearedevelopers.com/magazine/735-the-web-we-broke-and-why-ai-agents-are-paying-the-price-agentcon-berlin) ## Related Jobs - [Security Architect - AI](https://www.wearedevelopers.com/jobs/ext/1581899-security-architect-ai) at **ZEISS Group** - [Principal Software Engineer, Identity](https://www.wearedevelopers.com/jobs/ext/1469181-principal-software-engineer-identity) at **GitHub** - [Senior AI Agent Software Engineer (Go, Python) (m/f/x)](https://www.wearedevelopers.com/jobs/48277-senior-ai-agent-software-engineer-go-python-m-f-x) at **Dynatrace** - [Senior Backend Developer — AI: MCP & Agent Engine](https://www.wearedevelopers.com/jobs/48297-senior-backend-developer-ai-mcp-agent-engine) at **basebox GmbH** - [Security Engineer](https://www.wearedevelopers.com/jobs/ext/1574416-security-engineer) at **Twilio** - [AI Software Engineer (Germany)](https://www.wearedevelopers.com/jobs/48317-ai-software-engineer-germany) at **Sunhat**