Standards for Trusted Agentic Interactions
The FIDO Alliance is developing open, interoperable standards for agentic authentication and commerce
The Need for Standards in Agentic AI
AI agents are beginning to act on behalf of users – logging in, managing accounts, and executing transactions.
But today’s authentication and authorization models were built for direct human interaction, not delegated, agent-initiated actions.
- There is no consistent way to verify user intent
- Service providers cannot reliably validate agent identity
- Users may be required to expose credentials to agents
- Trust frameworks for agent-driven interactions do not yet exist
Industry-driven, interoperable standards are needed to address these challenges and establish a trusted foundation for agent-driven interactions across authentication and commerce.
Areas of Focus
FIDO Alliance is developing a standards-based foundation for trusted agentic interactions, focused on three core areas:
Verifiable User Instructions
Enabling users to authorize AI agents through phishing-resistant mechanisms, so agents perform only approved actions – including transactions – without exposing credentials.
Agentic Authentication
Enable users to let agents sign in on their behalf safely and in a controlled way that does not require agents to hold raw user credentials, and provides transparency, auditability and revocation
Trusted Delegation for Commerce
Defining how agent-initiated transactions execute within user-controlled boundaries, with verifiable authorization aligned to real-world commerce and payment flows.
Work Underway
The FIDO Alliance’s work in agentic AI is being carried out in its Agentic Authentication Technical Working Group, and the Payments Technical Working Group:
- The Agentic Authentication Technical Working Group is focused on how users securely and privately delegate actions to AI agents while maintaining strong, phishing-resistant authentication, including establishing clear boundaries between user-initiated and agent-initiated actions. The group is developing technical extensions, profiles, architectural frameworks, and best practices to enable secure, phishing-resistant, privacy-preserving authentication and delegated authority for AI agents acting on behalf of users.
- The Payments Technical Working Group is developing specifications for agent-initiated commerce including secure delegation, verifiable authorization and trusted transaction execution. These specifications will draw from initial contributions from Google (AP2) and Mastercard (Verifiable Intent) as a foundation that will be evaluated and further developed through FIDO’s open, collaborative standards process.
Get Involved
FIDO Alliance’s agentic AI work is open to member participation through both working groups. FIDO members can engage directly; non-members should explore FIDO membership to get involved.
