AI agents are calling your APIs. Your API gateway sees the request, your authorization server issues the token. But neither of them knows which agent made the call, whether it’s the same agent as last time, or whether it’s authorized to act on behalf of the user it claims to represent.
This session is about the identity layer that agentic systems are currently missing, and the emerging standard that addresses it: draft-ietf-oauth-client-id-metadata-document. We’ll cover why traditional OAuth client registration breaks down at agent scale, how the spec enables dynamic client identity without a registry, and why knowing the URL proves nothing, possession of the private key does. We’ll also cover what the spec doesn’t solve on its own, instance-level identity, the bootstrapping problem, and the gap between where the standard is and where enterprise authorization server support currently sits.
The goal is to leave you better equipped to evaluate, design, and challenge the identity layer in any agentic system you are building or buying.
This session will be held at at our upcoming event:
Nordic APIs Summit 2026
High impact blog posts and eBooks on API business models, and tech advice
Connect with market leading platform creators at our events
Join a helpful community of API practitioners
Can't make it to the event? Signup to the Nordic APIs newsletter for quality content. High impact blog posts on API business models and tech advice.
By clicking below, you agree that we process your information per the terms in our Privacy Policy.
Become a part of our global community of API practitioners and enthusiasts. Share your insights on the blog, speak at an event or exhibit at our conferences and create new business relationships with decision makers and top influencers responsible for API solutions.