AI Agent Trust Overview

Gain control of agent sprawl

Inventory every AI agent and extend cryptographic trust across organizational boundaries.

See a demo

Get the data sheet

Secure agentic deployments

Discovery, federated identity, policy, and lifecycle management for every agent across your environments.

Find what exists

Discover built and third-party agents across your enterprise and environments in a single unified control plane.

Create a registry

Register agents in a private or public registry, capturing metadata for identity, policy, and control.

Issue passports

Bind agent identity, metadata, policies, capabilities, and authorized human ownership to the AI Agent Passport—a cryptographically verifiable trust artifact.

Enforce policy

Protect agentic sessions by evaluating identity and permissions, with automated kill switching when trust conditions change.

Stay audit ready

Record agent actions, permissions, and outcomes across every session for a tamper-evident audit trail.

Introducing the AI Agent Passport

The AI Agent Passport is modeled after the real thing—proving agent identity and encoding policy across digital environments.

Identity verification

Identity verification

Like a government-issued human passport, the AI Agent Passport carries cryptographic proof of the agent's identity—without shared secrets or passwords.

Interoperability

Interoperability

Physical passports conform to global standards. The AI Agent Passport is also standards-based (NIST NCCoE) and proves trust across vendors, clouds, and agent frameworks.

Privileges

Privileges

Like stamps and visas in a physical passport, the AI Agent Passport clearly defines agent privileges, showing what the agent can do, when, and where.

Walk through the AI Agent Trust lifecycle

Explore each stage of the AI agent governance lifecycle—from discovery and passport issuance to revocation of privileges and the automated kill switch.

Discover inventory

Expose shadow AI and account for every agent

  • Discover built and third-party agents across your environments
  • Build a private registry for internal use, identifying every agent
  • Publish select agents to DigiCert's public agent registry
Issue a passport

Give every agent an identity and define policies

Every agent gets a passport, in which you can encode:

  • The agent's bound SPIFFE workload identity
  • The systems and MCP connections it is authorized to access
  • The operations it is permitted to perform
  • The environments in which it may operate
  • The sensitivity level of data it is approved to handle
  • The policies that govern its behavior
  • The expiration and renewal lifecycle of its authorization
  • The organization that owns the agent
  • The named accountable human owner responsible for it
Control agent actions

Enforce policies to ensure every action is authorized

  • Intercept agent traffic at the DigiCert Enforcement Point or via MCP gateway
  • Establish a secure, encrypted communication channel using mTLS
  • Evaluate passport and permit or deny agent actions based on trust conditions
  • Authorize temporary or purpose-specific access based on defined policies
  • Automatically kill agent sessions when trust conditions change
Automate lifecycle management

Eliminate the risk of standing access

  • Automate workflows for passport issuance, renewal, and expiration
  • Set criteria for automatic passport revocation based on agent actions, connections, and trust conditions
  • Maintain auditable lifecycle state records for every agent
Simplify AI governance

Govern agents with the structural controls they require

  • Derive lineage from runtime enforcement and audit events
  • Review relationship graphs connecting agents to systems, models, connections, and data classifications
  • Maintain a tamper-evident audit trail of agentic sessions

Want to go deeper?

Read the AI Agent Trust eBook

Get the AI Trust white paper

Why leaders choose DigiCert for AI Trust

Internet scale

AI is proliferating quickly, and DigiCert brings the proven expertise in managing trust at internet scale.

Cross-organization trust

The DigiCert AI Agent Passport federates identity and trust across environments and organizations.

Cryptographic identity

With DigiCert, agent identity and policy are cryptographically encoded and verifiable.

"We see DigiCert AI Agent Trust as a promising approach to extending proven principles of digital identity to this new class of autonomous systems. The ability to verify an agent's identity, define what it is authorized to do, and maintain visibility into its actions could give organizations the foundation they need to adopt agentic AI with greater confidence."

Ajitha Choudary

Vice President, Global Security Engineering and IAM, UKG

Go deeper into AI Agent Trust

Data sheet

Get the technical product summary

Get the data sheet

Agentic AI Governance Fundamentals

Learn how to build a trust foundation for agents

Read the ebook

IDC Perspective: The Domain Is the Root of Trust

Explore an analyst take on DigiCert's unique approach to AI Trust

Get the report

AI Agent Trust Demo

Dive into the product and see how it works

Explore the demo

Verifiable trust based on open standards

DigiCert's AI Agent Trust solution is built on open standards for easy adoption and interoperability.

Standard
How it is used
Product role
PKI
Provides the certificate-authority trust model for issuing, validating, renewing, and revoking cryptographic agent identities.
Trust foundation
DNS / TXT records
Publishes domain-anchored trust declarations, issuing-CA information, permitted scopes, and policy lookup data.
Trust discovery
X.509
Represents short-lived agent and workload certificates, certificate chains, validity periods, and revocation state.
Core identity
SPIFFE
Defines portable workload identities and URI-based SPIFFE IDs across distributed environments.
Core identity
SPIFFE SVID
Supplies the short-lived verifiable identity document bound to a workload; typically carried as an X.509 certificate.
Credential format
SPIRE
Acts as the central certificate authority and registry that manages identity data.
Credential issuance
TLS & mTLS
Encrypts communications and mutually authenticates agents, enforcement points, gateways, and connected systems.
Secure transport
OpenID Connect
Supports federated cloud authentication where long-lived static provider credentials should be avoided.
Federation
MCP
Provides the tool and service connection interface where an MCP gateway can evaluate identity and authorization policy.
Agent integration
OPA
Enforces policies as encoded in the DigiCert AI Agent Passport.
Policy enforcement
NIST NCCoE
Industry best practice framework applied to the DigiCert AI Agent Passport to establish secure identity and authorization for agents.
Identity and authorization

Ready to scale agentic AI with confidence?

See how AI Trust Manager helps teams discover, authenticate, authorize, and govern AI agents across complex enterprise environments.

Book a live demo Talk to an expert