AI Agent Trust overview

Gain control of agent sprawl

Inventory every AI agent and extend cryptographic trust across organizational boundaries.

See a demo

Get the data sheet

Gain control of agent sprawl

Secure agentic deployments

Discovery, federated identity, policy, and lifecycle management for every agent across your environments.

search-find-inspect.svg

Find what exists

Discover built and third-party agents across your enterprise and environments in a single unified control plane.

registry.svg

Create a registry

Register agents in a private or public registry, capturing metadata for identity, policy, and control.

ai-agent-passport.svg

Issue passports

Bind agent identity, metadata, policies, capabilities, and authorized human ownership to the AI Agent Passport—a cryptographically verifiable trust artifact.

document-secure-policy.svg

Enforce policy

Protect agentic sessions by evaluating identity and permissions, with automated kill switching when trust conditions change.

audit.svg

Stay audit ready

Record agent actions, permissions, and outcomes across every session for a tamper-evident audit trail.

Introducing the AI Agent Passport

The AI Agent Passport is modeled after the real thing—proving agent identity and encoding policy across digital environments.

Identity verification

Identity verification

Like a government-issued human passport, the AI Agent Passport carries cryptographic proof of the agent's identity—without shared secrets or passwords.

Identity verification
Interoperability

Interoperability

Physical passports conform to global standards. The AI Agent Passport is also standards-based (NIST NCCoE) and proves trust across vendors, clouds, and agent frameworks.

Interoperability
Privileges

Privileges

Like stamps and visas in a physical passport, the AI Agent Passport clearly defines agent privileges, showing what the agent can do, when, and where.

Privileges

Walk through the AI Agent Trust lifecycle

Explore each stage of the AI agent governance lifecycle—from discovery and passport issuance to revocation of privileges and the automated kill switch.

Discover inventory

Expose shadow AI and account for every agent

  • Discover built and third-party agents across your environments
  • Build a private registry for internal use, identifying every agent
  • Publish select agents to DigiCert's public agent registry
Issue a passport

Give every agent an identity and define policies

Every agent gets a passport, in which you can encode:

  • The agent's bound SPIFFE workload identity
  • The systems and MCP connections it is authorized to access
  • The operations it is permitted to perform
  • The environments in which it may operate
  • The policies that govern its behavior
  • The named accountable human owner responsible for it
Control agent actions

Enforce policies to ensure every action is authorized

  • Intercept agent traffic at the DigiCert Enforcement Point or via MCP gateway
  • Establish a secure, encrypted communication channel using mTLS
  • Evaluate passport and permit or deny agent actions based on trust conditions
  • Authorize temporary or purpose-specific access based on defined policies
  • Automatically kill agent sessions when trust conditions change
Automate lifecycle management

Eliminate the risk of standing access

  • Automate workflows for passport issuance, renewal, and expiration
  • Set criteria for automatic passport revocation based on agent actions, connections, and trust conditions
  • Maintain auditable lifecycle state records for every agent
Simplify AI governance

Govern agents with the structural controls they require

  • Derive lineage from runtime enforcement and audit events
  • Review relationship graphs connecting agents to systems, models, connections, and data classifications
  • Maintain a tamper-evident audit trail of agentic sessions

Want to go deeper?

Read the AI Agent Trust guide

Get the AI Trust white paper

Why leaders choose DigiCert for AI Trust

scale_white.svg

Internet scale

AI is proliferating quickly, and DigiCert brings the proven expertise in managing trust at internet scale.

trust-certified-authenticated_white.svg

Cross-organization trust

The DigiCert AI Agent Passport federates identity and trust across environments and organizations.

cryptography_white.svg

Cryptographic identity

With DigiCert, agent identity and policy are cryptographically encoded and verifiable.

"We see DigiCert AI Agent Trust as a promising approach to extending proven principles of digital identity to this new class of autonomous systems. The ability to verify an agent's identity, define what it is authorized to do, and maintain visibility into its actions could give organizations the foundation they need to adopt agentic AI with greater confidence."

Ajitha Choudary

Vice President, Global Security Engineering and IAM, UKG

ukg.svg

Go deeper into AI Agent Trust

Data sheet

Get the technical product summary

Get the data sheet

Guide

How to Trust AI Agents as they gain more autonomy

Get the guide

IDC Perspective: The Domain Is the Root of Trust

Explore an analyst take on DigiCert's unique approach to AI Trust

Get the report

AI Agent Trust demo

Dive into the product and see how it works

Explore the demo

Verifiable trust based on open standards

DigiCert's AI Agent Trust solution is built on open standards for easy adoption and interoperability.

Standard
How it is used
Product role
PKI
Provides the certificate-authority trust model for issuing, validating, renewing, and revoking cryptographic agent identities.
Trust foundation
DNS / TXT records
Publishes domain-anchored trust declarations, issuing-CA information, permitted scopes, and policy lookup data.
Trust discovery
X.509
Represents short-lived agent and workload certificates, certificate chains, validity periods, and revocation state.
Core identity
SPIFFE
Defines portable workload identities and URI-based SPIFFE IDs across distributed environments.
Core identity
SPIFFE SVID
Supplies the short-lived verifiable identity document bound to a workload; typically carried as an X.509 certificate.
Credential format
SPIRE
Acts as the central certificate authority and registry that manages identity data.
Credential issuance
TLS & mTLS
Encrypts communications and mutually authenticates agents, enforcement points, gateways, and connected systems.
Secure transport
OpenID Connect
Supports federated cloud authentication where long-lived static provider credentials should be avoided.
Federation
MCP
Provides the tool and service connection interface where an MCP gateway can evaluate identity and authorization policy.
Agent integration
OPA
Enforces policies as encoded in the DigiCert AI Agent Passport.
Policy enforcement
NIST NCCoE
Industry best practice framework applied to the DigiCert AI Agent Passport to establish secure identity and authorization for agents.
Identity and authorization

Ready to scale agentic AI with confidence?

See how AI Trust Manager helps teams discover, authenticate, authorize, and govern AI agents across complex enterprise environments.

See a demo

ai-trust-manager-screenshot.png

{{anchor:book-a-demo}}

Talk to an expert and book a demo

form sheet template
/forms/eloqua-gtm-system-master-form-contact-us
toc
701Vu00002xAYIVIA4
redirect
https://www.digicert.com/campaigns/thank-you
contactUsType
sales