Repository navigation
docs: ADR-0007 — External JWKS federation for cross-org identity - #1385
Imran Siddique (imran-siddique) merged 1 commit into
Conversation
Addresses the structural gap in cross-org agent identity verification by proposing DNS-anchored JWKS federation as a provider-based extension to AGT's identity model. Responds to maintainer invitation in microsoft#1234. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
🤖 AI Agent: contributor-guide — 🌟 What You Did WellHello @first-time-contributor! 👋 Welcome to the microsoft/agent-governance-toolkit community! 🎉 Thank you for taking the time to contribute to this project — we’re thrilled to have you here. Your detailed and well-structured pull request is a fantastic first contribution, and we appreciate the effort you’ve put into it. Let’s dive into the review! 🌟 What You Did Well
🛠 Suggestions for Improvement
📚 Helpful ResourcesHere are some resources to help you align your contribution with the project’s conventions:
✅ Next Steps
If you have any questions or need help with any of the feedback, don’t hesitate to ask! We’re here to support you. 😊 Thank you again for your thoughtful contribution — we’re excited to see this feature evolve! 🚀 |
|
LGTM. Reads clean and self-contained. Posted #1386 as a separate follow-up for cross-org policy-layer |
|
@microsoft-github-policy-service agree |
|
Thanks Kevin Knapp (@Knapp-Kevin) — appreciate the clean review and the scoping judgment to split the policy-layer questions into #1386. Agreed that folding them in here would've bloated the ADR past its natural boundary. CLA signed. This should be mergeable once CI is green and a maintainer approves. Happy to rebase or address anything else that comes up. |
e92fe0d
into
microsoft:main
Addresses the structural gap in cross-org agent identity verification by proposing DNS-anchored JWKS federation as a provider-based extension to AGT's identity model. Responds to maintainer invitation in microsoft#1234. Co-authored-by: piiiico <pico@aamdal.dev> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Summary
Proposal ADR for cross-org agent identity federation via external JWKS, as invited by Imran Siddique (@imran-siddique) in #1234.
What this ADR covers:
/.well-known/jwks.jsonfollowing the OpenID Federation / SPIFFE trust domain pattern — one dereference hop, no coordination overheadIdentityProviderChainalongside existing SPIFFE and Entra modules,HandshakeResult.external_identityextension, ADR-0003 (200ms SLA) and ADR-0005 (liveness) compositionKey design choice: The abstraction sits at the provider boundary, not the wire format. This allows operators to plug in any identity backend (hosted federation, DIF MCP-I, custom trust anchors) without modifying the handshake protocol.
Relationship to Entra Agent ID bridge: Complementary, not competing. Entra handles cross-tenant within the Microsoft ecosystem; external JWKS handles agents outside it. The ADR includes a routing table for when to use which.
Working example: AgentLair JWKS endpoint — production Ed25519 keys, same algorithm as ADR-0001. Two independent projects have adopted this verification pattern.
Incorporates technical input from Kevin Knapp (@Knapp-Kevin)'s analysis on discovery constraints, trust anchoring topology, and revocation cadence.
Closes #1234
Prior art
/.well-known/discoveryDisclosure: I maintain AgentLair, referenced as a working example in the ADR.
🤖 Generated with Claude Code