🤖 AI Summary
Autonomous LLM agents frequently invoke APIs in unsupervised settings, risking silent OAuth 2.0 privilege escalation due to stochastic reasoning, prompt injection, or multi-agent coordination.
Method: We propose the first zero-trust delegation protocol for AI agents, centered on Bidirectional Intent Tokens (BITs)—cryptographically binding agent identity hashes, chained delegation assertions, and proof-of-possession—to enable runtime self-verification and cross-agent invocation tracing. Our design integrates unidirectional verification hashes (derived from prompts, tools, and configurations), step-level workflow binding, a lightweight client shim, and runtime key derivation—ensuring backward compatibility with existing OAuth ecosystems.
Contribution/Results: Implemented on commodity hardware, our prototype incurs sub-millisecond overhead per delegation and effectively mitigates privilege escalation, replay, spoofing, and prompt injection attacks. The solution demonstrates production-ready deployability with minimal integration effort.
📝 Abstract
Autonomous LLM agents can issue thousands of API calls per hour without human oversight. OAuth 2.0 assumes deterministic clients, but in agentic settings stochastic reasoning, prompt injection, or multi-agent orchestration can silently expand privileges.
We introduce Agentic JWT (A-JWT), a dual-faceted intent token that binds each agent's action to verifiable user intent and, optionally, to a specific workflow step. A-JWT carries an agent's identity as a one-way checksum hash derived from its prompt, tools and configuration, and a chained delegation assertion to prove which downstream agent may execute a given task, and per-agent proof-of-possession keys to prevent replay and in-process impersonation. We define a new authorization mechanism and add a lightweight client shim library that self-verifies code at run time, mints intent tokens, tracks workflow steps and derives keys, thus enabling secure agent identity and separation even within a single process.
We illustrate a comprehensive threat model for agentic applications, implement a Python proof-of-concept and show functional blocking of scope-violating requests, replay, impersonation, and prompt-injection pathways with sub-millisecond overhead on commodity hardware. The design aligns with ongoing OAuth agent discussions and offers a drop-in path toward zero-trust guarantees for agentic applications. A comprehensive performance and security evaluation with experimental results will appear in our forthcoming journal publication