Agentic JWT: A Secure Delegation Protocol for Autonomous AI Agents

📅 2025-09-16
📈 Citations: 0
Influential: 0
📄 PDF

career value

195K/year
🤖 AI Summary
Autonomous LLM agents frequently invoke APIs in unsupervised settings, risking silent OAuth 2.0 privilege escalation due to stochastic reasoning, prompt injection, or multi-agent coordination. Method: We propose the first zero-trust delegation protocol for AI agents, centered on Bidirectional Intent Tokens (BITs)—cryptographically binding agent identity hashes, chained delegation assertions, and proof-of-possession—to enable runtime self-verification and cross-agent invocation tracing. Our design integrates unidirectional verification hashes (derived from prompts, tools, and configurations), step-level workflow binding, a lightweight client shim, and runtime key derivation—ensuring backward compatibility with existing OAuth ecosystems. Contribution/Results: Implemented on commodity hardware, our prototype incurs sub-millisecond overhead per delegation and effectively mitigates privilege escalation, replay, spoofing, and prompt injection attacks. The solution demonstrates production-ready deployability with minimal integration effort.

Technology Category

Application Category

📝 Abstract
Autonomous LLM agents can issue thousands of API calls per hour without human oversight. OAuth 2.0 assumes deterministic clients, but in agentic settings stochastic reasoning, prompt injection, or multi-agent orchestration can silently expand privileges. We introduce Agentic JWT (A-JWT), a dual-faceted intent token that binds each agent's action to verifiable user intent and, optionally, to a specific workflow step. A-JWT carries an agent's identity as a one-way checksum hash derived from its prompt, tools and configuration, and a chained delegation assertion to prove which downstream agent may execute a given task, and per-agent proof-of-possession keys to prevent replay and in-process impersonation. We define a new authorization mechanism and add a lightweight client shim library that self-verifies code at run time, mints intent tokens, tracks workflow steps and derives keys, thus enabling secure agent identity and separation even within a single process. We illustrate a comprehensive threat model for agentic applications, implement a Python proof-of-concept and show functional blocking of scope-violating requests, replay, impersonation, and prompt-injection pathways with sub-millisecond overhead on commodity hardware. The design aligns with ongoing OAuth agent discussions and offers a drop-in path toward zero-trust guarantees for agentic applications. A comprehensive performance and security evaluation with experimental results will appear in our forthcoming journal publication
Problem

Research questions and friction points this paper is trying to address.

Securing API delegation for autonomous AI agents
Preventing privilege escalation in stochastic agent environments
Enabling verifiable user intent binding in multi-agent workflows
Innovation

Methods, ideas, or system contributions that make the work stand out.

Dual-faceted intent token binding actions
Chained delegation assertion for downstream agents
Lightweight client shim with self-verification