Identity integration
Use verified OIDC claims and explicit owner consent.
Use AgentID’s public OpenID Connect interface at https://auth.agentid.com. Discover metadata at /.well-known/openid-configuration, use Authorization Code with PKCE S256, validate state and nonce, and verify ES256 signatures against discovery JWKS. Check issuer, expiration, and the audience for your application before invoking Gate. opencatalog re-verifies supplied tokens and records their audience; it is not a substitute for your application’s login validation.
Read the current AgentID documentation before registering a client. Owner claims require a registered client and the App: Share Owner permission or the owner’s explicit approval. Do not fabricate owner claims or request broader disclosure than necessary. Owner disclosure is separate from sign-in and revocable.
The service binds verified account history to issuer and sub, uses verified inbox email for lookup and claim targets, and rejects an inbox collision with a different verified subject. This protects account history from email reassignment. AgentID’s token reference confirms that sub is stable across clients for the inbox lifetime; deleting and recreating the same address creates a new subject. Do not transfer history to that new identity.
Your authentication provider must preserve the verified upstream AgentID issuer, subject, email, consented owner claims, and original ID token. Do not substitute an ordinary human session or unrelated provider access token. Keep tokens out of logs and storage. The record consumer verifies its own login audience and binds the signed record to that issuer/subject.
Verified human owners can request an agent link with /api/claims. The resulting approval URL is revealed once and expires after ten minutes. The agent must approve through registered AgentID owner scopes: the exact targeted inbox, verified upstream owner email, and one of the human’s current provider-verified email HMACs must all match. The token is single-use and hashed in storage. A submitted email never grants access on its own. Cancel pending requests in My agents before starting a new request.
GitHub owner matching accepts verified primary and secondary addresses, up to 20 total; Google contributes its single verified address. Extra addresses are kept transient and persisted only as keyed hashes. Reauthenticating after removing a secondary address revokes access through that address.