Binding a delegated capability's *use* to the delegating identity #6
Unanswered
source-origin
asked this question in
Q&A
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
AIP gives agents verifiable, delegable identity, and a UCAN-style chain proves that A delegated capability X to B. What it doesn't obviously prove is that a given invocation was made under that chain, by B, within the attenuation.
So there's a seam between the delegation artifact and the invocation record. My question: how is an invocation bound to the delegation chain that authorized it — does the invocation carry its own proof (capability reference + signature over the call), or is the binding enforced at the verifier / agent runtime?
I ask because the two differ in what a third party can check: in the first case they can recompute the binding from the evidence alone; in the second they have to trust the runtime that mediated it. Which does AIP take — and does that binding survive a root-key rotation?
All reactions