[Openid-aiim] Call notes
Atul Tulshibagwale
atul.tulshibagwale at crowdstrike.com
Thu May 7 17:23:37 UTC 2026
Hi all,
The notes for today's call, including the link to the proposed
interoperability event outline are stored in the AIIM GitHub Wiki here
<https://github.com/openid/cg-ai-identity-management/wiki/CG-Meeting-2026%E2%80%9005-07>.
Please note the new location
<https://docs.google.com/document/d/1AcX9v9cbGJd1on43Jkm-oep4a8umFpJZoH-wDEhGQLg/edit?usp=sharing>
for the Google Doc where we capture call notes.
I'm also copying the notes below for your convenience.
Thanks to all who participated,
Atul
---
*May 7, 2026AttendeesNameAffiliationParticipation Agreement signed?Atul
TulshibagwaleCrowdStrikeYesFlemming AndreasenCiscoYesNevzat
ÇırakIndependentYesEleanor MerittSelfYesMike KiserSailPointIndeedBjorn
HjelmIndependentYesGail HodgesOIDFN/AGovindaraj PalanisamyGlobal
PaymentsYesSarah CecchettiSemperisYesChris
phillipsIndependentYestomjindyBrook LovattindependentYesRamon
GalateRaidiamyesVaibhav NarulaIndependentYesAsanka
SamaraweeraIndependentYesSean O’DellCVS HealthYesLukasz
JarominRaidiamYesAgenda - Living spec- Interoperability event
possibilities- Anthropic Workload Federation- Create working group?Notes -
Gail raised one of key take aways in Board meeting last thursday was to
explore creation of a “living spec” like W3C developed, and that such a
living spec could offer the kind of agility needed to attract AI standards
work to the OIDF, and avert the defacto standards root of going for a quick
win via a GitHub repo/ open source code model. The length of time it can
take to develop a spec could be a double edged sword, bringing consensus
and rigor, but misses moment of creating impact in quick cycles of AI
domain space. Such a living spec could strike an interesting balance.This
concept will be discussed further at Strategy Task Force end of May…but
comments or suggestions from this group will be valuable pre/post. Workload
Identity Federation announcement from Anthropic: -
https://platform.claude.com/docs/en/manage-claude/workload-identity-federation
<https://platform.claude.com/docs/en/manage-claude/workload-identity-federation>
- Workload identity federation (Anthropic announcement)- (Atul) It’s
similar to Google’s Workload Identity Federation
<https://docs.cloud.google.com/iam/docs/workload-identity-federation> and
SPIFFE federation
<https://spiffe.io/docs/latest/spiffe-specs/spiffe_federation/>- (Brook)
“it’s about time” where are the rest of of the AI labs??- (Lukasz) I saw
an announcement that WIMSE and couple of IdPs could support this
federation? In the OpenID foundation, the solution could be OpenID
Federation- (sarah note from chat)Some other potential standards we could
interop:
https://clawdrey.com/blog/field-notes-from-the-future-of-standards.html
<https://clawdrey.com/blog/field-notes-from-the-future-of-standards.html>-
(Tom note in chat) relationship id sounds similar
https://docs.google.com/document/d/1CwBDRbw147YlNld-UOlJ4lGvmpDIOCSI/edit#heading=h.kp911j18z01y
<https://docs.google.com/document/d/1CwBDRbw147YlNld-UOlJ4lGvmpDIOCSI/edit#heading=h.kp911j18z01y>-
(Sarah note in chat) wimse/waffles would be fun - and is designed
specifically for AI delegated identity management…But that's work that will
be done in IETF, not OIDF, so not sure it's appropriate for this group to
facilitate?- (Gail) Do we need to do a blog post / reaction to the
Anthropic announcement
<https://platform.claude.com/docs/en/build-with-claude/workload-identity-federation>?
Is there a place to recognize this work, and encourage other AI LLMs to
follow suit, and to speak to roadmap beyond this…e.g. What use cases are
missing (end points beyond my organization…leads to role of just OpenID
Federation), or the potential to address higher risk security use cases
that serve high risk ecosystems like open data across trust boundaries (
e.g. FAPI), and perhaps further into interal or cross boundary risk
signals (e.g. SSF)- (Chris) I saw the announcement. We’re witnessing an
effort to consolidate the trust and identity into one provider. It’s more
about the authentication and singular identity than it is about federation.
Anthropic’s Workload Identity “Federation” is different. It sounds like an
“easy button”, but it doesn’t address questions like “who added the
workload”, etc. Good start, but there is more here. It’s directionally
correct, and it complements OpenID Federation. The governance backplane is
the hard part.The concrete use cases result in a better spec. When you get
into more common use cases, you start running into the trust part that is
not quite addressed in the Anthropic announcement.- - Interoperability
event- Interoperability event outline proposal
<https://docs.google.com/document/d/19BsomtItmRYFE20UFSb0osYNkjtgbcg8ZsgygoMAduA/edit?usp=sharing>-
This could be interested in the context of workload identity federation-
(Lukasz) Re: interop event, is this an interop, or a hackathon. The idea
could be just to build a concept, pilot and white paper.- (Atul) Shared
interop event details- (Flemming) We should understand what a bare bones
system would look like first.- (Mike K) This looks interesting and helpful,
but it seems more like a test bakeoff rather than an interop. That could be
the domain of IPSIE.- (Sarah) All press is good press, so we should go
ahead with the interop event, and we can specify the details between now
and the conference- (Sean) The agentic framework, where it is at right
now, we’re past registration, we’re getting into dynamically scoped intent
based authorization. The SDK thing that Sarah mentioned is important. The
problem right now is that we can’t do this with one codebase. Running
managed agents versus doing it yourself is financially discouraging. So
having vendors interoperate is important. How do your agentic gateways talk
to the PEP, etc. This is the interesting part of Atul’s proposal.
Integrating technology has to be dumb. - (Sarah) Is there value in creating
a transformer for various ID formats?- (Sean) yes. We’re just doing SCIM
for machines right now. Without cross-domain trust it’s hard to do.-
Everyone’s trying to sell vaporware- (Govindaraj) Sean is right. Everyone
is talking about agentic identity. Most of the stuff doesn’t work in
cross-domain scenarios. - (Sean) We should go after interoperability. We
should have the major players to demonstrate the interoperability.- (Sarah)
It would be great for us to influence major suppliers such as Anthropic,
etc. to interoperate.- (Govindaraj) Transaction Tokens are interesting.
Where do we stand on that? - (Sean) It should be a part of the interop
event. People are using short-lived tokens, but using TraTs is a good idea
because it works. It should happen behind the gateways.- (Gail) In
conversations with Ralph Bragg at Raidiam… The big buyer organizations in
this space like FIs and Healthcare…they have dependencies across domains,
will be able to pressure the suppliers. This timing of the interop (in Dec)
is really good in that respect. This will ensure that their IDPs and CSPs
are engaging. The CSPs are key to this puzzle. This is a topic and roadmap
George, Karl, and Gail discussed at IIW and then raised at the OIDF Board
last Thursday. We should shoot for the medium term in the interop event
scope, and bring stakeholders onboard now to shoot for it. - [image:
image.png]- (Gail) The other conversation that Karl and I were having,
consent model, delegated authority framework, etc. are going to be
important.We need to incubate the R&D items and futurespecs we know we will
need for 12-36 mo out at the same time.- (Gail in notes). The Bank of
international settlements Project Aparta is concluding now, and it
leveraged FAPI and OpenID Federation… so we can leverage that for playbook
that not only builds on known best practice and then layers on AI context.-
(Sean in notes) Being blunt.... The IdP's are not making it finanically
feasible to do agentic- Chris in notes: the Anthropic WIF means it still is
1 idp to rule them all..- (George) I think we need a reference
architecture, and Sean has been defining and pushing it within his
organization. TraTs can easily carry context, but how do we use TraTs to
cross domain boundaries? That work is doable using ID-Chaining, but we
don’t have a profile there. Leveraging TraTs to do cross-domain token
exchange is a very valid thing. - (George) Getting clarity around
deployment advice and how these things work together would be really
useful. But to me TraTs as a value statement is for “completing a task”
within a single trust domain. We know that we need to cross domain
boundaries, and that piece is missing. We need to be careful about
extending the use of TraTs. We should keep TraTs bound to one domain, and
use one of the other domains would add a lot of clarity to the deployment
model architecture.- (Govindaraj) Agentic commerce is .. OpenAI and others
are still using API credentials to authenticate, which is a huge risk.
That’s where in addition to TraTs, we need to have additional information
in the bearer token to specify the context. When the gateway receives a
token, there needs to be some identification added.- (George) There is a
place in TraTs to put the context. What goes in the context is the hard
part. Dick Hardt’s Agent Auth work (which has nothing to do with the
protocols discussed today), represents the task at hand. Karl McGuinness
has talked about “mission” as another layer. I’ve been doing work on an
authorization delegation model. What we’re missing is a standard way to
describe context around what is the authority structure, what is the
authority of the delegator and what have they delegated. What is required
to complete a task successfully. This context feeds into the authorization
decision. The closest thing is what Karl has published. It’s in the EKYC as
a PR. We need structure around how to represent context.- (Lukasz) On the
interop event, how is it structured? Is it like a pilot? Will we show how
interoperable everything would be? If that’s the case, it’s not an
interoperability event.- (Govindaraj) Are we looking into MCP intercepters
too.- (Gail) At least one clear takeaway is that there’s strong interest.
Having the draft doc is useful. We shouldn’t lock the scope though, until
we have some of the stakeholders.- (Chris) The definition of
interoperability is tough to nail down. However, if we call it a benchmark
and the models do it, then the models can get ranked on how well they can
implement.- - (Ramon) In the current MCP spec you can only do regular oauth
for cloud hosted mcp servers. This causes local agents, like claude code…,
to require certificates and key pairs using stdio to enable FAPI grade
connections. To enable facilitated connections for clients, a Dpop based
connection within a FAPI profile could open up better workflows.- (Sarah) A
FAPI profile of MCP would be interesting- (Sean) I’ve been working with
Google and Microsoft. Google has released “Agent ID” in GA. They’re
honoring SPIFFE IDs for first-party agents inside GCP. Microsoft will have
it by Q3. This is a huge step forward over using service principals.*
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-aiim/attachments/20260507/3e1e6187/attachment-0001.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image.png
Type: image/png
Size: 419773 bytes
Desc: not available
URL: <http://lists.openid.net/pipermail/openid-aiim/attachments/20260507/3e1e6187/attachment-0001.png>
More information about the Openid-aiim
mailing list