PKI establishes cryptographic identity and proves the caller is the right machine, while OpenID Federation governs which organisations or domains are trusted to register, describe, and manage those identities. In practice, PKI answers who the agent is, and federation answers which trust relationships allow that agent to operate across boundaries.
What PKI does for an AI agent
PKI is the cryptographic layer. It gives an AI agent a verifiable identity by binding keys and certificates to that agent, so a verifier can check that the caller holds the corresponding private key and is presenting a trusted certificate chain. That makes PKI the mechanism for proving possession, establishing trust in the credential, and enabling secure machine-to-machine authentication.
For AI agents, PKI is usually about runtime authentication and cryptographic trust, not about whether the agent should be allowed to act. A certificate can tell a receiver that a caller is the expected agent, but it does not by itself define the agent’s permissions, approval boundaries, or organisational trust relationships.
In practical terms, PKI is strongest when the question is “can I trust this agent’s presented identity at the protocol layer?” That is why certificate lifecycle, rotation, and revocation are central operational concerns, especially when an agent runs across services, clusters, or environments that depend on the same trust anchor.
What OpenID Federation governs
openid federation sits one layer above simple credential proof. It is about how organisations, domains, and operators establish and publish trust so that relying parties can decide which identities, metadata, and operational statements they are willing to accept. In other words, federation governs the trust framework around the identity, not just the proof that a private key exists.
For AI agents, that matters when the agent must be registered, described, or recognised across organisational boundaries. Federation can define who is authorised to assert metadata about the agent, which authorities are trusted to vouch for it, and how that trust is discovered and updated as relationships change.
The difference is important in multi-organisation workflows. PKI can authenticate an agent cryptographically, but OpenID Federation can answer whether a partner domain is a legitimate issuer, operator, or registry for that agent’s identity. That distinction becomes critical when agents move across SaaS providers, business units, or delegated operations.
How to choose between them in an agent architecture
Use PKI when the primary problem is secure authentication of the agent at connection time, especially for service-to-service or workload-to-workload communication. Use OpenID Federation when the primary problem is trust governance across domains, such as onboarding, metadata exchange, and relying-party trust decisions between organisations.
They are complementary rather than competing controls. A well-designed AI agent ecosystem may use PKI to prove possession of keys, OAuth or token-based flows to obtain access, and federation to decide which domains are allowed to participate in the trust network. The architecture choice depends on whether the control question is “who is this caller?” or “who is allowed to vouch for this caller?”
For readers working on agent onboarding, the cleanest mental model is that PKI anchors cryptographic authenticity, while federation governs trust relationships and registration authority. If you blur those layers, you risk treating a valid certificate as proof of business trust, which it is not.
Risk and Threat Considerations
AI agents are attractive targets because a weak identity layer can let an attacker impersonate a legitimate caller, register a rogue trust endpoint, or abuse delegated access across domains. The main failure mode is confusing cryptographic proof with organisational trust, which can allow a technically valid identity to operate in an environment that never intended to trust it.
Failure mechanism: Compromised keys, weak certificate governance, or overbroad federation trust can let an attacker present a believable agent identity, then use that trust to obtain tokens, invoke tools, or move laterally across connected systems.
Impact: The result can be unauthorized agent actions, cross-domain abuse, token theft, and trust-chain expansion that is hard to detect because the traffic still looks “legitimate” at the protocol layer.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | PKI underpins how AI agents prove cryptographic identity. |
| NHI-07 — Long-Lived Secrets | Agent certificates and keys must be rotated and revoked to limit misuse. | |
| Recommendation — Bind agent authentication to strong key and certificate assurance. Rotate agent credentials and shorten cryptoperiods aggressively. | ||
| NIST SP 800-53 Rev 5 | IA-9 — Identification and Authentication (Non-Organizational Users) | AI agents often authenticate as non-organizational system actors across services. |
| IA-5 — Authenticator Management | PKI depends on secure issuance, rotation, revocation, and protection of keys and certs. | |
| AC-3 — Access Enforcement | Federation governs which trusted parties may assert or manage agent identities. | |
| Recommendation — Apply IA-9 to verify non-organizational callers with strong authenticators. Manage agent keys and certificates through controlled issuance and revocation. Enforce access decisions separately from cryptographic identity proof. | ||
Practitioner Guidance
What to verify: Check whether your architecture needs proof of caller identity, trust brokerage between organisations, or both. If the agent must operate externally, require both certificate-level assurance and an explicit federation trust policy, not one as a substitute for the other.
Decision rule: If the control failure you are worried about is impersonation, broken authentication, or key misuse, prioritise PKI hardening and credential lifecycle control. If the control failure is an untrusted domain being able to register, describe, or assert authority for agents, prioritise federation governance and trust-anchor review.
Practitioner takeaway: PKI answers whether the agent can prove it holds the right key, while OpenID Federation answers whether the ecosystem should trust the entity that is presenting or managing that agent identity.
Related resources from NHI Mgmt Group
- What is the difference between managed identities and hardcoded secrets for AI agents?
- What is the difference between workload identity and API keys for AI agents?
- How should security teams authenticate AI agents in enterprise environments?
- What is the difference between logging actions and logging intent for AI agents?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org