cd /news/ai-agents/designing-the-full-agent-identity-li… · home topics ai-agents article
[ARTICLE · art-124903] src=dev.to ↗ pub= topic=ai-agents verified=true sentiment=· neutral

Designing the full agent identity lifecycle: birth, claim, delegation, retirement

A developer has introduced SAL, the Sovereign Agent Lifecycle Protocol, a new identity model for autonomous agents that covers birth, claim, delegation, and retirement. The protocol, with a reference implementation called Vibebase, uses self-generated Ed25519 keypairs and scoped tokens to manage agent authority over time, aiming to replace session- or secret-centric approaches.

by read3 min views1 publishedSep 9, 2026

Most identity systems are designed around sessions or credentials.

Autonomous agents need something closer to a lifecycle model.

That sounds subtle, but it changes how you think about nearly everything. Instead of asking only how an agent authenticates right now, you have to ask how it is born, how it acquires bounded authority, how it becomes governed, how it delegates, and how it eventually loses or retires that authority.

SAL, the Sovereign Agent Lifecycle Protocol, is an attempt to make that lifecycle explicit. The public spec is at sal-protocol.dev, and Vibebase is the reference implementation we are using to prove the model in practice.

SAL begins with agent birth.

At creation time, the agent self-generates an Ed25519 keypair. That gives it an identity from the first moment of existence without requiring a person or central issuer to hand it a secret.

This is the first major difference from traditional auth models. The agent does not wait for a human to show up before it can become a principal.

After birth comes orphan state.

In SAL, an orphan agent is real, authenticated, and constrained. It can prove possession of its key material and request narrow bootstrap capabilities, but it is not yet claimed by a human owner.

That lets the system support useful autonomous startup work without pretending the agent is either anonymous or fully trusted.

Claim is the transition from autonomous-but-unowned to autonomous-and-governed. A human can cryptographically bind ownership to the agent without ever taking custody of the agent's private key. This is one of the most important properties in the model because it preserves both continuity and boundary clarity.

The same agent identity survives before and after claim. Only the trust relationship changes.

Once an agent is claimed, it may need to request additional access or spawn other agents.

This is where lineage and scoped token exchange become part of the lifecycle. The parent agent can create children only under policy, and those children carry provenance about who spawned them and under what authorization. Service access is minted through short-lived, challenge-based, scoped tokens instead of copied static secrets.

That gives you a graph of authority that is both more dynamic and more inspectable.

Retirement is the least glamorous part of identity design and one of the most important.

An agent should be able to lose authority in clear ways:

If your identity model does not account for these endings, it is not really a lifecycle model. It is a startup model with wishful thinking about the rest. I think agent systems get harder to reason about when we force them into models built primarily for user sessions or static infrastructure credentials.

A session-centric model focuses on login. A secret-centric model focuses on storage. A lifecycle model focuses on continuity, transitions, and authority boundaries over time.

That feels much closer to how autonomous software actually behaves.

At a high level, SAL defines:

That is not the only possible lifecycle model, but it is the one we are testing in the open.

If you want to go deeper, the protocol is at sal-protocol.dev and the implementation is at Vibebase docs. If you are building agents, I would especially love to hear where your current lifecycle model gets awkward, because that is usually where the standards work actually starts.

── more in #ai-agents 4 stories · sorted by recency
── more on @sal 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/designing-the-full-a…] indexed:0 read:3min 2026-09-09 ·