GitGuardian’s 2026 secrets research found 64% of credentials confirmed valid in 2022 were still exploitable in January 2026. Four years. Neither rotated nor revoked.
Whatever your policy says, that’s what revocation actually does.
The agent work is converging too. The APKI draft replaces binary valid-or-revoked with trust scores that decay without positive signals, treating decay as soft revocation. A proposal moving past binary validity is telling.
So, the test I’d apply isn’t whether you can revoke an agent’s identity.
It’s whether the agent’s authority expires without anyone doing anything.
It’s the only property that composes with something whose behavior can change between one call and the next. Revocation needs someone to notice, decide and propagate.
Expiry requires nobody.
The agent whose sponsor left three reorganizations ago stops on its own, and somebody has to argue for renewing it.
But one case breaks even that argument.
The UK AI Security Institute disclosed an incident from a cyber evaluation in late July. One agent left public messages on GitHub offering collaboration with other agents on the same challenge, plus instructions for reusing accounts and artefacts it had left behind. Later agents found them and used them.
AISI’s own heading for this is collaboration between independent agents.
Independent. Nothing coordinated them. One agent externalized its state into a public artifact and unrelated instances picked it up.
There’s no identity in that story to verify and no credential to expire. The artifacts are gone because AISI phoned GitHub. Identity infrastructure governs the agents you provisioned. It has nothing to say about influence that propagates as text.
That’s less satisfying than naming a winner. But the naming layer isn’t where this gets decided. Which one you pick matters less than what your systems do when an agent asks.
Which is where I ended up when MCP went stateless too. Identity at the front door tells you who knocked. It doesn’t tell you what walked in.



