HNHacker News
TopNewBestAskShowJobs

x401throaway

4 karma · joined October 1, 2026

submissionscomments
x401throaway··on Identity Management for Agentic AI [pdf] (2025)
thank you for the clarification - thankfully some much smarter people than I are working on the protocol aspects :)

when I say `authorize who you are` I mean to say that you're saying both "hello I am in fact john doe" and "john doe the human is also saying this is ok to do".

I think this is interesting in the lens of Muse, GrokBot, Dots, OpenClaw, etc; if my agent wanted to rent a car on my behalf, it would forcibly have to get approval from me to do so

x401throaway··on Identity Management for Agentic AI [pdf] (2025)
I work at Proof, and we're working on x401 as a means for agentic authorization

https://x401.proof.com/spec/latest/#abstract

in a nutshell:

* a website that wants to authorize who you are (say, to book a flight or sign a waiver for go kart rental)

* the endpoint returns 401 and defines in a header what info it needs about you (over 18? you're actually John Doe? etc.)

on the proof side specifically, we're putting IAL2 verification in front of this https://pages.nist.gov/800-63-3-Implementation-Resources/63A...

pretty cool stuff, its early days but its a strong way to ensure there's a human authorizing sensitive actions an agent is taking on your behalf