# #422 - Decoded - Securing AI Agents with Standards You Already Have Page: https://stenobird.com/podcast/identity-at-the-center-344918/422-decoded-securing-ai-agents-with-standards-you-already-have Text version: https://stenobird.com/podcast/identity-at-the-center-344918/422-decoded-securing-ai-agents-with-standards-you-already-have.md Podcast: [Identity at the Center](https://stenobird.com/podcast/identity-at-the-center-344918) Published: 2026-05-15T09:00:00+00:00 Episode link: https://podcasters.spotify.com/pod/show/identity-at-the-center/episodes/422---Decoded---Securing-AI-Agents-with-Standards-You-Already-Have-e3j8ncb Audio file: https://anchor.fm/s/c5fefcc/podcast/play/119872331/https%3A%2F%2Fd3ctxlq1ktw2nl.cloudfront.net%2Fstaging%2F2026-4-12%2Ff6c78410-e236-381b-e77e-8263c1781dcb.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/identity-at-the-center-344918/episodes/422-decoded-securing-ai-agents-with-standards-you-already-have Duration seconds: 4697 ## Resource Episode 422 is the debut of Decoded by Identity at the Center, a new sub-series hosted by Jeff Steadman and Sean O'Dell dedicated to unpacking the specifications and standards powering IAM. Joining them is Pieter Kasselman, VP of Open Standards at Defakto and chair of the WIMSE working group. The conversation covers why traditional non-human identity approaches break at agentic scale, how SPIFFE and SPIRE enable short-lived automated credential provisioning without long-lived secrets, and why treating agents as workloads unlocks a decade of existing standards. Pieter walks through critical OAuth specs including JWT authorization grant, token exchange, client ID metadata, and the emerging transaction tokens draft. Sean connects these to practical gateway architecture, continuous access evaluation, and policy-based authorization. The episode closes with real-world deployment examples and a clear takeaway: the tools to secure agentic identity are available today. Episode Links:Pieter Kasselman: https://www.linkedin.com/in/pieter-kasselman-0259862/AI Agent Authentication and Authorization: https://datatracker.ietf.org/doc/draft-klrc-aiagent-auth/Workload Identity in Multi-system environments (WIMSE): https://ietf-wg-wimse.github.io/OAuth SPIFFE Client Authentication: https://datatracker.ietf.org/doc/draft-ietf-oauth-spiffe-client-auth/Transaction Tokens: https://datatracker.ietf.org/doc/draft-ietf-oauth-transaction-tokens/08/Agentic Identity Control Framework. You Already Have the Pieces. Now Build It. by Sean O'Dell: https://www.linkedin.com/pulse/agentic-identity-control-framework-you-already-have-pieces-o-dell-61b5e/ Timestamps: 00:00 Introduction to Decoded by Identity at the Center 00:13 The mission of the Decoded sub-series 03:02 Guest intro: Pieter Kasselman, VP of… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/identity-at-the-center-344918/episodes/422-decoded-securing-ai-agents-with-standards-you-already-have/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/identity-at-the-center-344918/422-decoded-securing-ai-agents-with-standards-you-already-have.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.