Field notes on agent identity fragmentation, from an evening w/ Okta, Auth0, Skyfire, Experian, Mastercard, Blackhawk Network & friends.
Last week Skyfire convened roughly 250 people at Okta’s San Francisco offices around a single question wearing many costumes: how does anyone trust an AI agent with money? The writer attended as someone who shipped developer platforms at PayPal & American Express and now runs a production MCP server with agent payments. Every demo of the night worked. More interesting was what every demo quietly assumed: that the agent arriving at the service door carried a credential the door recognized. Change the door, and the assumption breaks.

Craig DeWitt, Skyfire co-founder, set the stakes in the opening minutes:
“A bigger change in commerce than when smartphones put the internet in everybody’s pocket.”
Then a fireside with Nikhil (Nik) Sathe of Blackhawk Network, seven live demos and a closing panel moderated by Danny Fortson of the Sunday Times. What follows is the fracture the room exposed, not any single vendor’s pitch.

Three Postures at One Door
MCP helped standardize how agents reach tools. It did not standardize who an agent is. Into that gap, at least three distinct postures were visible in the room, each shaped by a different buyer pressure.
The first is enterprise identity extension. Okta, Auth0 and their peers treat the agent as another governed principal: authorization servers, token exchange, policies binding agents to the humans and organizations accountable for them. Abhishek Hingnikar of Auth0 demonstrated the problem this posture solves by walking a live Claude session into a merchant login flow and watching the task die in password recovery, a cart abandoned by an agent that could not remember which email its human used. His diagnosis carried the night:
“Capability doesn’t translate to trust. Trust is earned, not scaled.”
The second posture is portable credentials for the open web. Skyfire’s approach mints signed tokens an agent carries outward to merchants, CDNs and MCP servers it has never met. Around it, a layered mesh is forming rather than a single school: naming services for agents, verifiable credential formats from the W3C community, workload attestation efforts in the IETF orbit. These solve different problems at different layers, referenced from the stage as pieces still finding their joints.

Brent M. Maynard of Akamai Technologies described what this posture demands of edge infrastructure after a decade spent destroying exactly this traffic:
“I have to accept and swallow my pride, and I have to be friends with these bots again.”
The third posture belongs to payment networks. Craig Gilbert of Mastercard described tagging agents and tracking them across time, feeding risk signals to merchants and issuers in near real time. This is neither enterprise governance nor portable credentials. It is trust as a continuously updated score riding the rails money already moves on, and it arbitrates in its own bounded context regardless of which identity standard wins.
Each posture answers a real buyer. The friction begins where they meet: an enterprise-governed agent shopping the open web, a portable credential arriving at a payment network’s risk engine, a merchant fielding all three in one afternoon.
No Shared Arbiter Yet
Here is the question the evening circled without landing. An agent shows up at a service door with credential X. Does it get in? Does the merchant demand Y and Z as well? Does holding three credentials raise a trust score or just triple the integration cost for whoever parses them at the door?
Nikhil (Nik) Sathe, whose company sells stored value, a product that concentrates fraud, named the sprawl directly, ticking through AP2, UCP, ACP and their siblings:
“We’ve got to get that last “S” out of standardS. We need one standard that everyone can collaborate around”
His merchant math is instructive. Blackhawk Network cannot afford to guess wrong about which credential regime prevails, so it supports several. That multiplied parsing burden is the fragmentation tax, paid today, invoice by invoice.
Kathleen Peters of Experian located the deeper layer: human-to-agent binding. Card-not-present commerce earned consumer trust over decades because when something went wrong, everyone knew where remedy lived. Her question about an agent transaction gone sideways has no cross-standard answer:
“If I’m an average consumer, who’s gonna make that right?”
She noted that large model providers, asked the same question, currently point away from themselves. A token from one regime, an access token from another and a risk score from a third each encode trust, but no shared arbiter surfaced in the room, no registry that scores an agent’s reputation portably across all three postures, no clearinghouse telling a merchant that trust earned at one door transfers to the next.

Craig Gilbert of Mastercard sketched why arbitration grows urgent as the permutations multiply:
“You get a bad actor, good agent. You could have a good actor, a bad agent.”
Add merchant-side agents and the matrix expands again. His proposed remedy, shared dynamic signals letting the whole ecosystem react when an agent misbehaves, works best if signals travel across regimes. Which restates the problem it aims to solve.
Blocked at the Door
Scale sharpens all of this. Brent Maynard presented Akamai’s traffic picture from the stage: a majority of observed traffic now automated or agentic, with agents approaching one in five sessions during peak holiday season, figures he attributed to Akamai’s own data and adjacent CDN research. Definitions matter here, since scraper traffic and authorized shopping agents are not the same thing, and the writer flags that caveat. The direction, though, matched what the demand side reported all evening.
Amir Sarhangi of Auth0, an Okta company, gave the sharpest reason accountability still routes through people and organizations:
“There’s nothing at stake for an LLM, apart from the next token.”
Binding agents to accountable principals, human or organizational, is the liability architecture the room trusted most, for now.
One scope note for readers mapping the full stack: identity is half of agentic trust and payments is the other half. This piece takes the identity half.

Who Translates Trust
So which posture wins? The evening suggested that is the wrong resolution. All three keep their buyers. The unclaimed ground sits between them: the translation layer that lets trust earned in one regime be honored in another. A merchant does not want three parallel trust systems; a merchant wants one answer to the question standing at the door.
What the writer will watch between now and holiday season is not any vendor’s roadmap but the first honest handoff: a credential minted in one regime accepted, unpacked and scored in another, with liability that survives the crossing. The first standard that makes another standard’s credential useful may matter more than the first standard that perfects its own.

The Trust Layer: An evening on Agentic Commerce, hosted by Skyfire / Okta / Experian
AI agents are starting to transact on behalf of people and businesses but the systems that protect merchants weren’t built for this. The missing pieces are verified agent identity, human-to-agent binding, bot and fraud management that accepts agents, and payment credentials that travel with proof of authorization . The trust layer is now, being rolled out by the world’s largest and most innovative companies. Come see it live.
On the agenda
Two panels: one featuring the merchant POV on how they are evolving for the Agentic world and the on the state of agentic identity and commerce with leaders from Skyfire, Okta, Experian, and more.
Live demos from Fetch.ai, Replit, Apify, Rye and Ramp companies running agentic commerce in the wild across identity, payments, and merchant infrastructure.

