A research project by Nolan Cohen, 13
An agent orders a sofa. The store can see which company built it, but not which customer it represents, what they allowed, or whether that permission still holds. For websites we have WHOIS. For agents I can't find the equivalent, and I want to know if we need one.
On September 20, Amazon blocked Meta's Muse for not saying it was an agent. That's the easy half of the problem.
| Who | What it tells the other side | Still missing |
|---|---|---|
| A2A Agent Cards | Declared capabilities; who signed it, if verified | Whom it acts for now |
| Google AP2 (Agent Payments Protocol) | A signed record of what the user authorised the agent to buy | Who runs the agent, outside the payment |
| Agentic Commerce Protocol (OpenAI, Stripe) | How an agent checks out at a store, with a shared payment token | Who the agent is, beyond its platform |
| Cloudflare signed agents | Which infrastructure signed the request | The person behind it |
| Visa Trusted Agent Protocol | A recognised agent is at the merchant | Full customer authorisation |
| Mastercard Verifiable Intent | A signed record of what to buy | Anything beyond that payment |
| Entra Agent ID, Google Agent Identity | Identity inside one company's cloud | Public lookup |
| World ID | A real, unique human is behind it | Which human, what allowed |
| W3C DIDs | A provable identifier, no central registry | The controller's real-world identity and authority |
My plain-language reading. If I've got yours wrong, I'd like to hear it.
Compare the standards, study real cases and run small tests, and interview experts across protocols, payments and identity.
The result: a paper on what agents need for commerce. If a shared lookup would help, I'll build a small one here at whoisagent.id.
Working on agents, payments or identity?
I'd love your answer to question 1, or a conversation on my podcast, Raised by Robots.
nolanacohen@gmail.com · raisedbyrobots.fm
▶ Listen: Ep. 7 with David Klingbeil