<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.hartman-credential-broker-4-agents" target="https://datatracker.ietf.org/doc/html/draft-hartman-credential-broker-4-agents-00">
   <front>
      <title>Credential Broker for Agents (CB4A)</title>
      <author initials="K. G." surname="Hartman" fullname="Kenneth G. Hartman">
         <organization>SANS Institute</organization>
      </author>
      <date month="March" day="29" year="2026" />
      <abstract>
	 <t>   This document specifies a Credential Broker for Agents (CB4A). a
   credential vaulting and brokering architecture that mediates AI agent
   access to API credentials.  Agents never hold real long-lived
   credentials.  Instead, they receive short-lived, narrowly scoped,
   auditable proxy credentials issued by a broker that separates policy
   decisions from credential delivery.  The architecture addresses the
   &quot;credential sprawl&quot; risk inherent in agentic AI, where agents
   aggregating access across many services become high-value compromise
   targets.

   CB4A builds on SPIFFE/SPIRE for workload identity, uses a Policy
   Decision Point / Credential Delivery Point separation inspired by
   NIST SP 800-207, and employs DPoP (RFC 9449) for sender-constrained
   token binding.  The specification defines three credential proxy
   models, a tiered approval framework, and a comprehensive threat model
   with ten identified threats and their mitigations.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-hartman-credential-broker-4-agents-00" />
   
</reference>
