@techreport{ferro-dnsop-apertoid-00, number = {draft-ferro-dnsop-apertoid-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ferro-dnsop-apertoid/00/}, author = {Andrea Ferro}, title = {{ApertoID: DNS-Based Agent Identity Declaration Protocol}}, pagetotal = 22, year = 2026, month = mar, day = 24, abstract = {This document defines ApertoID, a DNS-based protocol that enables domain owners to declare authorized AI agents acting on their behalf, publish cryptographic keys for agent identity verification, and specify enforcement policies for unauthorized agents. ApertoID uses existing DNS TXT records under the "\_apertoid" underscore-scoped domain name to provide a decentralized, standards-based mechanism for AI agent identity declaration and verification. ApertoID defines two record types: a Policy Record analogous to DMARC that specifies domain-level enforcement behavior, and Agent Declaration Records analogous to DKIM key records that bind agent endpoints to Ed25519 public keys with mandatory expiration. A companion document {[}APERTOID-SIG{]} defines the HTTP request signing mechanism that enables agents to cryptographically prove their identity on each request.}, }