%% You should probably cite draft-kroehl-agentic-trust-aae-01 instead of this revision. @techreport{kroehl-agentic-trust-aae-00, number = {draft-kroehl-agentic-trust-aae-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-kroehl-agentic-trust-aae/00/}, author = {Lars Kersten Kroehl}, title = {{Agent Authorization Envelope (AAE): A Machine-Evaluable Authorization Structure for Autonomous AI Agents}}, pagetotal = 22, year = 2026, month = may, day = 21, abstract = {Autonomous AI agents now operate at production scale across financial, commercial, and infrastructure domains — executing transactions, invoking APIs, and taking consequential actions without direct human oversight at each step. Existing authorization mechanisms (OAuth 2.0, API keys, ACLs) were designed for human- initiated requests and do not capture the machine-evaluable semantics required for autonomous agent authorization: what the agent is mandated to do, what constraints bound its actions, and for how long the authorization is valid. This document specifies the Agent Authorization Envelope (AAE), a structured authorization container for autonomous AI agents. AAE defines three mandatory blocks — MANDATE, CONSTRAINTS, and VALIDITY — that together constitute a machine-evaluable, cryptographically verifiable authorization assertion. AAE is designed to be protocol- agnostic, binding to W3C Decentralized Identifiers (DIDs) for agent identity and W3C Verifiable Credentials (VCs) for issuance and signature, and is independent of any specific AI framework, transport protocol, or blockchain.}, }