SCIM for AI, one year later: What's changed in the IETF agent identity draft
Blog post from WorkOS
Efforts to define how SCIM should represent AI agents have consolidated from competing Okta and Microsoft proposals in 2025 into a jointly authored June 2026 informational draft, draft-wzdk-scim-agent-resource-00, also involving Nextident. The earlier disagreement centered on whether agents should be modeled primarily through their relationship to an application or as independent, platform-neutral identity resources, while the emerging approach increasingly treats agents as distinct SCIM-managed identities with lifecycle, group, role, entitlement, and external-reference attributes. Working-group discussions have also clarified a boundary between public agent identities and ephemeral workload identities: SCIM is intended to provision and manage an agent’s eligibility for an identity, rather than issue runtime credentials or govern authorization directly. Under this layered model, OAuth and workload identity systems such as SPIFFE would provide scoped, short-lived access and credentials, while SCIM handles identity lifecycle and federation-related provisioning. Because the consolidated draft remains informational, unfinished, and scheduled to expire in December 2026 unless renewed or advanced, organizations are advised to avoid relying on it as a stable standard while considering agent identities as first-class resources rather than solely properties of applications.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Agents | 2 | 931 | 231 | 103 | -84% |
| Platform Engineering | 1 | 358 | 65 | 25 | -70% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.