<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Projetxana</title>
    <description>The latest articles on DEV Community by Projetxana (@projetxana).</description>
    <link>https://dev.to/projetxana</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4172423%2Fee187bca-4408-404c-81b3-1f7b60ea3124.png</url>
      <title>DEV Community: Projetxana</title>
      <link>https://dev.to/projetxana</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/projetxana"/>
    <language>en</language>
    <item>
      <title>A Valid Signature Doesn't Mean an AI Agent Still Has Authority</title>
      <dc:creator>Projetxana</dc:creator>
      <pubDate>Fri, 09 Oct 2026 04:30:42 +0000</pubDate>
      <link>https://dev.to/projetxana/a-valid-signature-doesnt-mean-an-ai-agent-still-has-authority-1dm8</link>
      <guid>https://dev.to/projetxana/a-valid-signature-doesnt-mean-an-ai-agent-still-has-authority-1dm8</guid>
      <description>&lt;p&gt;Imagine an AI agent receives a valid, signed delegation to perform an action.&lt;/p&gt;

&lt;p&gt;The user later revokes that delegation in another system.&lt;/p&gt;

&lt;p&gt;The signature is still valid. The token may not have expired. But should the agent still be allowed to act?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Cryptographic validity and current delegated authority are two different questions.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;OAuth introspection, short-lived credentials and existing authorization systems address important parts of this problem. But we wanted to explore one specific challenge: checking whether a delegated authority path is still active when agents and issuers operate across different trust domains.&lt;/p&gt;

&lt;p&gt;We built &lt;strong&gt;GATE — Authority Verification Network&lt;/strong&gt; as an experimental Developer Preview to investigate this.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try the live demonstration
&lt;/h2&gt;

&lt;p&gt;Our hosted sandbox uses real HTTP requests to demonstrate three decisions:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Two authority paths are active → &lt;strong&gt;VALID / ALLOW&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;One path is revoked, but another survives → &lt;strong&gt;VALID / ALLOW&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Both paths are revoked → &lt;strong&gt;INVALID / DENY&lt;/strong&gt;
&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The demo uses a synthetic authority graph, not a third-party identity provider.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href="https://gate-beta-nu.vercel.app/demo.html" rel="noopener noreferrer"&gt;Try the interactive demonstration&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href="https://github.com/Projetxana/gate-authority-network" rel="noopener noreferrer"&gt;Explore the source code on GitHub&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;GATE also exposes an API for registering ES256 issuer keys and submitting signed authority events.&lt;/p&gt;

&lt;h3&gt;
  
  
  What we're not claiming
&lt;/h3&gt;

&lt;p&gt;GATE currently runs on a single Canadian primary, without production regional replicas or a guaranteed external issuer propagation time. It does not replace authentication, OAuth, application policy enforcement or an independently audited production authorization system.&lt;/p&gt;

&lt;p&gt;We're looking for developers who work with AI agents, MCP tools, delegated permissions or cross-domain authorization.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;I'd especially like to hear your thoughts on three questions:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;How do you currently handle upstream revocation for delegated agents?&lt;/li&gt;
&lt;li&gt;Is this already adequately solved by your existing stack?&lt;/li&gt;
&lt;li&gt;Would a separate authority-state verification service make integration easier, or just add another dependency?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;We're inviting a small group of independent developers to evaluate the API with their own authority sources.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://gate-beta-nu.vercel.app/" rel="noopener noreferrer"&gt;Join the GATE external developer beta&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Feedback and criticism are welcome.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>security</category>
      <category>opensource</category>
      <category>devops</category>
    </item>
  </channel>
</rss>
