AI Agents Have an Identity Crisis and OAuth Alone Will Not Fix It

Why multi-agent systems need verifiable delegation, not just valid tokens A human prompts an agent. That agent delegates to another agent. A sub-agent calls a tool, which calls an API, which touches real data and real systems. Now the key question: Who is acting at each step, and on whose authority? Most teams answer this with one of two lines: “We use OAuth through MCP.” “Our platform handles access controls.” Both can be true. Neither is enough for multi-step agent workflows. ...

February 25, 2026 · 3 min · Pawan Khandavilli