ANCHORED

Identity & Trust

On-chain identity registries, reputation systems, attestation services, validators and naming for autonomous agents. The substrate that makes agent-to-agent commerce, accountability and discovery possible without pre-existing trust.

236
Agents
31.2%
Of classified
TKTK
Avg AHS
TKTK
% HIGH conf.
Phase 2.2 classification: 25 Apr 2026 · 1,000-agent random sample

Definition & scope

An Identity & Trust Agent is an autonomous software agent or protocol primitive whose primary function is to establish, register, attest to, or verify the identity and trustworthiness of other agents. This is the substrate the rest of the agent economy stands on: without portable identity and verifiable trust signals, agent-to-agent commerce reduces to bespoke relationships between operators that already know each other.

The category is the second-largest anchored set in AHM Taxonomy v1, behind only Orchestration. Its size reflects how recently the standards-track foundation has matured: ERC-8004 went live on Ethereum mainnet on 29 January 2026, and the ecosystem has built out fast — multiple SDKs, cross-chain deployments, security audits, and reputation infrastructure indexing six-figure populations of registered agents.

In the Phase 2.2 classification run, Identity & Trust Agents were anchored on ERC-8004 Identity Registry. An agent qualified as Identity & Trust if its transaction history showed direct interaction with the registry contract on its deployed chain. The methodology is documented in the POC summary; subsequent classification phases are expected to expand the anchor set toward EAS (Ethereum Attestation Service), reputation-aggregator contracts, and naming systems.

Inclusion criteria

  • Primary function is identity registration, attestation, reputation aggregation, or trust signal production
  • Operates on-chain or interacts with on-chain trust primitives
  • Outputs are consumed by other agents to inform commercial or coordination decisions
  • May be a single agent, an SDK / framework, or a protocol acting as a registry

Exclusion criteria

  • Agents that verify specific outputs or claims rather than identity / reputation generally → Verification
  • Pure smart-contract registries with no autonomous agent component → infrastructure, classified separately
  • Off-chain identity systems with no on-chain footprint → outside v1 taxonomy scope

Five functional cuts

Identity Registries

~ count pending

On-chain agent ID issuance and resolution. ERC-8004 Identity Registry is the canonical implementation: each agent gets an ERC-721 token whose tokenURI resolves to a structured registration file with capabilities and endpoints.

Reputation Systems

~ count pending

Feedback aggregation, score signing, cross-agent reputation portability. ERC-8004 Reputation Registry plus an emerging ecosystem of specialised aggregators (8k4 IGGY-Score, Helixa, AIAttribution).

Attestation & Credentialing

~ count pending

Structured claims about agents and their capabilities, signed by issuers and verifiable by consumers. EAS is the dominant general-purpose attestation primitive; agent-specific credentials are starting to layer on top.

Validation Services

~ count pending

Third-party agents that verify other agents' outputs, claims, or behaviour. ERC-8004 Validation Registry hooks into validator contracts; TEE-based and zkML-based validators are early implementations.

Naming & Discovery

~ count pending

Human-readable identity for agents. ENS records are increasingly used as endpoints in ERC-8004 registration files, bridging human-friendly naming with machine-verifiable identity.

Five Identity & Trust primitives in the wild

The agents and protocols below are well-known illustrations of the Identity & Trust category as defined above. ERC-8004 Identity Registry is both the dominant Phase 2.2 anchor and the substrate most other examples build on or interoperate with. Several entries are protocols and SDKs rather than discrete agents — appropriate for a category whose unit of analysis is often the registry, not the registrant.

Network: Ethereum mainnet + many chains·Registry: ERC-8004·Sub-category: Identity Registries

The standards-track anchor for the entire category. Live on Ethereum mainnet since 29 January 2026 and deployed across Base, BSC, GOAT Network, MegaETH, Metis, XLayer, plus testnets including Hedera and Arc. Audited by Cyfrin, Nethermind, and the Ethereum Foundation Security Team. Each agent is an ERC-721 token whose tokenURI resolves to a registration file describing capabilities, A2A and MCP endpoints, and supported trust models. The deterministic vanity address pattern (0x8004A169... on mainnets) makes per-chain singletons easy to find.

Network: 25+ chains·Registry: Direct·Sub-category: Attestation & Credentialing

Tokenless public-good protocol for making structured attestations on-chain or off-chain. Functions as a general-purpose trust primitive that agent-specific credential systems increasingly build on. Used to issue verifiable claims about agent capabilities, audit results, behaviour, and operator identity. Supports zero-knowledge proof composition for selective disclosure. Funded by donations, grants, and retroactive public goods funding rather than tokens — a deliberate design choice to remain credibly neutral as critical infrastructure.

Network: cross-chain·Registry: ERC-8004·Sub-category: Identity Registries / Reputation

TypeScript and Python SDK for ERC-8004 — agent registration, reputation queries, validation flows, IPFS pinning, and OASF (Open Agent Standard Format) skill/domain taxonomy support. Developed by Marco De Rossi (one of the ERC-8004 specification authors) at Consensys / MetaMask, with subgraph integration for fast queries. Representative of how the spec is consumed in practice: most agent operators interact with ERC-8004 through SDKs rather than directly with the contracts.

8k4 API
Network: Base / BSC / Ethereum·Registry: Direct + ERC-8004·Sub-category: Reputation Systems

Reputation infrastructure layered on ERC-8004 — IGGY-Score trust scoring, metadata hosting, cross-chain agent lookup, with x402 pay-per-query pricing in USDC on Base. Public stats reported as 106,996 indexed agents across Base (33,939), BSC (44,020), and Ethereum (29,037). The figure is much larger than any single classification sample because it indexes the registry directly rather than sampling — a useful reference point for the size of the broader Identity & Trust population beyond AHM's Phase 2.2 sample.

Network: cross-chain·Registry: ERC-8004 + Phala TEE·Sub-category: Validation Services

Reference implementation combining ERC-8004 registration with Trusted Execution Environment attestation via Intel TDX. Demonstrates the "TEE-attestation" trust model from the ERC-8004 specification — agent identity is on-chain, but sensitive computation and key signing happen in a verifiable enclave. The pattern matters because pure on-chain trust models can verify that an agent registered, not how the agent operates internally; TEE attestation closes that gap for high-stakes use cases.

Use cases

Cross-organisational agent commerce. The core problem ERC-8004 was written to solve: how do agents from different operators discover each other, evaluate trustworthiness, and transact without pre-existing relationships? Identity registries plus reputation plus validation give an agent enough context about a counterparty to decide whether to engage. This is the precondition for an open agent economy — without it, every interaction has to be brokered by a trusted intermediary.

Portable reputation across platforms. An agent's identity is an ERC-721 NFT, transferable and queryable from any chain that supports the standard. Reputation accumulates against the on-chain identity, not against any single platform. An agent that builds a track record on Base can carry that reputation to BSC, to Ethereum mainnet, to Arc, and to any future deployment. The 8k4 API's 106,996 indexed agents across three chains is an early signal that this portability is being used.

Tiered trust matched to value at risk. ERC-8004's three trust models — reputation aggregation, crypto-economic staking, and TEE / zkML attestation — let agent operators pick a verification rigor appropriate to the task. Low-risk social interactions can rely on reputation; financial settlement might require TEE attestation; sensitive data workflows might require zk proofs. The standard provides primitives; the choice of trust model is application-specific.

Agent-to-agent due diligence at machine speed. Before transacting, an agent can query the Identity Registry (capability claims), the Reputation Registry (historical feedback), the Validation Registry (third-party validator results), and any layered attestations on EAS — in a single read pass. The latency of trust assessment drops to the speed of an on-chain read, which means agents can engage with previously-unknown counterparties without bottlenecking on human-mediated diligence.

Trust considerations

Sybil attacks
A malicious operator can register multiple agent identities to inflate reputation, manipulate aggregated scores, or evade negative history. Pre-authorised feedback partially mitigates this but does not solve it. Specialised reputation aggregators that apply Sybil resistance through reviewer trust scoring are emerging — but the protocol layer leaves the problem unsolved by design.
AHM Counterparty Map exposes interaction patterns that surface coordinated identity clusters; behavioural baselines flag identities whose activity profile matches known Sybil patterns.
Reputation gaming and collusion rings
Agents can mutually issue positive feedback to inflate each other's scores. The pattern is hard to detect from individual feedback events but visible in aggregate: tightly-coupled feedback graphs with low diversity of reviewers. Without aggregator-level Sybil resistance, naive reputation lookups can be systematically misled.
AHM Counterparty Map surfaces concentrated feedback relationships and low-diversity reviewer graphs.
Capability-claim integrity
ERC-8004 cryptographically links an agent's on-chain identity to its registration file, which advertises capabilities. The standard cannot verify those capabilities are actually functional or non-malicious. An agent can claim capabilities it does not have, and the trust layer above the protocol has to detect the gap.
AHM AHS multi-dimensional scoring captures behavioural consistency between claimed capabilities and observed activity; gap detection runs as a sub-dimension.
Validator capture and compromised attestation
Validators in ERC-8004's Validation Registry, and attestation issuers on EAS, are themselves trust assumptions. A captured or compromised validator can issue attestations that are formally valid but substantively wrong. The trust signal is only as strong as the validator's incentives, audit posture, and operational integrity.
AHM Health endpoint surfaces validator operational patterns; cross-validator consistency checks identify outliers.
Cross-chain identity fragmentation
Per-chain singleton deployment means an agent can register on multiple chains, with potentially divergent capabilities, reputation, and validation history. A consumer querying only one chain may miss critical history on another. The pattern resembles credit-history fragmentation across jurisdictions — solvable, but requires explicit cross-chain aggregation rather than the protocol providing it for free.
AHM ecosystem-wide scanning surfaces cross-chain identity correlations; behavioural baselines are calibrated against the agent's full multi-chain footprint where data is available.

AHM endpoints for this category

Related categories

Citations & further reading

  1. AHM Taxonomy v1 — POC summary and methodology (Phase 2.2), github.com/moonshot-cyber/agent-health-monitor
  2. ERC-8004: Trustless Agents (specification), eips.ethereum.org/EIPS/eip-8004
  3. ERC-8004: Trustless Agents — Fellowship of Ethereum Magicians discussion, ethereum-magicians.org
  4. ERC-8004 contracts repository and deployment addresses, github.com/erc-8004
  5. Awesome ERC-8004 — curated ecosystem resources, github.com/sudeepb02/awesome-erc8004
  6. QuickNode, "ERC-8004: A Developer's Guide to Trustless AI Agent Identity," March 2026, blog.quicknode.com
  7. Ethereum Attestation Service (EAS), attest.org
  8. Agent0 SDK documentation, sdk.ag0.xyz
  9. Composable Security, "ERC-8004: a practical explainer for trustless agents," October 2025, composable-security.com

Cite this page

BibTeX
@misc{ahm_taxonomy_identity_trust_2026,
  title  = {Identity \& Trust Agents --- AHM Taxonomy v1},
  author = {{Agent Health Monitor}},
  year   = {2026},
  month  = {May},
  url    = {https://intelligence.agenthealthmonitor.xyz/taxonomy/identity-trust},
  note   = {Accessed: 2026-05-07}
}

Classification methodology and category boundaries are documented in the AHM Taxonomy v1 POC summary.

Counts reflect the Phase 2.2 classification run (25 April 2026): a 1,000-agent random sample from Base mainnet wallets, of which 757 (75.7%) were classified across 6 anchored categories. Updated as new classification phases complete.