a 2026 proposal for verifiable identity and delegation in agent ecosystems - cryptographic chains of authority that travel along MCP and A2A invocations, so a downstream service can check that the agent calling it was actually delegated the authority to act.
The shelf: AIP secures the chain of command along invocations; the red box secures the chain of custody of what those invocations handed back.
Etymology and backstory
proposed by Prakash in 2026 as agent protocols consolidated - MCP standardized tool invocation, A2A standardized discovery, and identity was the missing layer. Its headline number, 0.086 percent overhead, is the field's comparable figure for an in-path trust layer.
Ecosystem
rides the same invocation rails as MCP and A2A; part of the agent-protocol standardization conversation alongside agent cards and delegation tokens.
In codexproof
cited beside MCP and A2A in the introduction and tagged in Related Work - AIP chains authority, delegation, and optional completion blocks along invocations, while codexproof makes typed evidence links target parent content-ids. Orthogonal layers that compose: AIP answers whether this agent was allowed to make this call; codexproof answers whether these bytes and this declared lineage survived the trip. Both can ride one gateway.