Problem
An agent can be known in more than one key namespace: met over an x402 payment signature, recognized later by AAuth agent identity. Nothing binds the two, so "can pay" and "is the agent we have met" cannot be connected even when both facts are established. On payment-only routes, payment is the only identity, which conflates ability to pay with recognition.
Suggested direction
The coherent ask is an AP metadata or agent-token claim by which an agent identity attests to other public keys it controls, verifiable in both directions (the AAuth identity lists the x402 key; possession of the x402 key can be challenged). This is not protocol-draft scope, but the draft should spend a paragraph saying where it would live — likely a companion document — so the gap is acknowledged rather than rediscovered. Related but distinct from #71 (sharing activity and compromise signals): that is about parties exchanging signals, this is about one identity attesting to its own keys.
Context
From the notes.ito.com deployment review (writeup, review pass) — their CR-8. Concrete case: an agent first seen paying over x402, later presenting an agent token; the deployment wants one reputation record, not two strangers.
Problem
An agent can be known in more than one key namespace: met over an x402 payment signature, recognized later by AAuth agent identity. Nothing binds the two, so "can pay" and "is the agent we have met" cannot be connected even when both facts are established. On payment-only routes, payment is the only identity, which conflates ability to pay with recognition.
Suggested direction
The coherent ask is an AP metadata or agent-token claim by which an agent identity attests to other public keys it controls, verifiable in both directions (the AAuth identity lists the x402 key; possession of the x402 key can be challenged). This is not protocol-draft scope, but the draft should spend a paragraph saying where it would live — likely a companion document — so the gap is acknowledged rather than rediscovered. Related but distinct from #71 (sharing activity and compromise signals): that is about parties exchanging signals, this is about one identity attesting to its own keys.
Context
From the notes.ito.com deployment review (writeup, review pass) — their CR-8. Concrete case: an agent first seen paying over x402, later presenting an agent token; the deployment wants one reputation record, not two strangers.