Identity programs were built for a person. They join, they get a role, they leave. People still do that. They’re just not most of the accounts anymore, and they’re not the only thing that can click a button.
Passkeys are finally in a place where you can put them in a contract. On 25 August 2026 the W3C published Web Authentication Level 3 as a Recommendation. That’s the stable spec. Browsers had already been shipping most of it. Level 4 opened as a first public draft on 15 September, so if a vendor waves “Level 4 support” at you, smile and ask for Level 3.
OAuth 2.1 is what I’d build to, and it’s still an Internet-Draft. Draft 16, dated 3 September 2026, is pretty clear: PKCE with S256, no implicit grant, no password grant, redirect URIs matched exactly, and the authorization server has to send iss back on the redirect. The working group hopes to hand it to the IESG in December. I wouldn’t wait for an RFC number before turning implicit off.
Then there’s the agent problem. NIST’s Center for AI Standards and Innovation opened an AI Agent Standards Initiative on 17 February 2026, and the National Cybersecurity Center of Excellence published a concept paper and a project on using the identity standards we already have. It’s a demo, which is useful, and it isn’t a new protocol with a compliance date. What they’re pointing at is familiar: OAuth, OpenID Connect, SCIM, workload identity, and a record of which person asked and which piece of software did the thing.
Put those next to each other and the pattern is ordinary. A grant, for one API, held by a key, with an end. The rest of this site is the news around that, and some diagrams for when the acronyms pile up.