Markdown Version | Transcript | Session Recording | Session Materials

Session Date/Time: 20 Jul 2026 12:00 ✎ Suggest a correction

WIMSE

Summary

The WIMSE (Workload Identity in a Multi System Environment) Working Group met at IETF 120 in Vienna. The session was split into two parts: a review of the group's active drafts heading toward Working Group Last Call (WGLC), followed by proposals for new work.

The WG has made significant progress since its last meeting, with several core documents nearing readiness for WGLC. The chairs emphasized the importance of completing current milestones before adopting new items. A strong theme throughout the meeting was the integration of transaction tokens into internal call stacks and the emerging security challenges surrounding AI agents and workload attestation.

Key Discussion Points

Part 1: Active Working Group Documents

1. Welcome and Chair Updates

2. Workload Credentials (WIT/WIC)

3. Workload Proof Token (WPT)

4. WIMSE HTTP Signatures

5. WIMSE Mutual TLS

6. WIMSE Architecture

7. Workload Identifier


Part 2: Proposed New Work

8. WIMSE Trust Domain Discovery

9. AI Agent Authentication and Authorization (AIMS)

10. Offline Workload Access for User-Owned Resources Without Refresh Tokens

11. Heterogeneous Credential Verification

12. PEDIGREE: Per-Hop Delegation Above Workload Credentials

13. WIMSE Workload Attestation

14. SOOS: Mandate JWT & Cross-Principal Transaction ID (XPID)


Part 3: Open Discussion / Other Business

Decisions and Action Items

Next Steps

Related Documents

draft-ietf-wimse-arch, draft-ietf-wimse-http-signature, draft-ietf-wimse-identifier, draft-ietf-wimse-mutual-tls, draft-ietf-wimse-workload-creds, draft-ietf-wimse-wpt