Executive summary

Skyfire is an open access, identity, and payment infrastructure designed for AI agents, known as the Agent Trust Stack. Powered by the open Know Your Agent (KYA) protocol, it provides AI agents with verifiable, signed credentials (built on OAuth 2.0, JWTs, and JWKS) and tokenized payment mechanisms, allowing merchants to distinguish legitimate agent purchases from malicious bot traffic without changing existing checkout flows.

Each month, we highlight one of the founders of an Okta Ventures portfolio company. You’ll learn more about them and how they work with Okta. This month, we’re speaking with Amir Sarhangi, CEO of Skyfire.

What is Skyfire, and what is your mission?

Skyfire is access, identity, and checkout infrastructure for AI agents—we call it the Agent Trust Stack. Our open Know Your Agent (KYA) protocol gives an agent a verifiable identity and a way to pay, so the businesses on the other side of that transaction know exactly who they're dealing with.

The mission is straightforward: Every system that decides who gets access online was built on the assumption that a person is on the other end. Agents break that assumption, and right now the default response is to block them. 

With more than half of all internet traffic now coming from agents, that's the wrong instinct. An agent accessing a service or executing a purchase on behalf of a real customer isn't a threat—it's a customer. We're building the layer that lets a merchant distinguish verified agents from other consumers and treat them like first-class consumers on the web.

What were you doing prior to Skyfire that led you to this moment?

I've spent most of my career on infrastructure that only works if the whole industry adopts it. I co-founded Jibe Mobile around Rich Communication Services (RCS), a messaging standard the industry had written off. Google acquired us in 2015, and I led RCS there through the Universal Profile rollout. It took about a decade, but RCS is now how billions of people message each other.

After that, I was VP of Product at Ripple, working on payment rails alongside Craig DeWitt, who co-founded Skyfire with me. That's where I learned how hard it is to move value between parties who don't already trust each other, and how much of that problem is actually an identity problem wearing a payments costume.

Agentic commerce is the same shape of bet, with one difference: the timeline isn't a decade. It's happening now.

What is Skyfire’s solution, and what challenge does it solve? 

The challenge is trust. Right now, when an agent hits a merchant's site, there's no principal behind the request—no verified human who authorized it, no financial relationship, and no recourse if something goes wrong. So bot defense treats it like every other piece of automation and blocks it. The same rules that stop fraud also stop revenue.

KYA fixes the trust gap. Every verified agent carries a signed token attesting to the platform it runs on, the specific agent making the request, and the human or enterprise that authorized it. It's built on JSON Web Tokens (JWTs) and the standard OAuth 2.0 and JSON Web Key Set (JWKS) infrastructure, a deliberate choice. Merchants can verify a KYA token with the same public key infrastructure they already run. Nobody replatforms.

On top of that identity layer, we provide tokenized payment credentials so an agent can complete checkout through the merchant's existing payment stack, with no parallel checkout path for agent traffic.

This creates a third option for merchants: They no longer choose between accepting unverified automation and blocking legitimate demand. They allow verified, trusted agents; they maintain their existing security posture for everything else; and they can finally attribute agent-driven transactions to revenue. Because we've integrated KYA with the vast majority of major bot defense and edge security providers, this capability covers most of the commercial web without merchants needing to do bespoke integration work.

Agent Trust Stack: Key technical capabilities and specifications

Feature/component

Technical standard

Primary function

Merchant implementation impact

Know Your Agent (KYA)

OAuth 2.0, JWT, JWKS

Verifies agent identity, authorizing platform, and human owner

Uses existing public key infrastructure; zero replatforming

Agent payment credentials

Tokenized payment rails

Enables agents to execute purchases on behalf of users

Integrates directly into existing payment gateways

Edge security integration

Standard HTTP header

Integrates KYA directly into bot defense providers

Operates natively across web application firewalls

Why did Skyfire want to work with Okta?

Because identity has to come first, and Okta is the most credible independent voice on identity in the market.

There's a temptation in this space to treat agentic commerce as a payments problem and bolt identity on later. That gets the order wrong. Payment is the easy part once you know who is making the purchase and what they're authorized to do. 

Okta has been making the case that every AI agent is an identity that has to be onboarded, governed, and revoked like any other. We've been making the case that the agent's credentials have to be portable across every layer it touches. Those are the same arguments.

There's also a practical reason: An agent credential is only useful if it's recognized everywhere the agent goes, inside the enterprise and out on the open web. Okta and Auth0 sit in front of an enormous share of enterprise and developer applications. That's the fastest path to making verified agent identity a default rather than a feature.

What trends do you expect to see in the industry? 

My thesis is simple: Open always wins. Not because open is more virtuous, but because scale is the only thing that makes any of this work, and nothing proprietary reaches everybody.

An agent shows up at a merchant's site carrying a KYA token in the header. The merchant's existing web security provider accepts that token and grants access. The merchant doesn't build anything, doesn't integrate anything, doesn't replatform. That model scales across the entire internet because on it rides infrastructure that's already deployed. A proprietary approach requires every merchant to say yes individually, and merchants aren't going to run a separate integration for every AI platform sending them traffic. They'll wait, and everyone loses time.

The nearer-term trend I'd point merchants to is more urgent than any of this. Internet traffic has grown roughly tenfold over the last couple of years, and more than half of it is now bot traffic. Merchants live on data, and a growing slice of their pie chart has gone gray. Some of that gray is fraud. Some of it is real customers who delegated the shopping to an agent. Right now, most merchants can't tell those apart, so they treat it all as risk. The first move isn't a strategy document—it's getting visibility into who's actually showing up and on whose behalf.

The three-stage evolution of autonomous agentic commerce

On the consumer side, I expect adoption to arrive in stages rather than all at once:

  1. “Buy for me” task execution: It starts with “buy for me,” where you already know what you want, and the agent just executes. 
  2. “Discover and confirm” guided shopping: Then it moves to a chat experience where you're discovering, and the agent comes back to ask permission before spending anything. 
  3. Autonomous execution of delegated commerce: Eventually, you get real autonomy, where you tell your agent to buy the concert tickets if it can find them for less than $200, and you've authorized that in advance. 

Each stage earns consumer trust for the next one.

People point to the implementations that got pulled back this year as evidence that the whole thing is premature. I'd read it differently. Some of those launched fast, and the experience wasn't ready. The bar is higher than people assume. If an agent just walks to a retailer and buys a thing, you'd have done that yourself. The reason to use an agent is that it does a better job than you would—finding the price, applying the offer, and completing the purchase, whether or not you already have a relationship with that merchant. That takes reach across the whole web, and reach is the thing open standards give you and closed ones don't.

Of course, this is all expected—people wouldn't put a credit card into a website 30 years ago either.

 

Interested in joining Okta Ventures? Check out our FAQ here and feel free to reach out to our team or submit your business for review.

 

Continue your Identity journey