1. A New Toolkit for a New Kind of Internet Activity
The identity project World, co-founded by Sam Altman, has released a developer toolkit designed to anchor AI agents to verifiable human identities. Called AgentKit, the tool enables software agents acting autonomously on behalf of users to carry cryptographic proof that a real, unique person stands behind their activity. The launch, announced on Tuesday, integrates with x402 — a payment protocol developed in collaboration between Coinbase and Cloudflare — creating a combined solution that addresses both the payment mechanics and the identity layer of automated digital commerce.
2. Understanding the Problem AgentKit Is Designed to Solve
As AI systems become more capable, a new class of software — commonly called agents — has emerged that can browse websites, complete purchases, book appointments, compare prices, and execute a wide range of tasks with minimal human involvement during each transaction. This shift introduces a structural challenge for the internet's existing infrastructure: the web was built for humans, not for software acting in their place.
Websites and platforms that have spent years building defenses against automated bot traffic now face the prospect of having to distinguish between malicious bots and legitimate AI agents operating on behalf of real users. Without a reliable mechanism for making that distinction, legitimate agents risk being blocked alongside the spam, scrapers, and abuse tools they resemble from a technical standpoint. AgentKit is, at its core, an attempt to give AI agents a credible answer to the question that every platform will eventually ask: is there a real person behind this?
3. How AgentKit Works
The technical foundation of AgentKit rests on World's existing identity system, World ID. World ID is a privacy-preserving credential that attests to its holder being a unique human being — currently established through biometric verification using World's iris-scanning Orb hardware. Crucially, the system is designed so that this verification can be demonstrated to a third party without revealing any personal data about the individual. This is accomplished through zero-knowledge proofs, a cryptographic technique that allows one party to confirm a fact to another without disclosing the underlying information that establishes it.
AgentKit extends this credential to AI agents. A user who has obtained a World ID can delegate that credential to one or more agents operating on their behalf. When those agents interact with platforms or services that recognize World ID, they can demonstrate that they represent a verified human — without exposing the user's identity, biometric data, or personal details.
4. Linking Multiple Agents to a Single Person
One of the more technically significant design choices in AgentKit is its capacity to tie several distinct agents to a single verified human identity. This matters because the natural trajectory of agentic computing is toward multiplicity: a single user might simultaneously run agents responsible for travel research, shopping, scheduling, financial monitoring, and other tasks — each operating as a separate software process.
Without an identity layer, platforms receiving requests from these agents have no way to know whether they originate from one person or from a coordinated network of unrelated automated systems. AgentKit resolves this by allowing developers to link agents to the same verified human, enabling platforms to apply usage limits, access controls, or pricing logic at the level of the underlying person rather than at the level of individual agent instances.
This has practical applications for services that want to enforce policies like one free trial per user, a fixed daily action quota, or personalized rate limits — all of which become enforceable once the person behind multiple agents can be reliably identified.
5. The x402 Integration: Payments Meet Identity
AgentKit's integration with x402 adds a payments dimension to the identity framework. Developed collaboratively by Coinbase and Cloudflare, x402 is a protocol designed to embed stablecoin micropayments directly into the internet's communication layer. Rather than requiring a user to authorize each payment manually, x402 allows software agents to pay for services autonomously as part of the same process by which they access them — eliminating friction from transactions that are too small or too frequent to warrant human authorization at each step.
The combination of World ID-based identity and x402-based payments creates a framework in which an AI agent can simultaneously prove it represents a real person and complete a transaction in one coherent interaction. This addresses what Erik Reppel, head of engineering at Coinbase Developer Platform and the founder of x402, described as the relationship between payments and identity in the agentic commerce context: payments answer the question of how transactions are completed, while identity answers the question of who stands behind them. Both are required for a functioning ecosystem of AI-driven commerce.
6. The Scale of the Market at Stake
The commercial case for solving these problems is substantial. World has cited industry estimates suggesting that agentic commerce — commerce conducted by or mediated through AI agents — could represent a market of between $3 trillion and $5 trillion by 2030. Projections further suggest that agents could account for as much as a quarter of all e-commerce activity in the United States within the same timeframe.
Industry observers have made similarly bold predictions about the rate at which AI agents will come to outnumber humans in transactional contexts. Coinbase's founder has expressed the view that AI agents conducting transactions will outnumber human actors in the near future. The scale of this projected shift underscores why the infrastructure questions around agent identity and payments are being treated as foundational problems rather than secondary concerns.
7. A Privacy-First Architecture
A recurring theme in World's communications around AgentKit is the emphasis on privacy as a design constraint rather than an optional feature. The use of zero-knowledge proofs throughout the system means that verification does not require platforms to collect, store, or process personal data about the humans behind the agents.
This is a meaningful distinction from alternative approaches to identity verification, which often require submitting documents, photographs, or personal information to a central service that stores it indefinitely. In a regulatory environment where data protection requirements are tightening globally, and in a technical environment where large databases of personal information represent persistent security liabilities, a verification architecture that achieves its goal without creating those vulnerabilities has clear advantages.
World has been explicit that AgentKit is not intended to replace other identity systems already in use. Rather, it is positioned as a complementary layer that developers can add to their existing authentication infrastructure or deploy independently, depending on their requirements.
8. The Orb and Its Controversies
AgentKit in its current beta form relies on World's Orb — the iris-scanning hardware device through which users obtain their World ID credential. The Orb has been the most contentious element of World's overall project since the organization's earliest days, drawing criticism on several fronts: concerns about the collection of biometric data, questions about the security and permanence of stored iris scans, and debates about accessibility and the equity implications of requiring physical hardware for identity verification.
World acknowledges the limitations of Orb-only verification as a pathway to scale. The company has indicated that future versions of AgentKit will support alternative verification methods, including NFC-enabled passports and government-issued identification documents accessed through a system called World ID Credentials. This expansion would allow users to prove specific attributes about their identity — nationality, age range, or other verifiable characteristics — without disclosing the underlying documents or data.
9. World's Broader Ambition
The launch of AgentKit should be understood within the context of World's long-term strategic position. The organization has been building toward becoming the foundational identity layer for the internet — not just for human users, but for the increasingly automated systems that act on their behalf. With over 17.9 million verified users in its network at the time of the announcement, World already operates one of the largest proof-of-personhood systems in existence.
AgentKit represents the extension of that network's utility into a new domain: not just verifying that a human is using an app or service, but verifying that a human is authorizing an autonomous agent to operate across a wide range of digital environments on their behalf. In framing identity as the necessary complement to payments infrastructure, World is making the case that its network should be treated as a prerequisite for a trustworthy AI-driven web rather than as one option among many.
10. Infrastructure for What Comes Next
The collaboration between World and Coinbase reflects a broader recognition within the technology and crypto industries that the emergence of agentic AI creates infrastructure problems that existing systems were not designed to handle. Payment rails, identity verification, access controls, fraud prevention, and usage metering were all built with human users as the assumed actor. Adapting those systems — or building new ones — to function correctly in a world where software agents are increasingly the proximate actors is a challenge that spans both technical and institutional domains.
AgentKit, still in beta, is an early attempt at one piece of that puzzle. Whether it achieves broad developer adoption will depend on factors that extend beyond the quality of the technology itself — including the pace at which platforms choose to recognize World ID as a legitimate credential, the extent to which privacy-preserving verification gains regulatory acceptance, and the speed at which agentic commerce actually materializes at the scale being projected. For now, it represents a substantive attempt to give the AI agent economy a coherent answer to the identity question that will define whether automated commerce can function at scale.

