Dev.to
6/24/2026

An AI agent acted across two companies. Whose audit log knows which human?
Short summary
When AI agents delegate work across identity providers, token-exchange standards lose cryptographic proof of which human authorized the action. Crumb solves this by embedding upstream tokens into downstream ones with hash verification, creating a tamper-evident chain verifiable without trusting intermediaries.
- •Current token-exchange breaks audit trails when agents cross company boundaries
- •Crumb embeds upstream tokens (with signatures) into downstream ones as unforgeable proof
- •Verifier can walk the chain backward, checking each segment against its actual issuer's key
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



