Identi3

Dock

Identi3 is all about Digital Identity. In each episode, we'll bring you insights from experts at the forefront of the Digital ID space. Hosted by Nick Lambert, Dock's CEO.

  1. 17h ago

    Building a Business Model Around EUDI Credentials [Live]

    In this session, we look at how money will move in the European Digital Identity ecosystem. EUDI is designed so that people hold verified credentials in their own wallets and share them with consent, which makes the traditional model of verifiers paying data brokers hard to run. So who pays, and for what? Speakers: - Agne Caunt, Product Owner at Dock Labs - Richard Esplin, Head of Product at Dock Labs (0:00) Introduction: business models for the EUDI ecosystem (0:45) Why EUDI discourages the data broker model (4:41) Scope: models beyond the notified EUDI wallet (7:01) How EUDI changes the way we do business (12:23) Why bother aligning with EUDI standards? (13:24) Custom credentials vs. EAAs vs. QEAAs (17:33) How the credential path shapes your business model (20:01) Reasons to participate in EUDI (21:27) Business models across the trust triangle (22:13) Issuer models: holder pays, bundled fees, cost savings (25:56) Issuer models: customer acquisition and mandated credentials (29:08) Verifier pays issuer per event, and why unlinkability breaks it (32:59) Audience question: identity, payments, and chargebacks (35:24) How verifiers capture value (38:13) Wallet models: holder pays, issuer pays, per verification (42:40) Which wallets can charge, and the privacy tradeoff (44:24) Business wallets (46:14) Ecosystems: open vs. closed (48:54) Ecosystem models: scheme fees, certification, entry fees (51:15) Ecosystem models: revenue sharing and marketplaces (53:41) Summary: every party can pay (55:50) Q&A: was a commercial model ever part of the EUDI design? (58:44) Q&A: when does the wallet provider pay? (1:00:29) Q&A: Apple, Google, Samsung, and multiple wallets (1:02:23) Q&A: where does liability fit? 📚 EXPLORE: Website - https://www.dock.io/ LinkedIn - https://www.linkedin.com/company/docknetwork/

  2. Sep 14

    How to Give AI Agents Verifiable Proof of Authority [Live Demo]

    In this session, we show how an AI agent can be given a narrow, revocable slice of a person's authority, and how the counterparty on the other side of the transaction can verify it. Identifying an agent is not the hard part. Proving who authorized it, what they authorized, and whether the action falls inside those limits is. The demo follows an office manager at a fictional enterprise who delegates part of her purchasing authority to an agent that reorders paper and toner. When the agent places the order, the vendor verifies the delegation chain: who granted the authority, what it covers, whether it is still valid, and whether this specific purchase sits inside it. (0:00) Why agent identity alone is not enough (2:10) Framing the problem: agents can transact, but cannot be trusted (5:09) The three questions behind trusting an agent (6:16) Delegation in four steps: issue, present, verify, revoke (7:46) The scenario: Lisa, Atlas and Stockwell (9:17) Demo: a cloud wallet embedded in the employee portal (11:07) Purchasing authority as a credential with limits (12:48) Delegating a narrow slice of purchasing authority (13:57) The agent assembles and submits an order (15:00) Verification from the vendor's side (16:21) Audit log, and why agents are not privacy holders (17:26) Changing the rules: schemas, rule sets and Cedar policy (19:37) Capabilities: vendors, product categories and spend limits (20:47) Delegation depth and sub-agent redelegation (22:07) Using the same mechanism for human delegation (23:26) Why an internal procurement use case (25:31) Where the vendor's trust in the buyer comes from (27:42) What the verification evidence actually contains (30:13) Responsibility, accountability and the delegation chain (32:07) Setup walkthrough: onboarding, issuance, delegation (34:28) Transaction walkthrough and audit trail (36:22) How much credential detail should a verifier ask for (40:03) Technology used: REST API, Wallet SDK, MCP servers (41:37) Agent wallets over MCP (42:38) Landscape: bot blocking, OAuth extensions, TAP, KYA-OS, x401, Verifiable Intent (46:43) Closed ecosystems versus industry-wide adoption (48:31) Roadmap: standards alignment, auditing and reporting (52:01) Payment settlement and AP2 (53:50) When delegation matters and when payment is enough Website - https://www.dock.io/ LinkedIn - https://www.linkedin.com/company/docknetwork/

  3. Aug 3

    FIDO’s Vision for Passkeys, Digital Identity and AI Agents, with Andrew Shikiar (FIDO Alliance CEO)

    In this session, Andrew Shikiar, CEO at the FIDO Alliance, explains why passkeys succeeded where earlier password replacements failed, and how the FIDO Alliance is now applying the same playbook to digital credentials and AI agents. (0:00) Introduction (2:00) What the FIDO Alliance does, and where passkeys stand today (5:04) Why passkeys succeeded where earlier password replacements did not (9:03) Why the password problem unified the whole industry (10:22) What a passkey proves, and what it does not (11:07) Passkeys versus credentials, or passkeys and credentials (12:32) Giving verifiable credentials a passkey moment (14:44) eIDAS and the EUDI wallet as catalyst (15:23) Inside the baseline wallet profile (17:26) Will other regions copy the EUDI model? (20:02) Derived credentials and the layer above the regulated core (23:23) Where agentic commerce actually is today (27:07) Why agentic commerce is a liability problem first (29:12) Will B2B agentic commerce arrive first? (33:47) What a merchant needs before it can trust an agent (37:58) What actually changed in identity over the past decade (39:40) AP2 and Verifiable Intent donated into FIDO (42:16) What AP2 and Verifiable Intent each solve (50:25) Audience question: how identity strategies are broadening (52:16) Audience question: who gives an agent its identity (53:18) Audience question: certification and smaller wallet providers (56:46) Privacy in the wallet certification programWebsite - https://www.dock.io/LinkedIn - https://www.linkedin.com/company/docknetwork/

  4. Jul 20

    The Identity Challenge in AI Agent Payments (with Harsh Mehta from Worldpay)

    In this session, Harsh Mehta of Worldpay and Dock Labs unpack the identity and trust challenges behind AI agents and agentic payments: what is genuinely working today, what is still marketing, and what has to be solved before agents can transact autonomously. (1:25) Meet the guest: Harsh Mehta on AI and agentic commerce at Worldpay (5:47) Defining agentic commerce: reactive agents vs proactive agents (8:08) The levels of autonomy and why the headlines run ahead of reality (9:06) Human in the loop today: ACP, Google's protocol, and why browsers stop at checkout (12:47) Are more agent transactions slipping through than we realize? (13:18) Structured retail flows, embedded checkout, and why discovery is the long pole (15:24) Why B2B and procurement may scale faster than consumer shopping (16:50) The three hardest unsolved problems: data loss, identity, intent and liability (19:20) How agentic commerce inverts twenty years of fraud detection (20:54) False positives: when your fraud stack blocks your best new customers (21:57) Dock Labs' model: tying agents to individuals through delegation and verifiable credentials (25:44) Liability at agentic scale and who ends up holding the can (27:56) Intent frameworks: Mastercard Verifiable Intent, Google AP2, and selective disclosure (29:00) When bad product data is the real culprit (32:27) Who owns the mandate verification layer: platforms, PSPs, or a neutral layer (37:05) Commercial models: where value lands when an agent sits in the middle (40:51) Closing takeaways: build the foundations now, do the unglamorous work Website - https://www.dock.io/ LinkedIn - https://www.linkedin.com/company/docknetwork/

  5. Jul 13

    The EU Digital Identity Wallet: A Practical Guide

    In this session, Agne Caunt and Richard Esplin from Dock Labs break down the EU Digital Identity Wallet (EUDI) at the level most explainers skip: how the ecosystem is actually structured, what matters versus what is noise, and the practical steps an organization can take today. (00:00) Introduction (06:18) Regulation: from eIDAS 2014 to the 2024 revision (07:30) The BLT model: business, legal, and technical layers (09:19) Where Europe innovated (legal and business) versus stayed conservative (technical) (10:44) The three credential types: PID, QEAA, EAA (12:18) Platform and format: when EUDI-compliant and "compliant enough" diverge (14:39) Wallets: state wallets versus private wallets (17:01) QEAAs in private wallets and what DICE revealed (19:18) Google, Apple, and Samsung: where big tech wallets fit (23:15) Where a technology provider fits across the ecosystem (26:10) The standards, in one slide: OpenID4VC, HAIP, SD-JWT VC, mdoc (29:47) What EUDI deliberately left out: JSON-LD, DIDs, and ZKPs (33:34) An honest assessment of what is still moving (35:14) Practical steps: the relying party path (45:12) The issuer path: QEAA versus EAA (47:48) The wallet provider path and white-labeling (54:20) The European Business Wallet and the WE BUILD consortium (57:19) Payment models: who pays whom (1:01:24) Audience Q&A: country front-runners, multiple wallets, and international interoperability Website - https://www.dock.io/ LinkedIn - https://www.linkedin.com/company/docknetwork/

  6. Jun 15

    Liability in Agentic Commerce: Who Takes the Risk? [Live]

    What happens to liability when the entity making a purchase is not a human? AI agents are moving from research into commercial reality. They can research and execute purchases. But the legal, identity, and payment infrastructure that commerce runs on was designed around humans in the loop. This session explores what breaks when agents enter the picture and what needs to be built before agentic commerce can scale. Guests: - Przemek Praszczalek, Product Lead at Invela Network (formerly Mastercard, nine years in emerging payments and verifiable credentials) - Ronald Kogens, Partner at MME, a Swiss law firm specializing in technology and financial markets law (0:00) — Introduction and framing (6:44) — How is agentic commerce different from traditional e-commerce? (10:18) — Legal perspective: what changes when a non-human initiates a transaction? (12:46) — Authenticating the agent vs. authenticating the person behind it (16:26) — Bank liability when agents interact with fraudulent merchants (19:07) — The closed vs. open ecosystem problem (20:34) — Does the "I agree" button still work when an agent is clicking it? (25:07) — Dispute flows, chargebacks, and cognitive overload (28:31) — When the agent screws up: who is actually liable? (31:33) — The EU AI Act and its implications for agent developers (33:18) — New fraud vectors introduced by agentic commerce (37:10) — Should agentic transactions be flagged differently in payment rails? (40:08) — How will dispute resolution change in practice? (43:37) — Could agents ever have legal personality? (46:00) — Timeline: when does autonomous agentic commerce actually arrive? (48:43) — B2B vs. B2C: which scales faster and why? (54:16) — Audience Q&A: UK regulation and the T&Cs consent problem Website - https://www.dock.io/ LinkedIn - https://www.linkedin.com/company/docknetwork/

  7. Jun 1

    Can We Really Have Zero Trust with a Federated Identity Architecture? With Justin Richer (MongoDB)

    Most organizations say they are doing Zero Trust. Many still trust their IAM directory implicitly, protect it with a firewall, and call that a modern identity architecture. That is a perimeter by another name. In this session, Agne Caunt (Dock Labs), Richard Esplin (Dock Labs) and Justin Richer (MongoDB) work through what Zero Trust actually requires at the identity layer, why federated architectures tend to recreate the problems they were designed to solve, and what a more structurally sound approach looks like. 0:00 Introduction and guest overview 3:48 Zero Trust: origins and core principles 10:26 Why Zero Trust is still unnatural 11:45 Zero Trust in what? The foundational question 13:14 Directory synchronization: how enterprise identity fragility compounds 15:47 Verifiable credentials and the move to user wallets 18:06 Is the wallet really untrusted? Justin pushes back 20:39 Practical transition: using wallets at domain boundaries, not everywhere 22:55 VCs as a reinvention of X.509 for an online world 26:22 Tool comparison: OAuth/OIDC/SAML + SCIM vs. VCs 27:42 Shared Signals and Events (SSE): strengths and structural limits 31:51 User Managed Access (UMA): what it got right, why it stalled 34:35 GNAP: what it solves, when to use it instead of OAuth 41:00 SPIFFE/SPIRE: workload identity and short-lived credentials 46:06 SPIFFE's trust model and the "bottom turtle" question 47:24 WIMSE: bridging workload identity across trust domains 51:12 Agentic identity: the question from the audience 52:38 AI agents -- neither human nor workload, and why that matters 55:26 "On behalf of" vs. "for the benefit of" -- the liability distinction 58:55 What would a Zero Trust native architecture actually look like? Website - https://www.dock.io/ LinkedIn - https://www.linkedin.com/company/docknetwork/

  8. May 18

    Trusted Caller Identity: Pilot Results from GSMA & Telefónica [Live]

    This session presents the results of a six-month proof of concept run by Telefónica Tech, GSMA, Dock Labs, and TMT ID to rebuild call center authentication using mobile network APIs and verifiable credentials. The PoC completed authentications in under 60 seconds on average, with 100% of trialists saying they would prefer it over existing methods. Guests: - Glyn Povah, Global Product Development Director at Telefónica Tech - Helene Vigue, Identity and Data Director at GSMA Timestamps (00:00) - Introduction and context (00:28) - Guest introductions: Glyn Povah (Telefónica Tech) and Helene Vigue (GSMA) (04:34) - Strategic context: why call center impersonation fraud prompted this PoC (07:00) - The problems with current authentication: CLI spoofing, SIM swap, knowledge-based checks (08:32) - PoC goals: speed, security, and privacy (10:17) - GSMA perspective: scam as a global cross-industry problem (14:41) - Demo video: how the authentication flow works (16:26) - PoC results: trialist feedback and quantitative outcomes (20:32) - Carrier perspective: commercialisation, network APIs, and next steps (22:09) - The wallet ecosystem: complexity, government-led development, and commercial tension (30:05) - Identity industry perspective: user experience design choices and distribution challenges (37:10) - The extensibility of verifiable credentials beyond call center authentication (44:06) - Audience Q&A 📚 EXPLORE: Website - https://www.dock.io/ LinkedIn - https://www.linkedin.com/company/docknetwork/

Ratings & Reviews

About

Identi3 is all about Digital Identity. In each episode, we'll bring you insights from experts at the forefront of the Digital ID space. Hosted by Nick Lambert, Dock's CEO.