A Confused Deputy arises when a trusted system with legitimate authority is induced to use that authority for a high-risk or irreversible action that the Agent's principal did not intend, creating a relying-party (RP) risk of repudiation. The Agent may arrive with valid Tokens, passkeys, inherited session, or tool credentials, even if instructions have been shaped by prompt injection or model miscomprehension. Whilst the request is authenticated, human consent to the means taken is not.
This session develops how RPs can deploy a gatekeeper to distinguish authorised access from authorised actions and produce a legally auditable record. When proving the principal is present and consenting, it assumes that any signal produced by the agent or its device remains endogenous to the compromised context. This requires an exogenous proof that the agent cannot generate, evaluated by the RP before execution.
The talk presents a decentralised, open-source, relying-party pattern that does not require the agent or its operator to have onboarded to or used the scheme. It composes with OAuth, MCP, and passkeys, adding the missing intent boundary for agent-mediated workflows.