| Primary SDK verifiers | Signed issuer/scopes; opt-in current authority and expected identities | Hosted human consent; strict execution policy |
| Framework wrappers / HTTP guards / adapters / gateway | Token and declared scope before callback/proxy; optional current authority | Action/input binding, decision consumption, atomic caps, server-owned identity |
| MCP Auth | Authenticated human consent and resource guards with configured issuer authority | Host login/session resolver, storage, issuer, policy engine and account lifecycle |
| Management MCP / CLI / Terraform | Privileged account administration using the operator’s API key | Private administrative access; do not expose principal-session creation to arbitrary end-user agents |
| Agent Passport / HTTP Signatures | Credential identity/status or request-key possession | Trusted issuer/key/status/nonce stores plus separate human grants and execution policy |
| Legacy MPP Passport | Passport transport/verification | Configure trusted issuer/current status; not a human-consent or spend-authorization proof |
| x402 legacy GDT | Delegation signature and configured token registry | Durable shared revocation and accounting; the default in-memory registry is not cross-process issuer status |
| x402 managed prepaid wallet | Issuer-managed wallet authorization | Issuer/custody/facilitator settlement and real-wallet testing remain separate dependencies |
| Gemma offline | Snapshot signature and configured local scopes | Cannot promise immediate revocation or fresh human confirmation; never use alone where current authority is required |
| DPDP / destinations / conformance / mock issuer | Purpose helpers, audit export or testing | Not authentication or human-consent guards |