What I mean is that once you have a token that represents your identity, you can pass it to your agent. As you said, humans aren’t digital, so we need to delegate the trust to a digital marker (auth token, cryptographic signature, etc). But once digitalized there is no way that I know of to block an agent from using that marker. And I don’t mean the agent stealing it. I mean the human running an agent that impersonates them deliberately

Exactly. There is only an arms race, which is escalating costs. Eventually it breaks and we use social means to manage it, surrender the digital space, or accept the artificial nature of the digital realm.