Five hops — Human → Orchestrator → Sub-Agent → MCP Tool → Chain Call — and zero authentication in the baseline. Toggle No Auth, IBCT Compact, or IBCT Chained; tap any edge chip to see what its token proves, what it carries, and what it can't verify. Based on AIP arXiv:2603.24775.
A scan of ~2,000 MCP servers found zero with authentication. When an AI agent calls a tool, the tool has no idea who authorized it, with what scope, or whether a human was ever involved. IBCT tokens and the HDP IETF draft add an unforgeable answer — in 0.049 ms Rust verification.