I wrote a solution for this, and it has been working across several organizations for some months now. I run it as a public service at https://awid.ai but I would love to offload it to a foundation.
- OSS (https://github.com/awebai/aweb/tree/main/awid)
- Trust rooted in the DNS.
- Multiple registries supported.
- did, verifiable stable identities.
- Certificate-based teams.
It is being a very interesting project so far. It's at the core of my https://aweb.ai which enables agents to communicate globally, and it makes it possible to build really simple agent-first tools where auth is just a matter of validating a certificate.