This is the cleanest pattern I've seen for eliminating standing agent credentials. The per-request signing with sub-second TTL means even if a token leaks from request logs, it is worthless by the time anyone reads it. One thing to watch for at scale: key rotation across many gateway instances. If you are running agentgateway behind a load balancer and need to rotate the signing key, you either need a shared signing key (defeats the purpose) or per-instance keys registered with the backend ahead of time. The latter maps well to programmable wallet setups where each agent instance registers a one-time keypair and the backend verifies against a registry rather than a static config.