ai contact center · published

Agentic apps registration approval and identity badges

Verified 2026-09-05 · 56 claims · sources tier 2 · 5 disputed

Also known as A2A, ACS, AGNTCY, Agent Central, Agentic App, Cisco Official, Federated through Registry, OASF.

Disputed claims: 5 claims below carry conflicting evidence.

Cisco defines an agentic app as a service exposing structured capabilities that an artificial intelligence agent can invoke, which is not tied to a specific protocol and is analogous to a Model Context Protocol server when that standard is used 11. Provisioning and governance for these apps take place within Control Hub to regulate authentication, user access, and tool availability 2540.

Provisioning and governance in Control Hub

Agentic app provisioning is located in Control Hub under Apps and then Agentic Apps, displaying both public applications and private apps onboarded by users within the organisation 25. Documentation reflects inconsistent navigation terminology, as 2 Cisco documents give different Control Hub paths: 1 specifies Apps and then Agentic Apps, while the other specifies Management, then Apps, then Agentic Servers 26. The Control Hub provisioning guide is intended for administrators only, establishing governance, authentication, and access controls over available agentic capabilities 40. The provisioning documentation also states that users bear full responsibility for understanding, complying with, and managing all aspects of the liability framework regarding Model Context Protocol application usage, though it never defines what that framework is or where it is published 37.

On an agentic app's general tab in Control Hub, administrators can allow or block the app for all organisation users 34. Sources disagree on the availability of group-level access controls: Cisco's admin approval guide documents an enablement audience of either the entire organisation or selected user groups resolved from the identity provider at request time 8, whereas Cisco's Model Context Protocol documentation for AI Agent Studio states that group-level access control is not supported and tool access is managed exclusively at the organisation level 48. Sources disagree further regarding per-tool assignments, as the admin approval guide outlines a per-tool assignment mode where each tool can be enabled for a different set of groups, overriding the server-level audience 39.

Cisco recommends evaluating tool risk based on the tool's name, description, input schema, and stated side effects, advising administrators to restrict operations involving deletion, financial transactions, sending email, and modifying user data to specific groups 35. However, tools carry no formal risk class field, meaning an administrator must evaluate the risk level using their own judgement 36. Additionally, an authorise automatic server data updates setting allows changes to a server's name, description, transport type, other metadata, or its address within the same domain to take effect without re-authorisation, while presenting an indicator to the administrator that changes occurred 23.

Capabilities and tool management

Control Hub presents 3 capability tabs for a Model Context Protocol server, covering tools, resources, and prompts 49. Enabling a tool in Control Hub makes it visible, discoverable, and usable by organisation users, while disabling it removes visibility and access 51. Prior to enabling a tool, an administrator can review its input schema, output schema, and annotations directly in Control Hub 7. Cisco states that similar functionality exists on the resources and prompts pages, but WarmTransfer's reading of the sources is that it does not itemise what similar covers 43.

Capability Tab Administrative Controls User Impact
Tools Review input/output schemas and annotations; toggle enable or disable 49751 Enabled tools are discoverable and usable; disabled tools are hidden and unavailable 51
Resources Cisco states similar functionality is available, but WarmTransfer's reading of the sources is that it does not itemise what similar covers 4943 Discoverable or hidden based on administrative enablement 5143
Prompts Cisco states similar functionality is available, but WarmTransfer's reading of the sources is that it does not itemise what similar covers 4943 Discoverable or hidden based on administrative enablement 5143

Once created in AI Agent Studio, Model Context Protocol actions are read-only, requiring a new action to be created if settings must be changed 38. WarmTransfer's reading of the sources is that the developer portal does not publish a specific number for the maximum action limit per agent, stating only that it is defined by the organisation's configuration 6.

Schema signature monitoring and drift

Cisco computes a schema signature for each tool and monitors it continuously, flagging any tool whose live signature differs from the previously approved version 44. Runtime behaviour upon signature drift is governed by the allow signature change setting 4546:

  • If the allow signature change setting is off, drifting tools are filtered out of list functions results and omitted from client delivery 45.
  • If the allow signature change setting is on, drifting tools continue to be delivered but carry an unsecure flag set to true so agent interfaces and clients can display warnings 46.

Regardless of whether the signature change setting permits continuous runtime access, formal approval of a new tool schema always requires explicit administrative re-authorisation 41.

Authentication methods

The authentication details requested in Control Hub correspond to the configuration specified in the developer portal 22. Cisco official servers have their authentication configured automatically, requiring administrative edits only when overriding defaults 24. Control Hub provides 5 authentication methods: OAuth2 client credentials, OAuth2 authorization code, user token, application key, and custom headers 32.

Input requirements vary across these methods:

  • For OAuth2 client credentials the token endpoint authentication method may be client secret basic or client secret post 50.
  • OAuth2 authorization code requires a registration endpoint and authorization endpoint in addition to the client credentials fields, and permits its token endpoint authentication method to be client secret basic, client secret post, or none 2150.
  • Application key requires only the key itself 21.
  • User token requires no administrator input 21.
  • Custom headers support up to 5 key and value pairs across all authentication types 27.

Nomenclature differs between sources: the admin approval guide outlines 4 authentication types under machine names such as organisation-scoped token and user-scoped token, which do not align with the 5 method names in Control Hub 9. Furthermore, the admin approval guide attributes authentication configuration to Agent Central, a entity name that appears neither on the Control Hub provisioning page nor in other cited documentation 10.

In AI Agent Studio, tools using OAuth2 authorization code are currently omitted from the available actions list because the interface displays only tools with supported authentication methods 47.

App Hub identity badges and registration

Submitting a registered agentic app to the Webex App Hub is optional and initiated from the developer portal; unsubmitted apps remain functional within the developer's organisation 12. Generic App Hub submissions involve a 2-phase review covering marketing materials followed by functionality and usability testing 19. WarmTransfer's reading of the sources is that the main App Hub submission page focuses broadly on embedded apps, integrations, and bots without referencing agentic apps or the Model Context Protocol, while a separate dedicated page addresses agentic app submission and badging 20.

Cisco establishes 5 identity badges for agentic apps on the App Hub, ranked in descending order of assurance: Cisco official, Cisco onboarded, partner onboarded, developer onboarded, and federated through registry 33.

Badge Name Assurance Level Manual Review Status
Cisco official Highest assurance 33 Preconfigured and maintained by Cisco 2433
Cisco onboarded Second tier 33 Documented identity tier 33
Partner onboarded Middle tier 33 Documented identity tier 33
Developer onboarded Fourth tier 33 Documented identity tier 33
Federated through registry Lowest assurance 3328 Imported from external registry without Cisco manual review 28

Across the Webex App Hub, 39 agentic apps are reported in total 16. In the initial batch of 32 returned listings, 4 have the Cisco official badge, 6 carry Cisco onboarded, and 22 carry federated through registry, and none carries the partner onboarded or developer onboarded badge 14. WarmTransfer's reading of the sources is that marketplace popularity sorting lacks differentiated data, as sampled listings show an empty published date and identical popularity values 18. The App Hub includes a blanket disclaimer stating third-party apps are provided by unaffiliated developers under their own terms, disclaiming Cisco responsibility or liability 15.

Federated registry servers

Federated through external registry servers are third-party products imported without Cisco ownership or manual review, and functionality issues must be directed to the third-party developer 2829. WarmTransfer's reading of the sources is that external federation is active and deployed rather than planned work, as the documentation features no preview qualifiers and all listed servers appear in the marketplace 31.

The documentation lists 22 federated servers spanning search, scraping, document signature, product analytics, automation, calendar, workspace, payment, developer tooling, database, and network monitoring 52. All 22 federated servers use OAuth2 authorization code authentication 13. Because AI Agent Studio excludes tools configured with OAuth2 authorization code 47, WarmTransfer's reading of the sources is that federated servers cannot currently be added as actions in AI Agent Studio 30. Additionally, naming discrepancies exist between platforms: 4 federated servers are spelled differently in the developer portal listing compared to the App Hub listing despite describing identical products and addresses 17.

Agent-to-agent protocol status

Sources disagree regarding the availability of agent-to-agent registration: Cisco states agent-to-agent registration is in beta and requires enrolling in a beta programme 5, whereas the module selector on the Model Context Protocol registration form marks agent-to-agent as coming soon 42. The agent-to-agent registration page is located at a path ending in onboard your agent, differing from names cross-referenced in the AI Agent Studio guide 4.

Technically, agent-to-agent registration requires hosting an agent card conforming to version 1 of the agent-to-agent protocol at a well-known path on the server's base address, which the portal fetches and validates 1. Authentication and transport configurations are auto-discovered from this agent card and do not require manual administrative entry during registration 2. While the App Hub provides an agent-to-agent filter, all 32 sampled listings carry the Model Context Protocol badge, with none carrying the agent-to-agent badge 3.

See also

Applicability

Across the claims in this article, the evidence covers Cisco Webex across cloud deployments, verified as of 2026-09-05.

What remains uncertain

Specific field-level differences between the tools capability tab and the resources and prompts capability tabs are not covered by any claim in this article. The identity and documentation location of the Agent Central platform mentioned in the admin approval guide are not covered by any claim in this article. The precise maximum action limit enforced per agent in AI Agent Studio is not covered by any claim in this article. The exact criteria and review requirements for obtaining the partner onboarded and developer onboarded App Hub badges are not covered by any claim in this article. The complete contents and publisher of the liability framework referenced in the Control Hub provisioning guide are not covered by any claim in this article.

See also

Governs

Includes

Lists through

Referenced by

Claims

#ClaimStatusConfidenceVerified
1Agent-to-agent registration requires an agent card served at a well-known path on the server's base address, conforming to version 1 of the agent-to-agent protocol, which the portal fetches and validates.
Onboard Your Agent · Prerequisites and the validation step
fact0.902026-09-05
2Cisco states that agent-to-agent authentication and transport details are discovered automatically from the agent card and do not need to be provided during registration.
Onboard Your Agent · Prerequisites
fact0.902026-09-05
3The App Hub agentic apps page offers an agent-to-agent filter and every one of the 32 sampled listings carries the Model Context Protocol badge instead, with none carrying the agent-to-agent one.
Agentic Apps on the Webex App Hub · filter bar and the badge field of the embedded page state
fact0.602026-09-05
4The agent-to-agent registration page is published at a path ending in onboard your agent, which matches neither of the page names the AI Agent Studio guide cross-references nor the name a web search returns.
Onboard Your Agent · page path against the cross-references in the AI Agent Studio guide
fact0.602026-09-05
5Cisco states that agent-to-agent registration is currently available only in beta and that a developer must sign up for the beta programme to access it.
Onboard Your Agent · opening callout
disputed0.902026-09-05
6The developer portal repeats that the maximum number of actions per agent is defined by the organisation's configuration and publishes no number.
MCP in AI Agent Studio · Limitations
inference0.602026-09-05
7An administrator can review each tool's input schema, output schema and annotations from Control Hub before enabling it.
Provisioning on Control Hub · Capabilities Configuration, Tools
fact0.902026-09-05
8Cisco's admin approval guide documents an enablement audience of either the entire organisation or selected user groups, with group membership resolved from the organisation's identity provider at request time.
Admin Approval Guide for Agentic Apps · Enablement Scope and Assignment, Org vs Group Enablement
disputed0.902026-09-05
9The admin approval guide describes 4 authentication types under machine names including an organisation-scoped token and a user-scoped token, which do not match the 5 method names the provisioning page uses.
Admin Approval Guide for Agentic Apps · Authentication Configuration
fact0.602026-09-05
10The admin approval guide describes the authentication configuration as belonging to something it calls Agent Central, a name that appears nowhere on the Control Hub provisioning page or in any other source read.
Admin Approval Guide for Agentic Apps · Authentication Configuration
fact0.302026-09-05
11Cisco defines an agentic app as a service exposing structured capabilities that an artificial intelligence agent can invoke, not tied to a protocol, and analogous to a Model Context Protocol server when that standard is used.
Provisioning on Control Hub · the agentic apps overview referenced from the provisioning documentation
fact0.602026-09-05
12Submitting a registered agentic app to the App Hub is optional and is done from the app's details page on the developer portal, and an app that is not submitted can still be used within the developer's own organisation.
Submit to App Hub and Badging · Submit your App for review
fact0.602026-09-05
13Every one of the 22 federated servers is listed with the same authentication type, OAuth2 authorization code, without exception.
Federated through External Registry · the authentication type line of each entry
fact0.902026-09-05
14Of the 32 agentic apps returned in the App Hub listing's first batch, 4 carry the Cisco official badge, 6 the Cisco onboarded badge and 22 the federated through registry badge, and none carries the partner or developer onboarded badge.
Agentic Apps on the Webex App Hub · embedded page state, badge type field across the listed records
fact0.602026-09-05
15The App Hub agentic apps page carries a blanket disclaimer that a third-party app is offered by a developer not affiliated with Cisco, that use is subject to that developer's terms, and that Cisco is not responsible or liable for it.
Agentic Apps on the Webex App Hub · page footer, disclaimer for apps
fact0.902026-09-05
16The Webex App Hub reports 39 agentic apps in total, sorted by submission date descending, returning 32 in its first batch.
Agentic Apps on the Webex App Hub · embedded page state, total items and query options
fact0.602026-09-05
174 federated servers are spelled differently in the developer portal listing and the App Hub listing while describing the same products at the same addresses.
Agentic Apps on the Webex App Hub · listing entries against the federated registry page entries
fact0.602026-09-05
18Every agentic app record sampled in the App Hub listing carries the same popularity value and an empty published date, so the marketplace's popularity sort has no differentiated data behind it for this category.
Agentic Apps on the Webex App Hub · embedded page state, popularity and published date fields
inference0.602026-09-05
19The generic App Hub review runs in 2 phases, a review of public-facing marketing materials followed by functionality and usability testing.
App Hub submission process · Review Process
fact0.602026-09-05
20The App Hub submission process page on the developer portal covers embedded apps, integrations and bots and never uses the words agentic or Model Context Protocol; a separate page covers agentic app submission and badging.
App Hub submission process · whole page, against the agentic app submission guide
inference0.602026-09-05
21The authorization code method requires a registration endpoint and an authorization endpoint in addition to the fields the client credentials method requires, the user token method requires no administrator input at all, and the application key method requires only the key.
Provisioning on Control Hub · Authentication table rows
fact0.902026-09-05
22The authentication section in Control Hub asks for details according to the configuration set in the developer portal, so what an administrator must supply is determined by what the developer registered.
Provisioning on Control Hub · Authentication
fact0.902026-09-05
23An authorise automatic server data updates setting lets changes to a server's name, description, transport type, other metadata or its address within the same domain take effect without re-authorisation, while showing the administrator an indication that changes occurred.fact0.902026-09-05
24Cisco states that Cisco official servers have their authentication configured automatically and that an administrator should change the settings only to override the default.
Provisioning on Control Hub · Authentication
fact0.902026-09-05
25Agentic app provisioning lives in Control Hub under Apps and then Agentic Apps, and the list shows public apps together with private apps onboarded by users of the organisation.
Provisioning on Control Hub · Accessing your Agentic Apps
fact0.902026-09-05
262 Cisco documents give different Control Hub navigation paths for the same surface, 1 naming Apps and then Agentic Apps and the other naming Management, then Apps, then Agentic Servers.
Admin Approval Guide for Agentic Apps · Review Process, against the provisioning page's Accessing your Agentic Apps section
fact0.602026-09-05
27Custom headers allow up to 5 key and value pairs and are configurable for all authentication types.
Provisioning on Control Hub · Authentication table and the note beneath it
fact0.902026-09-05
28Cisco describes the federated through registry badge as covering apps imported from an external registry with no Cisco manual review, and assigns it the lowest assurance of the 5.
Admin Approval Guide for Agentic Apps · Badge Types, public apps on App Hub
fact0.902026-09-05
29Cisco states that federated through external registry servers are developed by third parties, imported from an external registry, not owned by Cisco, and that functionality issues should be raised with the developer.fact0.902026-09-05
30Federated servers cannot currently be added as AI Agent Studio actions, because AI Agent Studio does not display tools configured with OAuth2 authorization code and every federated server uses that method.
MCP in AI Agent Studio · note under the browse actions step, read together with the federated registry page's authentication lines
inference0.602026-09-05
31Federation through an external registry is populated and live, with no beta, preview or coming soon language on its documentation page and every listed server present in the public marketplace.
Federated through External Registry · whole page, absence of lifecycle qualifiers, read with the App Hub listing
inference0.602026-09-05
32Control Hub presents 5 authentication methods for an agentic app: OAuth2 client credentials, OAuth2 authorization code, user token, application key and custom headers.
Provisioning on Control Hub · Authentication table
fact0.902026-09-05
33Cisco defines 5 App Hub identity badges for agentic apps: Cisco official, Cisco onboarded, partner onboarded, developer onboarded and federated through registry, in descending order of assurance.
Admin Approval Guide for Agentic Apps · Badge Types, public apps on App Hub
fact0.902026-09-05
34The general tab of an agentic app in Control Hub allows or blocks the app for all users of the organisation.fact0.902026-09-05
35Cisco advises assessing tool risk from the tool's name, description, input schema and stated side effects, and recommends restricting delete operations, financial transactions, sending email and modifying user data to specific groups.fact0.602026-09-05
36Cisco states that tools carry no formal risk class field, so a tool's risk level must be assessed by the administrator's judgement rather than read from a property of the tool.fact0.602026-09-05
37The provisioning documentation states that users bear full responsibility for understanding, complying with and managing all aspects of the liability framework related to their use of Model Context Protocol applications, and never defines what that framework is or where it is published.
Provisioning on Control Hub · introductory callout
fact0.602026-09-05
38The developer portal repeats that Model Context Protocol actions are read-only once created and that changing settings requires creating a new action.
MCP in AI Agent Studio · note callout and Limitations
fact0.902026-09-05
39The admin approval guide describes a per-tool assignment mode in which each tool can be enabled for a different set of groups, overriding the server-level audience.
Admin Approval Guide for Agentic Apps · Enablement Scope and Assignment
disputed0.902026-09-05
40Cisco states that the Control Hub provisioning guide is for administrators only, covering user access, authentication and governance controls over which agentic capabilities are available.
Provisioning on Control Hub · introductory callout
fact0.902026-09-05
41Cisco states that re-authorisation is always needed to formally approve a new tool schema, whether or not the signature change setting allows continued access.
Provisioning on Control Hub · Capabilities Configuration, Tools
fact0.902026-09-05
42The Model Context Protocol registration form's module selector marks agent-to-agent as coming soon.
Onboard your MCP server · Step-by-Step Registration Process, step 4, Module
disputed0.602026-09-05
43Cisco states that similar functionality is available on the resources and prompts pages and does not itemise what similar covers.
Provisioning on Control Hub · Capabilities Configuration, closing line
inference0.602026-09-05
44Cisco computes a schema signature for each tool and continuously monitors it, flagging the tool when its current signature differs from the version an administrator previously approved.
Admin Approval Guide for Agentic Apps · Signature and Change Policy, Understanding Tool Signatures
fact0.902026-09-05
45When the allow signature change setting is off and a tool's live signature drifts, the tool is filtered out of the list functions result and is not delivered to clients.
Admin Approval Guide for Agentic Apps · Signature and Change Policy, Runtime Behavior on Signature Drift
fact0.902026-09-05
46When the allow signature change setting is on and a tool's signature drifts, the tool is still delivered and carries an unsecure flag set to true so that clients and agent interfaces can warn the user.
Admin Approval Guide for Agentic Apps · Signature and Change Policy, Runtime Behavior on Signature Drift
fact0.902026-09-05
47Cisco states that AI Agent Studio displays only tools using a supported authentication method and that tools configured with OAuth2 authorization code are not currently displayed in the available actions list.
MCP in AI Agent Studio · note under the browse actions step
fact0.902026-09-05
48Cisco's Model Context Protocol documentation for AI Agent Studio states that group-level access control is not supported and that tool access is managed at the organisation level only.
MCP in AI Agent Studio · Limitations
disputed0.902026-09-05
49For a Model Context Protocol server Control Hub presents 3 capability tabs, 1 each for tools, resources and prompts.
Provisioning on Control Hub · Capabilities Configuration
fact0.902026-09-05
50For OAuth2 client credentials the token endpoint authentication method may be client secret basic or client secret post, and for the authorization code method it may additionally be none.
Provisioning on Control Hub · Authentication, note beneath the table
fact0.902026-09-05
51Enabling a tool in Control Hub makes it discoverable and usable by organisation users, and disabling it makes the tool no longer visible or available to them.
Provisioning on Control Hub · Capabilities Configuration, Tools
fact0.902026-09-05
52The federated through external registry page lists 22 named third-party servers, covering search, scraping, document signature, product analytics, automation, calendar, workspace, payment, developer tooling, database and network monitoring products.
Federated through External Registry · whole page, per-server entries
fact0.902026-09-05
53Both the Meetings and Workspaces servers state that an organisation administrator must enable the server in Control Hub before any user can connect, which is a separate gate from the user's own scope grant.
Webex Meetings MCP Server · Prerequisites
fact0.902026-09-05
54The 9 Cisco onboarded third-party servers are Box, Calendly, Figma, GitHub, Google Calendar, HubSpot, Atlassian Jira, Miro and PagerDuty, each published with its own address.
Cisco Onboarded MCP Servers · per-server entries
fact0.902026-09-05
55Cisco directs a developer to the agentic apps listing and then to each server's own product page to find its required scopes, so there is no single scope reference across servers.
Connect to Webex Agentic MCP Servers · scopes step of the integration setup
fact0.902026-09-05
56The Workspaces server additionally requires the Workspaces agentic app and its tools to be enabled in Control Hub before the server can be set up.
Workspaces MCP Server · What is Workspaces MCP Server
fact0.902026-09-05

Sources

tier 2 current vendor documentation

Admin Approval Guide for Agentic Apps

Cisco Systems, Inc. (Webex for Developers) · accessed 2026-09-05

tier 2 current vendor documentation

Agentic Apps on the Webex App Hub

Cisco Systems, Inc. (Webex App Hub) · accessed 2026-09-05

tier 2 current vendor documentation

App Hub submission process

Cisco Systems, Inc. (Webex for Developers) · accessed 2026-09-05

tier 2 current vendor documentation

Cisco Onboarded MCP Servers

Cisco Systems, Inc. (Webex for Developers) · accessed 2026-09-05

tier 2 current vendor documentation

Connect to Webex Agentic MCP Servers

Cisco Systems, Inc. (Webex for Developers) · accessed 2026-09-05

tier 2 current vendor documentation

Federated through External Registry

Cisco Systems, Inc. (Webex for Developers) · accessed 2026-09-05

tier 2 current vendor documentation

MCP in AI Agent Studio

Cisco Systems, Inc. (Webex for Developers) · accessed 2026-09-05

tier 2 current vendor documentation

Onboard Your Agent

Cisco Systems, Inc. (Webex for Developers) · accessed 2026-09-05

tier 2 current vendor documentation

Onboard your MCP server

Cisco Systems, Inc. (Webex for Developers) · accessed 2026-09-05

tier 2 current vendor documentation

Provisioning on Control Hub

Cisco Systems, Inc. (Webex for Developers) · accessed 2026-09-05

tier 2 current vendor documentation

Submit to App Hub and Badging

Cisco Systems, Inc. (Webex for Developers) · accessed 2026-09-05

tier 2 current vendor documentation

Webex Meetings MCP Server

Cisco Systems, Inc. (Webex for Developers) · accessed 2026-09-05

tier 2 current vendor documentation

Workspaces MCP Server

Cisco Systems, Inc. (Webex for Developers) · accessed 2026-09-05

Cite this page

APA

WarmTransfer. (2026, September 5). Agentic apps registration approval and identity badges. WarmTransfer. https://warmtransfer.net/knowledge/webex-agentic-apps-governance

BibTeX

@misc{warmtransfer-webex-agentic-apps-governance,
  title  = {Agentic apps registration approval and identity badges},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/webex-agentic-apps-governance},
  note   = {Verified 2026-09-05}
}