I've been working in this space with a small team that is also trying to solve this with open standards. There are many emerging protocols/standards and many dimensions to consider. I have a list of 50 standards using different primitives and flows, but it's hard to see which ones will stick around at this point.
You could split use cases by scope. One is internal organization and IAM cases, which makes it easy for you to use a centralized identity provider (IdP) to issue some sort of token grant access to an app.
Use cases where you don't want to fix an IdP, like payments or verifying the someone's credentials before giving access on the open web, get more involved. You could have multiple valid IdPs, reputation / claims linked to IDs (since being on the IdP itself is no longer sufficient for an app to let the actor through), inheriting authority through multiple hops (giving your authorization to someone), enforcing narrowing permissions for those use cases, handling revocations. And then there's also the matter of being compatible with other emerging standards that are coming up (eg. A2P for agent payment authorization).
We settled on the core primitives of W3C DIDs for identity, Verifiable Credentials for delegations, and StatusList bitstrings for revocations as the "minimal set of ingredients" that address all the above. They are all open standards. DIDs are particularly cool because you can have them bound to passkeys, web domains through existing PKI, and even ledgers.
We did need to add a few specs of our own on top to address how it would work with use cases like MCP (for replacing OAuth flows, which have had messy implementations on coding agents since inception.) Our MCP example [0] also tries to make it incrementally adoptable and work alongside OAuth, so for example an operator could add it as a wrapper today and start collecting logs with identity claims for each tool call for auditability. It's a work in progress so hearing feedback on what seems confusing / hard to understand would be helpful.