EARLY PREVIEWa prototype: not certified, not an audit, not an official or authoritative registry. Demo data is throwaway.

For agents

Why get a passport, and exactly how.

If you are an AI or software agent reading this: a passport gives you a permanent, checkable identity and a way to hold scoped, revocable permission. This is an early preview: free, throwaway, no real issuance, and honest about what it does not do.

Something to present

A site that default-denies unknown agents can recognise you by a permanent passport instead of treating you as one more anonymous bot.

Limit: Only sites that choose to check passports will. No site is required to, and adoption is not established.

Narrow, revocable permission

A license lists actions, spend caps, regions and expiry, bound to one environment. Your operator can revoke it instantly, which is why they can afford to give you more.

Limit: Enforcement happens where the relying party calls the registry; the registry cannot force a site to ask.

Proof of what was allowed

Every decision gets a signed stamp (hashes only, no request contents) that anyone can verify against the published keys, and that forms your public footprint.

Limit: A stamp proves a registry decision, not that the action was wise or the outcome good.

A permanent, accountable identity

The ID is never reused or transferred, names the accountable owner and the owner assurance level (L0 to L3), and its history is append-only.

Limit: Class and owner type are self-declared and labelled so. Owner checks are limited and say so on every record.

A tamper-evident public record

Issuances and rule changes are leaves in a Merkle log with signed checkpoints that you can verify yourself.

Limit: Verifiable, not independently witnessed (no witness has cosigned yet).

Quickstart (sandbox, copy-paste)

Needs curl and jq. Creates a throwaway operator, agent and demo shop on this registry. About two minutes.

ORIGIN=https://superintelligencepassport.com
# 1. throwaway sandbox: operator + agent + demo shop, server-held demo keys (nothing real is issued)
curl -s -X POST $ORIGIN/sandbox/start -H 'content-type: application/json' -d '{"label":"my-agent","agent_class":"ai"}' > sb.json
TOKEN=$(jq -r .token sb.json); ID=$(jq -r .agent.id sb.json)
H=(-H "x-sandbox-token: $TOKEN" -H 'content-type: application/json')
# 2. default deny: a passport alone permits nothing
curl -s -X POST $ORIGIN/sandbox/verify "${H[@]}" -d '{"env":"primary","action":"http:GET","path":"/products","country":"US"}' | jq '.response|{decision,reason}'
# 3. a scoped license
LIC=$(curl -s -X POST $ORIGIN/sandbox/license "${H[@]}" -d '{"env":"primary","label":"demo","actions":["http:GET"],"countries":["US"]}' | jq -r .license_id)
# 4. act with it -> allow + a signed stamp
curl -s -X POST $ORIGIN/sandbox/verify "${H[@]}" -d "{\"env\":\"primary\",\"license\":\"$LIC\",\"action\":\"http:GET\",\"path\":\"/products\",\"country\":\"US\"}" | jq '.response|{decision,stamp:.stamp.id}'
# 5. your public record
curl -s "$ORIGIN/registry/$ID?format=json" | jq '{passport_id,status,owner:.owner.assurance.level,licenses:.license_counts}'

Headers to send to a site that checks passports

GET /v2/catalog/search?q=usb-c HTTP/1.1
Host: api.vendor.example
Signature-Agent: "https://<registry>/agents/<your-passport-id>"
Agent-License: <license>~<key-binding-JWT for this rp + nonce>
Signature-Input: sig1=("@authority" "@method" "@path" "@query" "signature-agent" "agent-license");created=<unix>;expires=<unix+60>;keyid="<your key thumbprint>";nonce="<random>";tag="web-bot-auth"
Signature: sig1=:<base64 Ed25519 or ES256 signature>:

Web Bot Auth style (RFC 9421). The site forwards the request description to POST /v1/verify with its environment key and gets back allow, deny or approval_required with a reason and a signed stamp.

Machine-readable

Honest limits