1. Passport
Ed25519 request key + P-256 presentation key, bound to an accountable operator by a signed statement. Requests carry RFC 9421 / Web Bot Auth signatures. Tells you who. Permits nothing.
2. License
Operator-signed, short-lived, bound to the agent's key and to one environment id. Actions, spend caps, time, geography, human-approval threshold. Delegable only by narrowing.
3. Environment profile
The relying party's own rules, public and versioned. Empty by default = deny everything. Spend is reserved, then committed or rolled back by the RP. Every decision lands in a hash-chained audit log.
Try it live
The sandbox plays operator, agent and relying party against this registry's real API. It holds throwaway demo keys server-side so your browser can sign for you; real agents keep their own keys. Nothing leaves this server and no money moves.
1Register an agent
Creates a demo operator (level L0, unverified), an agent with two keys and a passport, and two environments: Demo Shop (can buy, up to $100 per purchase, US/CA only, human approval above $50) and Other Store (read-only).
2Environment rule profile (Demo Shop)
Edit and save: the next check uses it immediately. Remove allowed_actions entries to see default deny.
3Issue a license
4Run a live check as the relying party
5Kill switch and key hygiene
Takes effect on the very next check. The panic button uses a separate kill token and cannot be undone by the agent.
6Audit log
Use the real API
Same endpoints the sandbox uses. A relying party registers its environment once and gets a key:
curl -sX POST $ORIGIN/v1/environments -H 'content-type: application/json' \
-d '{"name":"My API","rp_origin":"https://api.example.com",
"profile":{"allowed_actions":["http:GET"],"geo":{"allow_countries":["US"]}}}'
# => { "id":"env_...", "environment_key":"ape_...", "prove_ownership":{ DNS TXT / .well-known challenge } } (key shown once)
# Until the origin is proven (POST /v1/environments/:id/verify-ownership) the environment cannot verify or receive licenses.
curl -sX POST $ORIGIN/v1/verify -H "authorization: Bearer $ENV_KEY" -d '{"rp":"https://api.example.com","request":{...},"intent":{...}}'
# => { "decision":"allow|deny|approval_required", "reason":"...", "reservation":{ "commit":"...","rollback":"..." } }
registry configuration + keys · agent revocation list · spec and source: see HANDOFF.md in the repository.