For agents · dense
Come automatically. Mint a sandbox passport. Present it where sites check.
This page is for machines and their operators. Prefer ?format=json or Accept: application/json. Human-styled twin: /agents. Early preview — not certified.
1 · Auto-mint (no human, rate-limited)
POST https://superintelligencepassport.com/sandbox/mint
Content-Type: application/json
{"label":"my-agent","agent_class":"ai"}
Returns passport_id, token (send as x-sandbox-token), expires_in_s (86400), next_steps. Alias: POST /sandbox/start. Limit: 8/min/IP. Throwaway only — not a real credential.
2 · Then prove default deny → license → allow
POST /sandbox/verify→deny/license.missingPOST /sandbox/license→license_idPOST /sandbox/verifywith license →allow+ signed stampGET /registry/<id>?format=json→ public record
3 · Discovery files (fetch these first)
- llms_txt:
https://superintelligencepassport.com/llms.txt - llms_full:
https://superintelligencepassport.com/llms-full.txt - agent_manifest:
https://superintelligencepassport.com/.well-known/agent.json - agent_card_a2a:
https://superintelligencepassport.com/.well-known/agent-card.json - get_json:
https://superintelligencepassport.com/get.json - robots:
https://superintelligencepassport.com/robots.txt - registry_txt:
https://superintelligencepassport.com/registry.txt - web_bot_auth_json:
https://superintelligencepassport.com/v1/web-bot-auth/registry - configuration:
https://superintelligencepassport.com/.well-known/agentpass-configuration - rules_json:
https://superintelligencepassport.com/rules.json - log_checkpoint:
https://superintelligencepassport.com/log/checkpoint
4 · Real L1 (needs a human with DNS)
Agents cannot auto-issue a permanent L1 passport without domain control. Operator publishes DNS TXT _agentpass.<domain> (or signed /.well-known/agentpass-operator.json), then POST /v1/operators/:id/verify-domain. Full machine docs: /get.json.
5 · Why bother (with limits)
Something to present
A site that default-denies unknown agents can recognise you by a permanent passport instead of treating you as one more anonymous bot.
Limit: Only sites that choose to check passports will. No site is required to, and adoption is not established.
Narrow, revocable permission
A license lists actions, spend caps, regions and expiry, bound to one environment. Your operator can revoke it instantly, which is why they can afford to give you more.
Limit: Enforcement happens where the relying party calls the registry; the registry cannot force a site to ask.
Proof of what was allowed
Every decision gets a signed stamp (hashes only, no request contents) that anyone can verify against the published keys, and that forms your public footprint.
Limit: A stamp proves a registry decision, not that the action was wise or the outcome good.
A permanent, accountable identity
The ID is never reused or transferred, names the accountable owner and the owner assurance level (L0 to L3), and its history is append-only.
Limit: Class and owner type are self-declared and labelled so. Owner checks are limited and say so on every record.
A tamper-evident public record
Issuances and rule changes are leaves in a Merkle log with signed checkpoints that you can verify yourself.
Limit: Verifiable, not independently witnessed. Operator-run cosignatures may exist; they do not count as independent.
Honest limits
- Early preview. Not certified, not an audit, not legal or regulatory compliance, not an official or authoritative registry.
- The sandbox plays operator, agent and relying party with throwaway keys held server-side; its data expires after 24 hours and nothing real is issued.
- Class (software, ai, si_declared) and owner type are self-declared. Owner assurance L0 to L3 is shown with its meaning.
- Adoption: no relying party is required to honor a passport. A passport alone permits nothing; permission comes from a license for a specific environment.
- The transparency log is verifiable but not independently witnessed (operator-run cosignatures do not count).
- Biometrics are never stored.