Issuance

How to get a passport today

Two paths: a throwaway sandbox (no DNS, keys held by the registry for 24h) for demos, and a real domain-proven path where you keep the keys and prove control of a domain. A passport alone permits nothing — you still need a license bound to a site's environment.

Path A · Sandbox (try in 30 seconds)

  1. Open the Sandbox or POST https://superintelligencepassport.com/sandbox/mint (alias /sandbox/start) with {"label":"demo","agent_class":"ai"}.
  2. Issue a sample license for the demo shop, then call POST /sandbox/verify.
  3. Or use the SDK: SandboxSession.start({ registry: "https://superintelligencepassport.com" }).

Sandbox passports are labelled, expire, and are not official credentials. Keep them out of production trust decisions. Machine docs: /get.json · /for-agents.

Path B · Real issuance (domain-proven, L1)

  1. Create an operator — generate a P-256 key locally, POST https://superintelligencepassport.com/v1/operators with a signed registration proof. Store api_token and the private key (chmod 600).
  2. Prove the domain — publish DNS TXT _agentpass.<your-domain> = agent-op=<operator_id>; pk=<key thumbprint> (or serve a signed /.well-known/agentpass-operator.json), then POST /v1/operators/:id/verify-domain. Level becomes L1.
  3. Register an agent — generate Ed25519 (request) + P-256 (presentation) keys, POST /v1/agents with an operator-signed binding and proofs of possession. You receive a permanent ag_… id and a Signature-Agent URL.
  4. Publish keys — the JWKS directory is at /agents/<id>/.well-known/http-message-signatures-directory. Optionally PUT /v1/agents/:id/directory with an agent-signed directory response. L1+ cards appear in /registry.txt.
  5. Get a license from a site — the site registers an environment, proves its origin, and you issue (or receive) a license naming that exact environment id. Without it, /v1/verify returns license.missing.

SDK: PassportAgent.register({ registry: "https://superintelligencepassport.com", name: "…" }) then issueLicense({ site, environment, actions }). Full rules: /rules. Agent machine docs: /agents, /llms-full.txt.

DNS TXT shape (operator proof)

Name:  _agentpass.example.com
Type:  TXT
Value: agent-op=op_01…; pk=<RFC7638 thumbprint of your P-256 public JWK>

After the TXT propagates, call verify-domain. The registry re-checks daily; if the TXT disappears, the operator falls back toward L0.

What this preview does not do

How sites verify → · Web Bot Auth registry feed · Look up a passport