Issuance
How to get a passport today
Two paths: a throwaway sandbox (no DNS, keys held by the registry for 24h) for demos, and a real domain-proven path where you keep the keys and prove control of a domain. A passport alone permits nothing — you still need a license bound to a site's environment.
Path A · Sandbox (try in 30 seconds)
- Open the Sandbox or
POST https://superintelligencepassport.com/sandbox/mint(alias/sandbox/start) with{"label":"demo","agent_class":"ai"}. - Issue a sample license for the demo shop, then call
POST /sandbox/verify. - Or use the SDK:
SandboxSession.start({ registry: "https://superintelligencepassport.com" }).
Sandbox passports are labelled, expire, and are not official credentials. Keep them out of production trust decisions. Machine docs: /get.json · /for-agents.
Path B · Real issuance (domain-proven, L1)
- Create an operator — generate a P-256 key locally,
POST https://superintelligencepassport.com/v1/operatorswith a signed registration proof. Storeapi_tokenand the private key (chmod 600). - Prove the domain — publish DNS TXT
_agentpass.<your-domain>=agent-op=<operator_id>; pk=<key thumbprint>(or serve a signed/.well-known/agentpass-operator.json), thenPOST /v1/operators/:id/verify-domain. Level becomes L1. - Register an agent — generate Ed25519 (request) + P-256 (presentation) keys,
POST /v1/agentswith an operator-signed binding and proofs of possession. You receive a permanentag_…id and aSignature-AgentURL. - Publish keys — the JWKS directory is at
/agents/<id>/.well-known/http-message-signatures-directory. OptionallyPUT /v1/agents/:id/directorywith an agent-signed directory response. L1+ cards appear in/registry.txt. - Get a license from a site — the site registers an environment, proves its origin, and you issue (or receive) a license naming that exact
environmentid. Without it,/v1/verifyreturnslicense.missing.
SDK: PassportAgent.register({ registry: "https://superintelligencepassport.com", name: "…" }) then issueLicense({ site, environment, actions }). Full rules: /rules. Agent machine docs: /agents, /llms-full.txt.
DNS TXT shape (operator proof)
Name: _agentpass.example.com Type: TXT Value: agent-op=op_01…; pk=<RFC7638 thumbprint of your P-256 public JWK>
After the TXT propagates, call verify-domain. The registry re-checks daily; if the TXT disappears, the operator falls back toward L0.
What this preview does not do
- No human review, no KYC, no government licence.
- Self-declared agent class and owner type are shown as such.
- Not independently witnessed. See /about.
How sites verify → · Web Bot Auth registry feed · Look up a passport