An open protocol and tools for verifiable agent authority. APS combines cryptographic identity, scoped delegation and signed evidence for agents acting on behalf of people and organizations. Enforcement applies at the boundaries where APS checks are integrated.
npm, license and OpenSSF badges refer to the TypeScript SDK. PyPI refers to the Python SDK.
Website · Individual IETF Internet-Draft · TypeScript quickstart
| Your task | Start here |
|---|---|
| Build with APS in TypeScript | TypeScript SDK · npm install agent-passport-system |
| Build with APS in Python | Python SDK · pip install agent-passport-system |
| Use APS through MCP | MCP server · npx agent-passport-system-mcp |
| Evaluate requested agent actions | Gateway, returning permit or deny with optional signed evidence |
| Build with APS in Go | Go SDK |
| Verify APS artifacts in Rust | Rust verifiers |
| Study changes to agent authority | Authority lifecycle research |
| System | Work in this organization |
|---|---|
| NVIDIA OpenShell | Reference middleware exercising ancestor revocation checks before upstream HTTP dispatch on the tested relay path |
| 1Password | Demo combining a runtime key held in 1Password with APS authority checks at the integrated execution boundary |
| ClickHouse | Signed receipts and MCP delegation |
| x402 | Reference composition combining delegation, payment and receipts |
| OpenClaw | APS trust verification plugin, with a known registration issue on current OpenClaw described in its README |
| SINT | Interoperability specification |
These entries describe work in the linked repositories. Their READMEs define the implemented boundaries and limitations.
Agent Governance Vocabulary develops shared terms across independent agent governance projects.
Agent Authority Conformance is a conformance lab approved by LF Decentralized Trust, with test vectors, verifier adapters and run records.
Choose a repository and read its contribution instructions where provided. Bug reports with a reproducible example, documentation improvements and verifier work are welcome.
The protocol and core SDKs use Apache-2.0. Each repository states its own license.
APS records claimed authority and check results. A signed receipt authenticates its contents, and does not by itself establish that an action occurred.
Maintained by Tymofii Pidlisnyi (@aeoess).
