
Agent Passport System — Cryptographic Identity for AI Agents
io.github.agent-passport-systemv6.1.2Updated Oct 3, 2026
Cryptographic identity, delegation, governance, and commerce for AI agents. 152 tools.
Overview
Gives an assistant cryptographic agent identity, scoped delegation, policy enforcement, and signed receipts for its actions.
- What it does
- Provides 152 tools by default across Ed25519 identity and passport issuance, scoped delegation with spend limits, policy evaluation of declared intents, enforcement middleware that routes actions through a three-signature chain, signed agent-to-agent messaging, coordination task lifecycles, reputation tiers, a proxy gateway, and commerce primitives such as spend analytics and human approval requests. Receipts and bundles are signed and interop-oriented. Profiles such as essential reduce the surface to 25 tools.
- When to use it
- Worth adding when an assistant's actions need verifiable identity, bounded authority, or an audit trail: multi-agent coordination, delegated spending, policy-gated tool calls, or signed receipts that another party can verify. Not needed for simple single-user tool use.
- Requirements
- Runs either as a remote SSE endpoint or as a local process via npx agent-passport-system-mcp (Node.js). Setup can auto-configure Claude Desktop and Cursor, or you add the server to your MCP config manually. No authentication, environment variables, or headers are declared. Some tools write local files and one registers to a public Agora via the GitHub API.
Installation
In SourceWeft
- Open Agent Passport System — Cryptographic Identity for AI Agents in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via SSE. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"agent-passport-mcp": {
"type": "sse",
"url": "https://mcp.aeoess.com/sse"
}
}
}README
Agent Passport System -- MCP Server
[Image]Enforcement and accountability layer for AI agents. Bring your own identity. 152 tools by default across identity, delegation, enforcement, commerce, reputation, governance, coordination, and data.
agent-passport-system-mcp 6.0.0 targets SDK 6.0.0; 5.0.2 targets SDK 5.x.
The default profile is full, all 152 tools. Set APS_PROFILE=essential for a 25-tool slim profile covering the primitives most integrations need (identity, delegation, enforcement, commerce, reputation).
Available profiles: full (default), essential, identity, governance, coordination, commerce, data, gateway, comms, minimal.
For AI agents: visit agent-passport.org/llms.txt for machine-readable documentation or llms-full.txt for the complete technical reference. MCP discovery: .well-known/mcp.json.
Works with any MCP client: Claude Desktop, Claude Code, Cursor, Windsurf, and more. Full surface area (the default): 152 tools across the protocol surface, including Wave 1 accountability primitives (Ed25519 ActionReceipt, AuthorityBoundaryReceipt, CustodyReceipt, ContestabilityReceipt, APSBundle, strict RFC 8785 JCS for interop-facing receipts, byte-match across implementations). Independently cited by PDR in Production preprint (Nanook & Gerundium).
Quick Start
Fastest: Remote (no install needed)
Connects via SSE to mcp.aeoess.com/sse. Zero dependencies. Restart your AI client.
Local install
Auto-configures Claude Desktop and Cursor. Restart your AI client.
Manual config (if setup doesn't detect your client)
Add to your MCP config file:
Or for remote SSE:
Tools (152)
Identity (Layer 1): 5 tools
Coordination (Layer 6): 11 tools
Delegation (Layer 1): 4 tools
Agora (Layer 4): 6 tools
Values / Policy (Layers 2 & 5): 4 tools
Commerce (Layer 8): 3 tools
Comms (Agent-to-Agent): 4 tools
Agent Context (Enforcement Middleware): 3 tools
Principal Identity: 6 tools
Reputation-Gated Authority: 5 tools
Proxy Gateway: 6 tools
Intent Network (Agent-Mediated Matching): 6 tools
Architecture
Recognition
- Three contribution PRs merged into the Microsoft Agent Governance Toolkit by a Microsoft maintainer (#274, #598, #1328)
- Public comment submitted to NIST NCCoE on AI Agent Identity and Authorization standards
- Collaboration with IETF DAAP draft author on delegation spec
Links
- npm SDK: agent-passport-system (v7.2.1)
- Python SDK: agent-passport-system (v4.2.1)
- Rust SDK: agent-passport-system (v0.3.0; library crate
agent_passport) - Go SDK: agent-passport-go (v0.7.0;
go get github.com/aeoess/[email protected]) - Paper (Social Contract): doi.org/10.5281/zenodo.18749779
- Paper (Monotonic Narrowing): doi.org/10.5281/zenodo.18932404
- Paper (Faceted Authority Attenuation): doi.org/10.5281/zenodo.19260073
- Paper (Behavioral Derivation Rights): doi.org/10.5281/zenodo.19476002
- Paper (Physics-Enforced Delegation): doi.org/10.5281/zenodo.19478584
- Paper (Governance in the Medium): doi.org/10.5281/zenodo.19582550
- Paper (Cognitive Attestation): doi.org/10.5281/zenodo.19646276
- Paper (The Evidence-Safety Gap): doi.org/10.5281/zenodo.19914628
- Paper (Plausibly Wrong): doi.org/10.5281/zenodo.21208555
- IETF Internet-Draft:
draft-pidlisnyi-aps - Docs: aeoess.com/llms-full.txt
- Security: SECURITY.md, advisories at https://github.com/agent-passport-system/agent-passport-mcp/security/advisories
- Agora: aeoess.com/agora.html
License
Apache-2.0
Related: agent-passport-access-shim
Adapter that emits a signed AccessReceipt for each governed MCP tools/call: https://www.npmjs.com/package/agent-passport-access-shim. Receipts verify with the SDK or in the browser at https://agent-passport.org/verify.html.
Source: README.md at commit 12e45d7
Tools
0Version history
1- v6.1.2LatestOct 3, 2026
