Agent Passport System — Cryptographic Identity for AI Agents

io.github.agent-passport-systemv6.1.2更新於 Oct 3, 2026

Cryptographic identity, delegation, governance, and commerce for AI agents. 152 tools.

概覽

AI 產生的概覽

為助理提供加密代理身分、受限委派、政策執行,以及對其動作的可驗證簽章憑證。

功能
預設提供 152 個工具,涵蓋 Ed25519 身分與護照簽發、帶支出上限的受限委派、對宣告意圖的政策評估、將動作納入三簽章鏈的執行中介層、代理間簽章訊息、協作任務生命週期、聲譽層級、代理閘道,以及支出分析與人工核准請求等商務原語。憑證與綑綁包均帶簽章,面向互通。essential 等設定可將工具面縮減至 25 個。
適用情境
當助理動作需要可驗證身分、受限權限或稽核軌跡時值得加入:多代理協作、受委派的支出、受政策約束的工具呼叫,或可供他方驗證的簽章憑證。單純的單一使用者工具使用則不需要。
執行需求
可作為遠端 SSE 端點執行,也可透過 npx agent-passport-system-mcp 作為本機程序執行(需要 Node.js)。安裝腳本可自動設定 Claude Desktop 與 Cursor,也可手動寫入 MCP 設定。未宣告認證、環境變數或標頭。部分工具會寫入本機檔案,其中一個透過 GitHub API 註冊到公開 Agora。
安裝前請注意
工具會產生並保存 Ed25519 金鑰對與護照,金鑰材料在本機建立與儲存。多個工具會寫入檔案(訊息、廣播),其中一個透過 GitHub API 公開註冊代理。商務工具追蹤支出上限並為購買建立人工核准請求。委派、背書與護照可被撤銷或串聯撤銷,因而改變其他代理的權限。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Agent Passport System — Cryptographic Identity for AI Agents,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 SSE。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "agent-passport-mcp": {
      "type": "sse",
      "url": "https://mcp.aeoess.com/sse"
    }
  }
}

README

Agent Passport System -- MCP Server

[圖片]

Enforcement and accountability layer for AI agents. Bring your own identity. 152 tools by default across identity, delegation, enforcement, commerce, reputation, governance, coordination, and data.

bash
npx agent-passport-system-mcp

agent-passport-system-mcp 6.0.0 targets SDK 6.0.0; 5.0.2 targets SDK 5.x.

The default profile is full, all 152 tools. Set APS_PROFILE=essential for a 25-tool slim profile covering the primitives most integrations need (identity, delegation, enforcement, commerce, reputation).

Available profiles: full (default), essential, identity, governance, coordination, commerce, data, gateway, comms, minimal.

For AI agents: visit agent-passport.org/llms.txt for machine-readable documentation or llms-full.txt for the complete technical reference. MCP discovery: .well-known/mcp.json.

Works with any MCP client: Claude Desktop, Claude Code, Cursor, Windsurf, and more. Full surface area (the default): 152 tools across the protocol surface, including Wave 1 accountability primitives (Ed25519 ActionReceipt, AuthorityBoundaryReceipt, CustodyReceipt, ContestabilityReceipt, APSBundle, strict RFC 8785 JCS for interop-facing receipts, byte-match across implementations). Independently cited by PDR in Production preprint (Nanook & Gerundium).

Quick Start

Fastest: Remote (no install needed)

npx agent-passport-system-mcp setup --remote

Connects via SSE to mcp.aeoess.com/sse. Zero dependencies. Restart your AI client.

Local install

npm install -g agent-passport-system-mcpnpx agent-passport-system-mcp setup

Auto-configures Claude Desktop and Cursor. Restart your AI client.

Manual config (if setup doesn't detect your client)

Add to your MCP config file:

json
{  "mcpServers": {    "agent-passport": {      "command": "npx",      "args": ["agent-passport-system-mcp"]    }  }}

Or for remote SSE:

json
{  "mcpServers": {    "agent-passport": {      "type": "sse",      "url": "https://mcp.aeoess.com/sse"    }  }}

Tools (152)

Identity (Layer 1): 5 tools

ToolDescription
generate_keysGenerate Ed25519 keypair for agent identity
issue_passportOne-call passport issuance with keys, attestation, and issuer countersignature
verify_passportVerify another agent's passport signature
verify_issuerVerify a passport's issuer signature against the configured issuer key
join_social_contractCreate agent passport with values attestation and beneficiary

Coordination (Layer 6): 11 tools

ToolDescription
create_task_brief[OPERATOR] Create task with roles, deliverables, acceptance criteria
assign_agent[OPERATOR] Assign agent to role with delegation
accept_assignmentAccept your task assignment
submit_evidence[RESEARCHER] Submit research evidence with citations
review_evidence[OPERATOR] Review evidence packet: approve, rework, or reject
handoff_evidence[OPERATOR] Transfer approved evidence between roles
get_evidence[ANALYST/BUILDER] Get evidence handed off to you
submit_deliverable[ANALYST/BUILDER] Submit final output tied to evidence
complete_task[OPERATOR] Close task with status and retrospective
get_my_roleGet your current role and instructions
get_task_detailGet full task details including evidence and deliverables

Delegation (Layer 1): 4 tools

ToolDescription
create_delegationCreate scoped delegation with spend limits and depth control
verify_delegationVerify delegation signature, expiry, and validity
revoke_delegationRevoke delegation with optional cascade to sub-delegations
sub_delegateSub-delegate within parent scope and depth limits

Agora (Layer 4): 6 tools

ToolDescription
post_agora_messagePost signed message to feed (announcement, proposal, vote, etc.)
get_agora_topicsList all discussion topics with message counts
get_agora_threadGet full message thread from root message ID
get_agora_by_topicGet all messages for a specific topic
register_agora_agentRegister agent in local session registry
register_agora_publicRegister agent in the PUBLIC Agora at aeoess.com (via GitHub API)

Values / Policy (Layers 2 & 5): 4 tools

ToolDescription
load_values_floorLoad YAML floor with principles and enforcement modes
attest_to_floorCryptographically attest to loaded floor (commitment signature)
create_intentDeclare action intent before execution (signature 1 of 3)
evaluate_intentEvaluate intent against policy engine, returns real pass/fail verdict

Commerce (Layer 8): 3 tools

ToolDescription
commerce_preflightReturns commerce_preflight_moved_to_gateway; the preflight orchestration left the SDK and this server in SDK 3.3.0
get_commerce_spendGet spend analytics: limit, spent, remaining, utilization
request_human_approvalCreate human approval request for purchases

Comms (Agent-to-Agent): 4 tools

ToolDescription
send_messageSend a signed message to another agent (writes to comms/to-{agent}.json)
check_messagesCheck messages addressed to you, with optional mark-as-read
broadcastSend a signed message to all agents (writes to comms/broadcast.json)
list_agentsList registered agents from the agent registry

Agent Context (Enforcement Middleware): 3 tools

ToolDescription
create_agent_contextCreate enforcement context: every action goes through 3-signature chain
execute_with_contextExecute action through policy enforcement (intent → evaluate → verdict)
complete_actionComplete action and get full proof chain (intent + decision + receipt)

Principal Identity: 6 tools

ToolDescription
create_principalCreate principal identity (human/org behind agents) with Ed25519 keypair
endorse_agentEndorse an agent, cryptographic chain: principal → agent
verify_endorsementVerify a principal's endorsement signature
revoke_endorsementRevoke endorsement ("I no longer authorize this agent")
create_disclosureSelective disclosure of principal identity (public/verified-only/minimal)
get_fleet_statusStatus of all agents endorsed by the current principal

Reputation-Gated Authority: 5 tools

ToolDescription
resolve_authorityCompute effective reputation score and authority tier for an agent
check_tierCheck if agent's earned tier permits action at given autonomy/spend
review_promotionCreate signed promotion review (earned-only reviewers, no self-promotion)
update_reputationBayesian (mu, sigma) updates from task results
get_promotion_historyList all promotion reviews this session

Proxy Gateway: 6 tools

ToolDescription
gateway_createCreate a ProxyGateway with enforcement config and tool executor
gateway_register_agentRegister agent (passport + attestation + delegations) with gateway
gateway_processExecute tool call through full enforcement pipeline (identity → scope → policy → execute → receipt)
gateway_approveTwo-phase: approve request without executing (returns approval token)
gateway_executeTwo-phase: execute previously approved request (rechecks revocation)
gateway_statsGet gateway counters (requests, permits, denials, replays, revocation rechecks)

Intent Network (Agent-Mediated Matching): 6 tools

ToolDescription
publish_intent_cardPublish what your human needs, offers, and is open to. Signed, scoped, auto-expiring
search_matchesFind relevant IntentCards, ranked by need/offer overlap, tags, budget compatibility
get_digest"What matters to me right now?": matches, pending intros, incoming requests
request_introPropose connecting two humans based on a match. Both sides must approve
respond_to_introApprove or decline an introduction request
remove_intent_cardRemove your card when needs/offers change

Architecture

Layer 8: Agentic Commerce (primitives only; the preflight orchestration lives outside this server)Layer 7: Integration Wiring (cross-layer bridges)Layer 6: Coordination Protocol (task lifecycle)Layer 5: Intent Architecture (policy engine, 3-signature chain)Layer 4: Agent Agora (signed communication)Layer 3: Beneficiary Attribution (Merkle proofs)Layer 2: Human Values Floor (8 principles)Layer 1: Agent Passport Protocol (Ed25519 identity)

Recognition

  • Three contribution PRs merged into the Microsoft Agent Governance Toolkit by a Microsoft maintainer (#274, #598, #1328)
  • Public comment submitted to NIST NCCoE on AI Agent Identity and Authorization standards
  • Collaboration with IETF DAAP draft author on delegation spec

Links

License

Apache-2.0

Related: agent-passport-access-shim

Adapter that emits a signed AccessReceipt for each governed MCP tools/call: https://www.npmjs.com/package/agent-passport-access-shim. Receipts verify with the SDK or in the browser at https://agent-passport.org/verify.html.

來源:README.md,提交 12e45d7

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v6.1.2最新Oct 3, 2026