The authorization layer your AI agents are missing

Scoped permissions, spend limits, delegation chains, and cascade revocation. Every action cryptographically signed and logged.

$ npm install @passport-agent/sdk
Agent Passport
Active
Agent
booking-bot
Principal
user:alice@acme.com
Permissions
calendar:read calendar:write email:send
Limits
$500
Max spend
24h
Time to live
Delegation chain
alice
→
booking-bot
→
email-drafter
The problem

Your agents have full access or no access at all

Identity says who an agent is. Nothing says what it's allowed to do right now, how much it can spend, or when to cut it off.

Without passport

✗ Full account access, no scoping
✗ No spend limits — agents drain budgets
✗ Revocation means rotating all keys
✗ No audit trail of what agents actually did

With passport

✓ Scoped permissions per agent, per task
✓ Budget caps with server-side tracking
✓ Instant revocation cascades to sub-agents
✓ Every action logged — allowed or denied
How it works

Three verbs. That's the whole API.

Issue a passport, authorize actions against it, delegate to sub-agents with narrower scope.

01
Issue
Create a signed passport scoped to specific actions, budgets, and time windows.
const passport = AgentPassport.issue({ agent: "booking-bot", permissions: ["calendar:*"], limits: { maxSpend: 500 }, ttl: "24h", })
02
Authorize
Check every action before executing. Allowed or denied — every call is logged.
const result = passport.authorize({ action: "calendar:write", spend: 0, }) // → { allowed: true, remaining: 500 } // → { allowed: false, reason: "…" }
03
Delegate
Hand a narrower passport to a sub-agent. Permissions only shrink, never grow.
const child = passport.delegate({ agent: "email-drafter", permissions: ["email:send"], limits: { maxSpend: 50 }, })
Audit trail

Know exactly what your agents did

Every authorize() call is logged. Persisted in SQLite, queryable by passport ID. Compliance-ready.

Action Agent Time Reason
✓ calendar:read booking-bot 14:23:01 —
✓ calendar:write booking-bot 14:23:04 —
✗ payment:charge booking-bot 14:23:08 exceeds $500 budget
✓ email:send email-drafter 14:23:12 —
✗ email:send email-drafter 14:23:15 rate limit: 5/hour
✗ database:drop booking-bot 14:23:19 permission not granted
Integrations

Works with your stack out of the box

Eight packages, one protocol. Click any to explore.

MCP
@passport-agent/mcp
Middleware for MCP tool call authorization
View details →
Express / Fastify
@passport-agent/middleware
HTTP middleware for Node.js frameworks
View details →
LangChain
@passport-agent/langchain
Tool wrapper for LangChain agents
View details →
CrewAI
@passport-agent/crewai
Agent decorator for CrewAI
View details →
A2A Protocol
@passport-agent/a2a
Agent Card extensions for A2A
View details →
Authority Server
@passport-agent/server
Self-hosted REST API with SQLite and dashboard
View details →
Core
@passport-agent/core
Token creation, validation, policy engine
View details →
SDK
@passport-agent/sdk
Developer-facing API — the main entry point
View details →

Start in ten lines. Scale to production.

Open protocol. MIT licensed. No vendor lock-in.

$ npm install @passport-agent/sdk