Scoped permissions, spend limits, delegation chains, and cascade revocation. Every action cryptographically signed and logged.
Identity says who an agent is. Nothing says what it's allowed to do right now, how much it can spend, or when to cut it off.
Issue a passport, authorize actions against it, delegate to sub-agents with narrower scope.
Every authorize() call is logged. Persisted in SQLite, queryable by passport ID. Compliance-ready.
Eight packages, one protocol. Click any to explore.
Open protocol. MIT licensed. No vendor lock-in.