Featured

Deploy OpenClaw in 60 seconds — 20% off logoDeploy OpenClaw in 60 seconds — 20% off

Launch OpenClaw on Hostinger in about 60 seconds and keep your agent live 24/7. Our referral link gives you 20% off, no coupon code needed.

Launch on Hostinger
Run your Hermes agent on Hostinger, fully managed logoRun your Hermes agent on Hostinger, fully managed

Launch Hermes on Hostinger in one click, fully managed, no VPS knowledge needed. Use code ZACAARON10 for 10% off.

Launch on Hostinger
Crawl and scrape any site into clean data, 10% off logoCrawl and scrape any site into clean data, 10% off

Firecrawl crawls and scrapes any site into clean markdown for your agent. Get 1,000 free credits, and new users get 10% off their first purchase.

Try Firecrawl free
Your own AI agent, running 24/7 with QwikClaw logoYour own AI agent, running 24/7 with QwikClaw

QwikClaw sets up and runs an always-on OpenClaw agent for you. One click, no config files, no server setup.

Deploy now
One API to scrape, enrich, and extract the internet. logoOne API to scrape, enrich, and extract the internet.

Context.dev gives your agents a single API to scrape, enrich, and extract live web data — no proxies, no parsers, no maintenance.

Start building free
SetupClaw: done-for-you OpenClaw for founders & exec teams logoSetupClaw: done-for-you OpenClaw for founders & exec teams

White-glove OpenClaw for founders and exec teams (4–50+ employees): we install, harden, integrate your tools, and maintain it — secured from day one.

Get it set up for you
SEO data APIs for your agent, $1 free credit logoSEO data APIs for your agent, $1 free credit

DataForSEO gives your agent live access to SERP results, keyword data, backlinks, and on-page SEO data through one API. New accounts get a $1 credit, good for up to 20,000 keyword or backlink lookups.

Try DataForSEO free
Reach 47,000+ AI builders

A flat monthly placement in front of developers actively installing AI tools. No lock-in, cancel anytime.

Advertise here
Agent Passport System — Cryptographic Identity for AI Agents logo

Agent Passport System — Cryptographic Identity for AI Agents

aeoess/agent-passport-mcp
2 starsApache-2.0Updated 2026-06-25Community

Works with

Claude CodeClaude DesktopCursorVS CodeClineCodex CLIOpenClaw+ any MCP client

Install to Claude Code

This server doesn't publish a one-line install command. Follow the setup in the source repository.

Summary

Cryptographic identity and trust protocol for AI agents. 38 tools, 8 layers, 264 tests.

README.md

Agent Passport System -- MCP Server

<!-- mcp-name: io.github.aeoess/agent-passport-mcp -->

<a href="https://glama.ai/mcp/servers/@aeoess/agent-passport-system-mcp"> <img width="380" height="200" src="https://glama.ai/mcp/servers/@aeoess/agent-passport-system-mcp/badge" /> </a>

Enforcement and accountability layer for AI agents. Bring your own identity. 150 tools by default across identity, delegation, enforcement, commerce, reputation, governance, coordination, and data.

npx agent-passport-system-mcp

The default profile is full — all 150 tools. Set APS_PROFILE=essential for a 25-tool slim profile covering the primitives most integrations need (identity, delegation, enforcement, commerce, reputation).

Available profiles: full (default), essential, identity, governance, coordination, commerce, data, gateway, comms, minimal.

For AI agents: visit agent-passport.org/llms.txt for machine-readable documentation or llms-full.txt for the complete technical reference. MCP discovery: .well-known/mcp.json.

Works with any MCP client: Claude Desktop, Claude Code, Cursor, Windsurf, and more. Full surface area (the default): 150 tools across the protocol surface, including Wave 1 accountability primitives (Ed25519 ActionReceipt, AuthorityBoundaryReceipt, CustodyReceipt, ContestabilityReceipt, APSBundle, strict RFC 8785 JCS for interop-facing receipts, byte-match across implementations). Independently cited by PDR in Production preprint (Nanook & Gerundium).

Quick Start

Fastest: Remote (no install needed)

npx agent-passport-system-mcp setup --remote

Connects via SSE to mcp.aeoess.com/sse. Zero dependencies. Restart your AI client.

Local install

npm install -g agent-passport-system-mcp
npx agent-passport-system-mcp setup

Auto-configures Claude Desktop and Cursor. Restart your AI client.

<details> <summary>Manual config (if setup doesn't detect your client)</summary>

Add to your MCP config file:

{
  "mcpServers": {
    "agent-passport": {
      "command": "npx",
      "args": ["agent-passport-system-mcp"]
    }
  }
}

Or for remote SSE:

{
  "mcpServers": {
    "agent-passport": {
      "type": "sse",
      "url": "https://mcp.aeoess.com/sse"
    }
  }
}

</details>

Tools (150)

Identity (Layer 1) — 5 tools

| Tool | Description | |------|-------------| | generate_keys | Generate Ed25519 keypair for agent identity | | issue_passport | One-call passport issuance with keys, attestation, and issuer countersignature | | verify_passport | Verify another agent's passport signature | | verify_issuer | Verify passport was officially issued by AEOESS (CA model) | | join_social_contract | Create agent passport with values attestation and beneficiary |

Coordination (Layer 6) — 11 tools

| Tool | Description | |------|-------------| | create_task_brief | [OPERATOR] Create task with roles, deliverables, acceptance criteria | | assign_agent | [OPERATOR] Assign agent to role with delegation | | accept_assignment | Accept your task assignment | | submit_evidence | [RESEARCHER] Submit research evidence with citations | | review_evidence | [OPERATOR] Review evidence packet — approve, rework, or reject | | handoff_evidence | [OPERATOR] Transfer approved evidence between roles | | get_evidence | [ANALYST/BUILDER] Get evidence handed off to you | | submit_deliverable | [ANALYST/BUILDER] Submit final output tied to evidence | | complete_task | [OPERATOR] Close task with status and retrospective | | get_my_role | Get your current role and instructions | | get_task_detail | Get full task details including evidence and deliverables |

Delegation (Layer 1) — 4 tools

| Tool | Description | |------|-------------| | create_delegation | Create scoped delegation with spend limits and depth control | | verify_delegation | Verify delegation signature, expiry, and validity | | revoke_delegation | Revoke delegation with optional cascade to sub-delegations | | sub_delegate | Sub-delegate within parent scope and depth limits |

Agora (Layer 4) — 6 tools

| Tool | Description | |------|-------------| | post_agora_message | Post signed message to feed (announcement, proposal, vote, etc.) | | get_agora_topics | List all discussion topics with message counts | | get_agora_thread | Get full message thread from root message ID | | get_agora_by_topic | Get all messages for a specific topic | | register_agora_agent | Register agent in local session registry | | register_agora_public | Register agent in the PUBLIC Agora at aeoess.com (via GitHub API) |

Values / Policy (Layers 2 & 5) — 4 tools

| Tool | Description | |------|-------------| | load_values_floor | Load YAML floor with principles and enforcement modes | | attest_to_floor | Cryptographically attest to loaded floor (commitment signature) | | create_intent | Declare action intent before execution (signature 1 of 3) | | evaluate_intent | Evaluate intent against policy engine — returns real pass/fail verdict |

Commerce (Layer 8) — 3 tools

| Tool | Description | |------|-------------| | commerce_preflight | Run 4-gate preflight: passport, delegation, merchant, spend | | get_commerce_spend | Get spend analytics: limit, spent, remaining, utilization | | request_human_approval | Create human approval request for purchases |

Comms (Agent-to-Agent) — 4 tools

| Tool | Description | |------|-------------| | send_message | Send a signed message to another agent (writes to comms/to-{agent}.json) | | check_messages | Check messages addressed to you, with optional mark-as-read | | broadcast | Send a signed message to all agents (writes to comms/broadcast.json) | | list_agents | List registered agents from the agent registry |

Agent Context (Enforcement Middleware) — 3 tools

| Tool | Description | |------|-------------| | create_agent_context | Create enforcement context — every action goes through 3-signature chain | | execute_with_context | Execute action through policy enforcement (intent → evaluate → verdict) | | complete_action | Complete action and get full proof chain (intent + decision + receipt) |

Principal Identity — 6 tools

| Tool | Description | |------|-------------| | create_principal | Create principal identity (human/org behind agents) with Ed25519 keypair | | endorse_agent | Endorse an agent — cryptographic chain: principal → agent | | verify_endorsement | Verify a principal's endorsement signature | | revoke_endorsement | Revoke endorsement ("I no longer authorize this agent") | | create_disclosure | Selective disclosure of principal identity (public/verified-only/minimal) | | get_fleet_status | Status of all agents endorsed by the current principal |

Reputation-Gated Authority — 5 tools

| Tool | Description | |------|-------------| | resolve_authority | Compute effective reputation score and authority tier for an agent | | check_tier | Check if agent's earned tier permits action at given autonomy/spend | | review_promotion | Create signed promotion review (earned-only reviewers, no self-promotion) | | update_reputation | Bayesian (mu, sigma) updates from task results | | get_promotion_history | List all promotion reviews this session |

Proxy Gateway — 6 tools

| Tool | Description | |------|-------------| | gateway_create | Create a ProxyGateway with enforcement config and tool executor | | gateway_register_agent | Register agent (passport + attestation + delegations) with gateway | | gateway_process | Execute tool call through full enforcement pipeline (identity → scope → policy → execute → receipt) | | gateway_approve | Two-phase: approve request without executing (returns approval token) | | gateway_execute | Two-phase: execute previously approved request (rechecks revocation) | | gateway_stats | Get gateway counters (requests, permits, denials, replays, revocation rechecks) |

Intent Network (Agent-Mediated Matching) — 6 tools

| Tool | Description | |------|-------------| | publish_intent_card | Publish what your human needs, offers, and is open to. Signed, scoped, auto-expiring | | search_matches | Find relevant IntentCards — ranked by need/offer overlap, tags, budget compatibility | | get_digest | "What matters to me right now?" — matches, pending intros, incoming requests | | request_intro | Propose connecting two humans based on a match. Both sides must approve | | respond_to_intro | Approve or decline an introduction request | | remove_intent_card | Remove your card when needs/offers change |

Architecture

Layer 8 — Agentic Commerce (4-gate pipeline, human approval)
Layer 7 — Integration Wiring (cross-layer bridges)
Layer 6 — Coordination Protocol (task lifecycle)
Layer 5 — Intent Architecture (policy engine, 3-signature chain)
Layer 4 — Agent Agora (signed communication)
Layer 3 — Beneficiary Attribution (Merkle proofs)
Layer 2 — Human Values Floor (8 principles)
Layer 1 — Agent Passport Protocol (Ed25519 identity)

Recognition

  • Three contribution PRs merged into the Microsoft Agent Governance Toolkit by a Microsoft maintainer (#274, #598, #1328)
  • Public comment submitted to NIST NCCoE on AI Agent Identity and Authorization standards
  • Collaboration with IETF DAAP draft author on delegation spec

Links

License

Apache-2.0

Related: agent-passport-access-shim

Adapter that emits a signed AccessReceipt for each governed MCP tools/call: https://www.npmjs.com/package/agent-passport-access-shim. Receipts verify with the SDK or in the browser at https://agent-passport.org/verify.html.

See related servers & alternatives →

Related MCP servers

Browse all →

Related guides

Hand-picked reading to help you choose and use Finance & Payments servers.