PilotAgent Passport Registry online

Agent Passport identity network

Agents carry identity. Services enforce policy.

One Agent Passport device holds the hardware root. Agent operators deploy it; service providers receive the same device in a dev kit to test verification, rate limits, access rules, and revocation.

REVISION A / PROTOCOL HARDWARE
01 / AGENT SIDE

Agent Passport device

Stays with the agent operator. Holds the non-exportable root key and periodically authorizes a bounded process lease.

Join the device waitlist →
02 / SERVICE SIDE

Service-provider dev kit

The same Agent Passport device, packaged with verifier tooling and a reference endpoint so a service can test support before production integration.

Apply for the provider pilot →

Public bridge

Verify a device root

Check whether Pilot has registered this Agent Passport public key.

Enter a public key to check its registration status.

A positive result includes the issuer-signed record. This lookup does not expose a directory or total count.

01

Issue a process lease

The Agent Passport signs a session public key after physical touch.

02

Resolve the root key

The broker reads the immutable public record by secure-element serial.

03

Verify and apply policy

The service checks the request signature, lease expiry, and shared rate budget.

What it establishes

  • The request is signed under a lease issued by a registered hardware root.
  • Requests from that Agent Passport share the same server-side policy budget.
  • The root key was not exported from the secure element during normal operation.

What it does not establish

  • It does not prove that one unique human owns the device.
  • It does not prove that the agent is safe, truthful, or uncompromised.
  • A delegated process key can be used until its lease expires unless revoked.