Inspiration
As autonomous AI agents transition from conversational chatbots to active executing entities—committing code to repositories, deploying cloud containers, and purchasing API credits—granting them static, over-privileged master API keys creates immense security hazards. If an agent hallucinates, loops, or is prompt-injected, it can wipe production environments or drain bank accounts.
We were inspired to build AGENT-PASSPORT, a sovereign, zero-trust delegation standard that acts as a cryptographically verifiable bearer passport for autonomous agents.
What it does
AGENT-PASSPORT establishes a scope-bounded bearer credential layer for AI agents.
- Ed25519 Cryptographic Proof: Human owners sign short-lived JWT claim payloads defining explicit capability scopes (e.g.
github:merge_staging), financial spend limits (e.g.$150.00 USD), and validity expiration windows. - Perimeter Verification Guard: Target API gateways (GitHub, AWS, Stripe) inspect the presented bearer passport signature and verify requested scopes before allowing execution.
- Emergency 1-Click Revocation: Includes an instant global kill-switch webhook that nullifies agent credentials across all connected microservices instantly if an anomaly occurs.
How we built it
- Core Architecture: Built an interactive web application and specification visualizer using HTML5, CSS3, and modern JavaScript.
- Cryptographic Engine: Implemented asymmetric signature generation (Ed25519 claim payloads) and zero-trust verification rules.
- Agent Sandbox & Mock Guard: Created an autonomous task execution simulator with real-time API verification log streams and non-repudiable audit ledgers.
Challenges we ran into
Designing a zero-trust verification model that enforces financial spend caps without introducing heavy latency at the target API perimeter. We solved this by structuring lightweight JSON claim payloads and real-time webhook revocation checks.
Accomplishments that we're proud of
- Created a fully functional interactive prototype and visualizer for the Egoist AI Passport standard.
- Enforced strict least-privilege scoping that automatically blocks unauthorized production deploys or overspending attempts.
- Successfully published the repository and live demo to GitHub Pages.
What we learned
We learned how crucial fine-grained, short-lived delegation credentials are for the future of multi-agent autonomous ecosystems.
Built With
- cryptography
- css3
- ed25519
- github
- html5
- javascript
- json

Log in or sign up for Devpost to join the conversation.