Inspiration

As autonomous AI agents transition from conversational chatbots to active executing entities—committing code to repositories, deploying cloud containers, and purchasing API credits—granting them static, over-privileged master API keys creates immense security hazards. If an agent hallucinates, loops, or is prompt-injected, it can wipe production environments or drain bank accounts.

We were inspired to build AGENT-PASSPORT, a sovereign, zero-trust delegation standard that acts as a cryptographically verifiable bearer passport for autonomous agents.

What it does

AGENT-PASSPORT establishes a scope-bounded bearer credential layer for AI agents.

  • Ed25519 Cryptographic Proof: Human owners sign short-lived JWT claim payloads defining explicit capability scopes (e.g. github:merge_staging), financial spend limits (e.g. $150.00 USD), and validity expiration windows.
  • Perimeter Verification Guard: Target API gateways (GitHub, AWS, Stripe) inspect the presented bearer passport signature and verify requested scopes before allowing execution.
  • Emergency 1-Click Revocation: Includes an instant global kill-switch webhook that nullifies agent credentials across all connected microservices instantly if an anomaly occurs.

How we built it

  • Core Architecture: Built an interactive web application and specification visualizer using HTML5, CSS3, and modern JavaScript.
  • Cryptographic Engine: Implemented asymmetric signature generation (Ed25519 claim payloads) and zero-trust verification rules.
  • Agent Sandbox & Mock Guard: Created an autonomous task execution simulator with real-time API verification log streams and non-repudiable audit ledgers.

Challenges we ran into

Designing a zero-trust verification model that enforces financial spend caps without introducing heavy latency at the target API perimeter. We solved this by structuring lightweight JSON claim payloads and real-time webhook revocation checks.

Accomplishments that we're proud of

  • Created a fully functional interactive prototype and visualizer for the Egoist AI Passport standard.
  • Enforced strict least-privilege scoping that automatically blocks unauthorized production deploys or overspending attempts.
  • Successfully published the repository and live demo to GitHub Pages.

What we learned

We learned how crucial fine-grained, short-lived delegation credentials are for the future of multi-agent autonomous ecosystems.

Built With

Share this project:

Updates

Submission history