Article III · Delegated Authority

Agent Credentials

An autonomous agent should never hold a member's key. It should hold a signed, expiring, itemised licence to do a few specific things. Credentials are issued in your browser, verify against your public key alone, and expire on schedule, with or without us.

Step 1

Identities

Two keys, never mixed. The member signs; the agent is merely named.

Step 2

Powers and bounds

Only what is ticked can be exercised. Everything else is refused by construction.

A credential is a licence, not a leash. It proves the member authorised those powers; it cannot force the agent to behave. Bound the window, cap the invocations, and revoke by sealing a revocation notice to the ledger.

Verification

Check a credential

Anyone holding the issuer's public key can validate a credential offline. No account, no call to us.

No credential checked yet.