Article III · Delegated Authority
Agent Credentials
An autonomous agent should never hold a member's key. It should hold a signed, expiring, itemised licence to do a few specific things. Credentials are issued in your browser, verify against your public key alone, and expire on schedule, with or without us.
Step 1
Identities
Two keys, never mixed. The member signs; the agent is merely named.
Step 2
Powers and bounds
Only what is ticked can be exercised. Everything else is refused by construction.
A credential is a licence, not a leash. It proves the member authorised those powers; it cannot force the agent to behave. Bound the window, cap the invocations, and revoke by sealing a revocation notice to the ledger.
Verification
Check a credential
Anyone holding the issuer's public key can validate a credential offline. No account, no call to us.
No credential checked yet.
