World-Class AI Security Training ↗

The security layer for AI agent infrastructure

End-to-end security for AI agents.

Cryptographic trust for autonomous AI agents.

Every agent gets a verifiable passport. Every action gets a signature. Authority is earned through five graduated trust levels, and proven with tamper-evident receipts.

Built in the UK
Deployed anywhere

Open standards
IETF internet-drafts

SPIFFE-native
workload identity

SOC 2 & PCI DSS v4
control mappings

NEW Read the AgentPass case study, Securing the $5 trillion agentic economy

( Manifesto )

Agents don't need another login. They need a passport.

API keys were built for code that waits to be called. Autonomous agents act, they spend, deploy, delete and negotiate on your behalf. AgentPass gives every agent a verifiable passport, signs every action it takes, and meters its authority through five graduated trust levels. Not a dashboard after the fact. A control plane in the request path.

Identify. Sign. Govern.

Every agent action signed, scored and accountable

( The platform )

Four layers between your agents and disaster.

01
AGENT PASSPORTVALID

spiffe://acme.internal/ops-agent

KeyES256 · P-256
Validity24h · JIT
TrustL3 · Trusted

SHA-256  a9 1f 33 c2 e7 48 0b d4 … 6f 9d

Agent passports

Verifiable certificates for every agent in your fleet. Workload identity that survives restarts, redeploys and scale-out, with instant revocation when an agent goes rogue. One call, revoked everywhere.

Certificates • SPIFFE-native • Instant revocation

02
MCPS RECEIPTSIGNATURE VERIFIED
{
  "type":   "mcps.call.v1",
  "agent":  "ops-agent",
  "action": "POST /v1/deployments",
  "target": "prod-cluster", "nonce": "8f31…",
  "sig":    "c6e72fcc43e012e4…"
}

Signed actions

MCPS signs every call an agent makes, payments included, with per-call replay protection and tool-hash pinning. If the request wasn't signed by the passport, it doesn't happen. No vibes, just verification.

MCPS • Replay protection • Tool-hash pinning

03
TRUST LEVELSCORE 72 / 100
L0$0
L1$10
L2$100
L3$1,000
L4$50,000

Graduated trust

Authority is earned, not assumed. Five trust levels gate what an agent can touch and what it can spend, from L0 sandbox to L4 autonomy. Trust is earned gradually and stepped down the moment behaviour slips.

L0–L4 • Trust-gated scopes • Spend limits

04
AEBA · BEHAVIOURAL WATCHLIVE

baseline ok · 142 actions · 0 anomalies

anomaly · spend velocity +312%

trust reduced L3 → L1 · scopes narrowed

kill switch armed · denial receipt signed

Detection & response

AEBA (Agent Event Behaviour Analysis) is continuous behavioural monitoring of how every agent actually behaves, the missing XDR dimension for AI agents. Anomalies lower trust scores in real time, the kill switch stops a compromised agent instantly, and a hash-chained audit trail makes the whole story tamper-evident.

AEBA • Kill switch • Hash-chained audit • aeba.co.uk →

( Trust levels )

From sandbox to autonomy, one earned level at a time.

Every agent starts at zero. Behaviour, age and track record move its score, and its score sets hard limits on every action it can take. No exceptions, no overrides without a human.

Level Trust score Per action Daily limit
L0 Untrusted 0–19 $0 $0
L1 Limited 20–39 $10 $50
L2 Standard 40–59 $100 $500
L3 Trusted 60–79 $1,000 $5,000
L4 Full 80–100 $50,000 $200,000
0 Graduated trust levels,
L0 sandbox to L4 autonomy
0K OFAC + HMT sanctions
entries screened
0 SOC 2 trust service criteria
mapped to agent operations
0 IETF internet-drafts:
MCPS · ATTP · AEBA

( How it works )

Trust is a loop, not a checkbox.

AgentPass sits in the request path, not in a quarterly review. Four moves, running continuously, for every agent you operate.

  1. / 01

    Register

    An agent enrols and receives its passport, a verifiable certificate bound to its workload identity. It starts at L0 with zero authority and nothing to lose.

  2. / 02

    Sign

    Every call the agent makes carries a cryptographic signature with replay protection and pinned tool hashes. Servers verify before they execute, unsigned means undone.

  3. / 03

    Score

    Behavioural monitoring turns conduct into a live trust score. Clean history earns authority gradually; anomalies revoke it instantly. The score is the policy.

  4. / 04

    Enforce

    Scopes, spend limits and daily caps follow the trust level automatically. When something is wrong, revocation is one call and the kill switch is instant, with a tamper-evident audit trail of everything that happened.

OpenAPI Initiative · Approved extension

Our x-agent-trust extension is officially registered in the OpenAPI Extensions Registry.

The first vendor extension designed specifically for APIs serving autonomous AI agents.

View the registry entry → View live spec JWKS endpoint See it in the demo

( Why trust us )

Built on open standards. Mapped to law.

Open by design

MCPS, ATTP and AEBA are public IETF internet-drafts. The x-agent-trust extension lives in the OpenAPI Extensions Registry. No proprietary lock-in at the trust layer.

Regulator-ready

SOC 2 and PCI DSS v4 control mappings out of the box, sanctions screening built in, FCA regulatory sandbox applicant. Compliance evidence, not compliance theatre.

Kill switch included

Trust is graduated, never assumed. One call revokes a passport everywhere, instantly, and the hash-chained audit trail proves exactly what happened, in order, untampered.

Self-hosted

Get AgentPass Self-Hosted

The identity and trust layer for AI agents. One Docker container. Deploy in minutes.

What you need

  1. Docker installed on your server
  2. A license key from us (email below)
  3. That's it. Run docker-compose up.

What you get

  • Private GitHub repo access
  • Built-in CA, issue agent certificates immediately
  • Trust levels L0–L4 with scope enforcement
  • Sanctions screening (OFAC, EU, UK HMT)
  • Agent dashboard and management
  • Instant agent revocation
  • Integration support for your platform

Starter

10 agents

  • Built-in CA
  • Trust levels L0–L4
  • Scope enforcement
  • Sanctions screening
  • Dashboard
  • Signed audit trail
Get Starter
POPULAR

Pro

50 agents

  • Everything in Starter
  • + Priority support
  • + Custom CA subject
  • + Revocation support
  • + Integration support
Get Pro

Enterprise

unlimited agents

  • Everything in Pro
  • + Unlimited agents
  • + KMS integration
  • + AEBA monitoring
  • + Dedicated support
  • + Custom trust models
Contact Us

Ready to deploy?

Email us your company name and tier. You get private repo access and a license key. Deploy with Docker in minutes.

Get AgentPass →

contact@agentsign.dev