The problem
AI agents are showing up with production credentials and no portable proof of what they are allowed to do. "Trust me, it is scoped" does not survive an audit or an incident. An Agent Passport makes the answer self-evident: a signed credential stating the agent’s purpose, its tool ceiling, and when it expires — built on open standards so anyone can check it without calling you.
What you get
Outcomes you can take to a skeptical security team.
- A signed passport per agent stating its purpose, tool ceiling, and expiry
- Served at a public URL and verifiable fully offline — no account needed
- Built on W3C Verifiable Credentials 2.0 and did:key, not a proprietary format
- A portable answer to "what is this agent allowed to do" that an auditor can keep
How it works
Three steps, no surprises.
01
Scope the agent
State the agent’s purpose, the tools it may touch, and when its authority expires.
02
Issue the passport
A signed Agent Passport is minted and served at a public, shareable URL.
03
Anyone verifies it
A partner, auditor, or downstream service checks the signature offline, no TrustFix login.
Continue the platform