Skip to content

Latest commit

 

History

249 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

AAuth

AAuth gives every agent its own cryptographic identity and signs every request it makes, so no credential is a bearer token and nothing needs pre-registration. A person server represents the person the agent acts for, and access servers apply resource policy across trust domains. Each party adopts independently.

Specifications

Draft Scope Editor's copy
AAuth Protocol Agent, person, resource, and auth tokens; five access modes; missions; PS–AS federation html
HTTP Signature Keys The Signature-Key header and key discovery that AAuth signs with html
AAuth Bootstrap Informational: how an agent provider enrolls agents and issues agent tokens html
AAuth R3 Authorization in the vocabularies agents already use: MCP, OpenAPI, gRPC, GraphQL html
AAuth Budgets Spending ceilings for metered resources html
AAuth Events Event delivery to agents through their agent provider html

Exploration, not yet submitted: AAuth Supervision, the PS–SS interface where a supervision server decides on the person's behalf.

Implementing against an earlier revision? See Updating from -10 to -11. For the minimum live pieces needed to show interoperability, see the Interoperability Demo Profile.

Get Involved

Implementations

Project Kind
packages-js TypeScript SDK for agents and MCP servers
dotnet-samples .NET SDK and samples
aauth-python-library Python request signing and verification
aauth-go-library Go request signing and verification
regent-httpsig Python resource-side verification and budgets metering
keycloak-aauth-extension Keycloak SPI (26.2.5)
aauth-person-server Person server with missions
extauth-aauth-resource Envoy / agentgateway ext-authz that makes an HTTP, MCP, or A2A service an AAuth resource
whoami Identity claims resource
proxy The user's AAuth agent as an MCP server
AAuth Web Agent Protocol playground
AAuth Explorer Walkthrough of the protocol flows
aauth-full-demo A2A multi-agent flow with Keycloak and user consent

Building

make builds each draft-*.md into HTML and text.


Author: Dick Hardt (dick.hardt@gmail.com). Founding sponsor: Geffen Posner.

About

explainer for AAuth

Resources

Contributing

Stars

125 stars

Watchers

8 watching

Forks

Releases

Packages

Used by

Contributors

Languages