[{"data":1,"prerenderedAt":216},["ShallowReactive",2],{"docs-\u002Fdocs\u002Fv2\u002Fagent\u002Fidentity":3},{"id":4,"title":5,"body":6,"description":16,"extension":209,"meta":210,"navigation":211,"path":212,"seo":213,"stem":214,"__hash__":215},"docs\u002Fdocs\u002Fv2\u002Fagent\u002Fidentity\u002Findex.md","Identity",{"type":7,"value":8,"toc":202},"minimark",[9,13,17,20,25,28,51,54,57,70,73,77,80,83,86,90,97,103,161,164,168,171,174,189,198],[10,11,5],"h1",{"id":12},"identity",[14,15,16],"p",{},"Every deployed agent is a cryptographic entity on the internet. Not a process running\non a server. Not a service account tied to a human's login. An entity — with a stable\nidentity, a verifiable presence, and the ability to act in the world as itself.",[14,18,19],{},"The identity is provisioned automatically at deploy time. No configuration. No module\nto install. It arrives the same way a URL and an API key arrive.",[21,22,24],"h2",{"id":23},"what-the-identity-is","What the identity is",[14,26,27],{},"At its root, the identity is a keypair: a private key that never leaves Axon's\ninfrastructure, and a public key published where anyone can find it.",[29,30,35],"pre",{"className":31,"code":32,"language":33,"meta":34,"style":34},"language-bash shiki shiki-themes dark-plus","did:web:agents.arclabs.it:alice:barry  # the identity — a standard W3C DID\n","bash","",[36,37,38],"code",{"__ignoreMap":34},[39,40,43,47],"span",{"class":41,"line":42},"line",1,[39,44,46],{"class":45},"sCudf","did:web:agents.arclabs.it:alice:barry",[39,48,50],{"class":49},"sOLPB","  # the identity — a standard W3C DID\n",[14,52,53],{},"The DID is the canonical form. It resolves to the agent's public key and service\nendpoints. Any DID-aware system can verify an agent's identity without calling back\nto Axon, without a shared secret, without any prior arrangement.",[14,55,56],{},"The email address is the human-readable alias for that identity:",[29,58,60],{"className":31,"code":59,"language":33,"meta":34,"style":34},"barry.alice@agents.arclabs.it  # the same identity, legible to human-built systems\n",[36,61,62],{"__ignoreMap":34},[39,63,64,67],{"class":41,"line":42},[39,65,66],{"class":45},"barry.alice@agents.arclabs.it",[39,68,69],{"class":49},"  # the same identity, legible to human-built systems\n",[14,71,72],{},"Same agent. Two representations. The DID is how machines see it. The email is how\nservices built for humans see it. Both point to the same keypair.",[21,74,76],{"id":75},"why-this-matters","Why this matters",[14,78,79],{},"Agents have operated by borrowing until now. They borrow a human's OAuth token to call\nGitHub. They borrow a team's API key to call Linear. The human rotates their token, or\nleaves the company, and the agent breaks. The audit trail shows actions taken by a person\nwho didn't take them.",[14,81,82],{},"An agent with its own identity can own these things instead of borrowing them. It can\ninitiate an OAuth flow as itself — using its email address to create the account,\ncompleting the verification flow through its own inbox, holding the resulting token\nagainst its own keypair. The agent is the authorised party. Not a proxy for one.",[14,84,85],{},"That distinction is the difference between an agent that is genuinely autonomous and one\nthat falls apart when the wrong person leaves.",[21,87,89],{"id":88},"the-web-parallel","The web parallel",[14,91,92,93,96],{},"The web solved this problem for servers fifteen years ago. A domain has a TLS certificate\nproving you control it. Services publish capabilities at ",[36,94,95],{},".well-known\u002F"," paths — a standard\nlocation any caller can check without prior arrangement. Trust is decentralised: the\ncertificate is signed by a known authority, the verification is local.",[14,98,99,100,102],{},"Axon applies the same pattern to agents. The keypair is the TLS certificate — proof of\ncontrol, no central authority required for verification. The email address is the domain\nname — the human-legible identifier that anchors the agent in existing systems. The\n",[36,101,95],{}," endpoint is where you go to find the public key.",[104,105,106,122],"table",{},[107,108,109],"thead",{},[110,111,112,116,119],"tr",{},[113,114,115],"th",{},"Component",[113,117,118],{},"Web equivalent",[113,120,121],{},"Role",[123,124,125,137,148],"tbody",{},[110,126,127,131,134],{},[128,129,130],"td",{},"ES256 keypair",[128,132,133],{},"TLS certificate",[128,135,136],{},"Root of identity — verifiable proof",[110,138,139,142,145],{},[128,140,141],{},"Email address",[128,143,144],{},"Domain name",[128,146,147],{},"Human-legible alias — works with existing services",[110,149,150,155,158],{},[128,151,152,154],{},[36,153,95],{}," endpoint",[128,156,157],{},"DNS + service discovery",[128,159,160],{},"Public key lookup, no auth required",[14,162,163],{},"No new infrastructure. No proprietary protocol. The same pattern that made the web\ntrustworthy — applied to agents.",[21,165,167],{"id":166},"credentials","Credentials",[14,169,170],{},"An agent with its own identity can hold credentials as itself rather than borrowing them\nfrom a human. OAuth grants, API keys, service tokens — attached to the agent's identity,\nscoped to this agent only, persisting across redeployments and personnel changes. Agent\ncredential ownership is in active development.",[172,173],"hr",{},[14,175,176,184,185,188],{},[177,178,179],"strong",{},[180,181,183],"a",{"href":182},"\u002Fdocs\u002Fv2\u002Fagent\u002Fidentity\u002Femail","Email"," — the email alias: the inbox, the ",[36,186,187],{},"waitFor","\nprimitive, how an agent participates in services built for humans.",[14,190,191,197],{},[177,192,193],{},[180,194,196],{"href":195},"\u002Fdocs\u002Fv2\u002Fagent\u002Fidentity\u002Fsigning","Signing"," — the keypair: what it proves, how\nverification works, the DID standard it implements.",[199,200,201],"style",{},"html pre.shiki code .sCudf, html code.shiki .sCudf{--shiki-default:#DCDCAA}html pre.shiki code .sOLPB, html code.shiki .sOLPB{--shiki-default:#6A9955}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}",{"title":34,"searchDepth":203,"depth":203,"links":204},2,[205,206,207,208],{"id":23,"depth":203,"text":24},{"id":75,"depth":203,"text":76},{"id":88,"depth":203,"text":89},{"id":166,"depth":203,"text":167},"md",{},true,"\u002Fdocs\u002Fv2\u002Fagent\u002Fidentity",{"title":5,"description":16},"docs\u002Fv2\u002Fagent\u002Fidentity\u002Findex","xYJroCuSiJWTglzdSIyPvcuTkvBM7NzEkrW-c8M_i_k",1786104358771]