Skip to content

Conversation

@hammadtq
Copy link
Contributor

This PR adds the first draft of the OpenBotAuth Agent Identity & Passport spec:

  • Defines agent: and sub-agent identifiers
  • Introduces principals and Agent Delegation Tokens (ADT, JWS-based)
  • Describes mapping from agent-id → registry → key directory
  • Specifies Signature-Agent usage and required signed components
  • Adds optional 402 Agent Required semantics
  • Documents Agent Cards and basic security considerations

What I’d like feedback on:

  • Whether the principal/ADT model matches how you’re thinking about ownership
  • If the sub-agent convention (agent:.../voice, .../browser) + registry fields feel right
  • Any sections that are too heavy / need to be split out or simplified

Feel free to edit the draft directly in the PR or leave comments/suggestions inline.

@hammadtq hammadtq self-assigned this Nov 27, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants