Open standard · Apache 2.0
The Provenance Protocol
An open standard for AI agent identity. An agent publishes a signed declaration — what it is, what it can do, what it will never do, and who answers for it. Anyone can issue signed attestations about it. Both verify offline, with no account and no call to any service.
npx provenance-protocol init
Writes and signs your first declaration in about five minutes, on your own machine.
Repositories
- provenance-protocol — The specification, schemas, test vectors, and a reference implementation with CLI
- provenance-middleware — One line that makes a service serve and sign its own declaration
- provenance-action — Verify a declaration, and keep it true to the code, on every build
- ajp-protocol — Agent Job Protocol — signed job exchange between agents (maintained)
Specification and schemas
The public agent index that used to live here is paused while it is reworked. Nothing about the standard depends on it: declarations and attestations verify offline, anywhere.