PERSISTENT
HARNESS
Critical Infrastructure for an Agentic Future

Persistent Receipts

Trust, but verify.

Cryptographic Trust is the foundation Agentic Name Service is built upon.

Service DomainUser DomainPersistent HarnessTrilateral Handshakesign_token_requesttrustsMCP PROTOCOL LAYERkey lookupkey lookupREST API LAYER/api/* portals/api/* dashboardscallback๐Ÿ‘คUserHuman Principal๐Ÿค–AgentUntrusted Transport๐ŸšชGatewayService AnchorCoordinationNodeTrust Registry๐Ÿ›ก๏ธGuardianIdentity Providerโ˜๏ธServiceAPI / ApplicationMCP Protocol LayerAgent relays signed tokens via MCP tools.MCP protocolKey verificationDelegationCallback
Three independent partiesThree keysThree signaturesOne verifiable receipt

Cryptographic trust

Three independent nodes. Three roles.

Three independent parties, three keys, three signatures โ€” one verifiable receipt provides an irrefutable answer to "who authorized that?"

01

Agent Requests a Challenge

Your agent calls get_uns_challenge on the service's Gateway. The Gateway generates a cryptographic nonce and packages it with the service's attestation requirements.

02

Guardian Signs the Delegation

Your Identity Guardian verifies the challenge matches your delegation rules, then signs a scoped, time-bounded attestation. The agent never sees your key.

03

Gateway Assembles the Receipt

The Gateway verifies both signatures against Coordination Node keys, adds its own signature, and hands your agent a portable receipt the service can independently verify.

Persistent Receipts

Three independent nodes. Three roles.

Your personal trust authority.

Holds your delegation rules, manages passkeys, and makes approval decisions on your behalf. During onboarding, you'll set your default attestation posture โ€” and you can configure rules per action, as long as they meet or exceed service minimums.

The public key registry.

Nodes register here so they can verify each other's signatures without direct communication. DNS-like shared infrastructure for key distribution and rotation.

The service-side trust anchor.

Generates challenges, verifies signatures, assembles receipts. Spin up a Service Gateway and authenticate it to your Guardian account.

Performance

99% of actions are instant.

The full handshake happens at session start and for high-risk escalations. Everything in between is a local credential check.

<1msLocal credential check
~300msFull trilateral handshake
1 handshakePer session start
3 signaturesPer receipt

Open beta

Signed. Verified. Receipted.

Test Drive