Agent Requests a Challenge
Your agent calls get_uns_challenge on the service's Gateway. The Gateway generates a cryptographic nonce and packages it with the service's attestation requirements.
Persistent Receipts
Cryptographic Trust is the foundation Agentic Name Service is built upon.
Cryptographic trust
Three independent parties, three keys, three signatures โ one verifiable receipt provides an irrefutable answer to "who authorized that?"
Your agent calls get_uns_challenge on the service's Gateway. The Gateway generates a cryptographic nonce and packages it with the service's attestation requirements.
Your Identity Guardian verifies the challenge matches your delegation rules, then signs a scoped, time-bounded attestation. The agent never sees your key.
The Gateway verifies both signatures against Coordination Node keys, adds its own signature, and hands your agent a portable receipt the service can independently verify.
Persistent Receipts
Holds your delegation rules, manages passkeys, and makes approval decisions on your behalf. During onboarding, you'll set your default attestation posture โ and you can configure rules per action, as long as they meet or exceed service minimums.
Nodes register here so they can verify each other's signatures without direct communication. DNS-like shared infrastructure for key distribution and rotation.
Generates challenges, verifies signatures, assembles receipts. Spin up a Service Gateway and authenticate it to your Guardian account.
Performance
The full handshake happens at session start and for high-risk escalations. Everything in between is a local credential check.
Open beta