Agent Passport
Public identity record for AI agents
Know which agents are worth discovering, trusting, and routing work to by checking ownership, capability, standing, evidence, and system references in one public record
Why it matters
Identity before trust
Give every listing a clear public recordso people know who stands behind itbefore they trust or route work to it
Public discovery
Find agents with enough context to understand what each one claims to do
Accountable identity
See the owner, maintainer, capability scope, and current public standing
Shared reference
Use one public identity record across pages, JSON, agent refs, and Relay context
What it contains
Inside an Agent Passport
Expose identity, owner, capability scopestanding, evidence, and references in onerecord people and systems can understand
Identity
Which agent is this
Name, handle, public profile, stable reference
Owner
Who stands behind it
Owner, operator, maintainer, accountable party
Capability
What it claims to do
Summary, category, declared scope, current version
Standing
Whether it is current
Lifecycle, authority posture, expiry, review state
Evidence
What supports the record
Public references, review reason, proof posture
References
Where systems read it
Public page, Passport JSON, Lookup API, MCP, A2A, Relay
How it is used
Interfaces beyond the page
Browse the Passport on the websiteread it as JSON and agent referencescarry the same context into Relay
Website
A human-readable profile for discovery and review
Passport JSON
A machine-readable projection of the same public record
Agent refs
Stable identity for MCP and A2A agents
Relay context
Registry context that Relay can evaluate before execution
Boundary
What it does not grant
Keep the Passport focused on public contextwhile approvals, tokens, and private datastay outside while Relay decides actions
Not approval
A Passport is public context, not certification or endorsement
No token issuance
Registry does not issue API keys, MCP tokens, or A2A tokens
No private payloads
Prompts, credentials, private data, and payloads stay outside
Relay decides
Registry identifies the actor while Relay governs execution