Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Agent Passport

OAuth-like identity verification for AI agents

Details

External ID
47096131
Source
HN
Company
—
Product
—
Website domain
—
Launched
Feb. 21, 2026
Cohort
—
Upvotes
14
Upvotes percentile
0.6314016172506739
Tags
—
Fetched at
Sept. 7, 2026, 9:25 p.m.
Updated at
Sept. 7, 2026, 9:25 p.m.

Description

Hi HN,I built Agent Passport, an open-source identity verification layer for AI agents. Think "Sign in with Google, but for Agents."The problem: AI agents are everywhere now (OpenClaw has 180K+ GitHub stars, Moltbook had 2.3M agent accounts), but there's no standard way for agents to prove their identity. Malicious agents can impersonate others, and skill/plugin marketplaces have no auth layer. Cisco's security team already found data exfiltration in third-party agent skills.Agent Passport solves this with: - Ed25519 challenge-response authentication (private keys never leave the agent) - JWT identity tokens (60-min TTL, revocable) - Risk engine that scores agents 0-100 (allow/throttle/block) - One-line verification for apps: `const result = await passport.verify(token)`It's fully open source (MIT), runs on free tiers ($0/month), and has a published npm SDK.GitHub: https://github.com/zerobase-labs/agent-passport Docs: https://github.com/zerobase-labs/agent-passport/blob/main/do... Live demo: https://agent-passport.vercel.appBuilt this because I kept seeing the same security gap in every agent platform. Happy to answer questions about the architecture or the agent identity problem in general.

Enrichment

Theme
ai cybersecurity and penetration testing
Vertical
Security
Function
Agent / copilot
Audience
Developer
AI stance
AI-native
Project type
Commercial product
Normalized one-liner
identity verification for ai agents
Manually corrected
False

Could you build this?

Yes An OAuth/OIDC-like authentication service with cryptographic key generation and token verification for AI agents can be readily built using standard web and crypto libraries.

Discussion

15 comments analyzed.

Competitors mentioned: OAuth2 with Dynamic Client Registration, SPIFFE/SPIRE, ERC-8004 (on-chain agent identity), agent-passport-system (open source alternative)

Concerns raised: JWT theft and 60-minute token lifetime enables masquerading, Bearer token relay attack (confused deputy problem), Doesn't solve root trust / bottom turtle problem, No security underpinnings compared to established standards, Generic term "Agent Passport" creates naming/trademark conflicts

Feature requests: Audience-scoped tokens (aud claim binding), Proof-of-possession (DPoP) implementation, Token binding to client fingerprint/IP, Per-request short-lived tokens instead of 60-minute window, Interoperability with SPIFFE/SPIRE for internal infrastructure

Competitors

Other products that read as similar to this one — 483 launches clear the similarity bar, closest 8 shown.

Attention rank: #191 of 484 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 110 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a agent / copilot tool for Agriculture yet.