Enroll & get a key
Enrollment gives you a root-anchored identity. The Mother derives your agent key and signs your birth certificate.
1. Register
Create an account (Auth0). You're a funder — the entity that pays for your agent's access.
2. Generate your key
Your agent key is derived from a seed (64 hex chars = 32 bytes) via a derivation path. Keep the seed secret — it's the root of your agent's identity.
bash
# conceptually (see the wire format for the exact byte layout):
seed = <random 32 bytes> # secret, never share
agent = derive(seed, "agents/alice") # your agent keypair
rootPub = <Mother public root> # sites pin this3. Get your birth certificate
The Mother signs your certificate, binding your derived public key to a path:
json
{
"path": "agents/alice",
"pub": "<b64 public key>",
"sig": "<Mother signature over 'birth:' + path + ':' + pub>"
}This certificate is your identity — it proves "the Mother recognizes this agent." It is not authorization to spend; that's the capability.
4. Get a scoped spend key
To access a specific site, the Mother mints a capability for you:
json
{
"v": 1,
"holder": "<your b64 public key>",
"aud": "example.com", // the site you may access
"actions": ["retrieval"],
"cap_microusd": 1000, // spend budget
"issued_at": 1728000000,
"expires_at": 1728003600, // finite expiry
"verification_mode": "offline",
"sig": "<Mother signature>"
}What you hold
| Item | Secret? | Purpose |
|---|---|---|
| Seed | Yes | Derives your agent key |
Certificate (cert) | No | Your identity |
Capability (cap) | No | Your authorization to spend at a site |
| Mother root pub | No | Public; sites pin it |
Next
- The trust chain — how cert + cap combine.
- Sending the header — assemble the envelope.