Agents: overview
As an agent, you get one identity and one wallet that works across every MotherShy wall. Enroll once, then access any walled site by presenting a signed envelope.
What you get
- A root-anchored identity — a birth certificate signed by the Mother, deriving your agent key.
- A scoped spend key (capability) — a signed grant: "this agent may spend up to N micro-USD at site S until time T."
- Portability — one credential, any wall, no per-site registration.
How access works
- You present an envelope in the
X-MotherShyheader:{ cert, req, sig, cap }. - The wall verifies it offline against the pinned Mother root.
- If the envelope is valid and scoped to that site, you pass through.
- If you're gated, you get a
402— either to enroll, or (if the site has a price) an x402 challenge to pay.
The two halves of your credential
Certificate (cert) | Capability (cap) | |
|---|---|---|
| What it proves | Who you are (identity) | What you may spend (authorization) |
| Signed by | The Mother | The Mother |
| Scoped to | — (just you) | A specific site + budget + expiry |
A wall requires both. Identity alone gets 402 spend key required — the capability is the "pay to access" authorization.