{"name":"aport-spec: The Open Agent Passport (OAP) Specification for AI Agent Trust","description":"The aport-spec repository introduces the Open Agent Passport (OAP) specification, a critical framework for establishing trust in AI agents. It defines a lightweight, cryptographically verifiable credential, enabling real-time, pre-action authorization for AI agents across various platforms. OAP provides the essential runtime trust layer for secure and scalable agentic commerce.","github":"https://github.com/aporthq/aport-spec","url":"https://osrepos.com/repo/aporthq-aport-spec","source":"osrepos.com","sourceDescription":"This repository profile is provided by osrepos.com, an open source repository discovery platform.","repositoryProfile":"https://osrepos.com/repo/aporthq-aport-spec","generatedFor":"open source discovery and AI-assisted research","markdown":"https://osrepos.com/repo/aporthq-aport-spec.md","json":"https://osrepos.com/repo/aporthq-aport-spec.json","topics":["ai","aiagent","authorization","security","TypeScript","specification","agent passport","verifiable credentials"],"keywords":["ai","aiagent","authorization","security","TypeScript","specification","agent passport","verifiable credentials"],"stars":null,"summary":"The aport-spec repository introduces the Open Agent Passport (OAP) specification, a critical framework for establishing trust in AI agents. It defines a lightweight, cryptographically verifiable credential, enabling real-time, pre-action authorization for AI agents across various platforms. OAP provides the essential runtime trust layer for secure and scalable agentic commerce.","content":"## Introduction\n\nThe `aporthq/aport-spec` repository introduces the **Open Agent Passport (OAP) v1.0 specification** (currently a draft), designed to establish a runtime trust rail for AI agents. As AI agents increasingly handle digital commerce, the critical challenge of trusting unseen agents emerges. OAP addresses this by providing a lightweight, cryptographically verifiable credential that enables real-time, pre-action authorization for AI agents across any platform. It shifts the focus from *who* built an agent to *what* it is allowed to do at the point of action.\n\n## Why Use and Benefits\n\nThe rapid acceleration of agentic commerce demands a robust trust infrastructure, which current solutions, primarily focused on agent identity, fail to provide. Merchants and platforms require instant verification and sub-100ms authorization decisions before sensitive data or money moves.\n\nOAP offers a comprehensive solution by providing the essential runtime trust layer for secure and scalable agentic commerce. Key benefits include:\n\n*   **Pre-action Authorization**: Ensures agents are authorized before sensitive operations.\n*   **Cryptographically Signed Decisions**: Provides immutable audit trails for all actions.\n*   **Global Suspend Capabilities**: Allows for instant risk mitigation across platforms.\n*   **Standardized Policy Packs**: Enables consistent enforcement of rules.\n*   **Instant Trust**: Delivers authorization decisions in under 100 milliseconds.\n*   **Standards Compliance**: Built to integrate with existing identity frameworks like W3C Verifiable Credentials and complement KYC/KYB.\n\n## Implementation Guidance\n\nThe `aport-spec` repository provides comprehensive guidance for both platform builders and developers looking to implement the OAP specification.\n\n**For Platform Builders:**\n1.  **Understand the Specification**: Begin by reading the [OAP v1.0 Specification](https://github.com/aporthq/aport-spec/blob/main/oap/oap-spec.md).\n2.  **Review Examples**: Explore the [examples](https://github.com/aporthq/aport-spec/tree/main/oap/examples) to understand implementation patterns.\n3.  **Validate Implementation**: Utilize the [conformance runner](https://github.com/aporthq/aport-spec/tree/main/conformance) for testing and validation.\n4.  **Integrate with VCs**: Follow the [VC mapping guide](https://github.com/aporthq/aport-spec/blob/main/oap/vc/vc-mapping.md) for Verifiable Credentials integration.\n\n**For Developers:**\n1.  **API Integration**: Use the [OpenAPI spec](https://github.com/aporthq/aport-spec/blob/main/api/openapi-generated.json) for client generation.\n2.  **SDK Implementation**: Follow the [integration guides](https://github.com/aporthq/aport-spec/blob/main/oap/vc/tools/INTEGRATION.md).\n3.  **Policy Development**: Review the [capability registry](https://github.com/aporthq/aport-spec/blob/main/oap/capability-registry.md) for defining agent capabilities.\n\n## Examples\n\nThe repository includes various examples to help developers understand and implement the OAP specification:\n\n*   **Passport Examples**: See [Template Passport](https://github.com/aporthq/aport-spec/blob/main/oap/examples/passport.template.v1.json) and [Instance Passport](https://github.com/aporthq/aport-spec/blob/main/oap/examples/passport.instance.v1.json) for agent identity and capabilities.\n*   **Decision Examples**: Review [Allow Decision](https://github.com/aporthq/aport-spec/blob/main/oap/examples/decision.allow.sample.json) and [Deny Decision](https://github.com/aporthq/aport-spec/blob/main/oap/examples/decision.deny.sample.json) for authorization decisions.\n*   **Verifiable Credentials Examples**: Find [Passport and Decision as VCs](https://github.com/aporthq/aport-spec/tree/main/oap/vc/examples/) to understand VC integration.\n\n## Links\n\n*   [GitHub Repository: aporthq/aport-spec](https://github.com/aporthq/aport-spec)\n*   [OAP v1.0 Specification](https://github.com/aporthq/aport-spec/blob/main/oap/oap-spec.md)\n*   [Main Documentation](https://aport.io/docs/){:target=\"_blank\"}\n*   [Contributing Guide](https://github.com/aporthq/aport-spec/blob/main/CONTRIBUTING.md)\n*   [License](https://github.com/aporthq/aport-spec/blob/main/LICENSE)","metrics":{"detailViews":1,"githubClicks":0},"dates":{"published":null,"modified":"2026-09-18T19:38:56.000Z"}}