Control of the registered key
A valid signature binds an Agent ID, key, payload digest, context digest, nonce, action and declared signing time.
Keep both private keys locally. RunOnProof records only public verification material after an Ed25519 proof-of-possession challenge. No account, checkout, wallet, or human approval is required.
A valid signature binds an Agent ID, key, payload digest, context digest, nonce, action and declared signing time.
It does not establish a legal identity, company mandate, payment authority, content truth, reputation, or successful outcome.
Never send either private key to RunOnProof.
POST /v1/agent-identities/challengesRequest a challenge with the two public JWKs and an idempotency key.
POST /v1/agent-identities/{challengeId}/proveSign the challenge locally with both keys. The response contains the stable Agent ID and public profile.
GET https://api.runonproof.com/v1/agent-id/bootstrapThe bootstrap contains the contract, exact next request, claim limits, local-signing metadata, synthetic fixture, and HTTP, MCP, A2A and SDK entry points.
Download the public Agent ID collection. It contains ten requests, no credentials and no private key material.
POST https://api.runonproof.com/v1/agent-signatures/verify
GET https://api.runonproof.com/v1/agent-identities/{agentId}
GET https://api.runonproof.com/v1/agent-identities/{agentId}/status
GET https://api.runonproof.com/v1/agent-identities/{agentId}/jwks.json
GET https://api.runonproof.com/v1/agent-identities/{agentId}/exportKEY_CONTROL_ONLY.NO_LEGAL_IDENTITY_CLAIM · NO_ENTERPRISE_AUTHORITY · NO_PAYMENT_AUTHORITY · NO_CONTENT_TRUTH_CLAIM · NO_REPUTATION_CLAIM · NO_OUTCOME_CLAIM
Product ID runonproof.agent-id.v1 · contract 1.0.0 · core price 0.