zeroid
View on GitHubHighflame ZeroID: Autonomous Agent Identity Management System (AAIMS)
ZeroID is a Go-based identity server giving autonomous AI agents their own credentials: OAuth 2.1 issuance, RFC 8693 on-behalf-of delegation with scope attenuation, SPIFFE/WIMSE identities, DPoP, attestation, and cascade revocation for agent chains and MCP servers.
Use Cases
Issue short-lived per-agent credentials for autonomous AI agentsDelegated authority between orchestration agents and sub-agents with scope attenuationAuthenticate MCP servers and tool agents calling APIsCryptographic on-behalf-of audit trails for agent actionsReal-time cascade revocation of agent credential chainsAttestation-based trust elevation (GitHub Actions, GCP, Kubernetes SA tokens)Sender-constrained DPoP tokens for agent-to-service callsHuman-in-the-loop backchannel approval of agent actions via CIBA
Built With
- Language
- Go
- Frameworks
- OAuth 2.1 · RFC 8693 Token Exchange · SPIFFE · WIMSE · RFC 9449 DPoP · OpenID CIBA · RFC 7591 DCR · RFC 9396 RAR · OpenID SSF/CAE · MCP Authorization · chi · huma · jwx · Bun · PostgreSQL · OpenTelemetry
Tags
agent-identity · authentication · oauth2 · delegation · mcp · spiffe · wimse · dpop · token-exchange · ciba · attestation · revocation · nhi · zero-trust · golang · jwt