Steward of open protocols and cryptographic standards for autonomous AI agents.
We build the trust infrastructure that enables secure, verifiable agent-to-agent boundaries. Our mission is to establish decentralized trust boundaries that protect environments from unauthorized agent access while letting verified agents collaborate securely.
Our core repositories, client verifiers, and SDKs are now open to the public:
- creduent — Core specification documents (CREDUENT-001 to CREDUENT-006), schemas, and the reference registry server implementation.
- creduent-js — JavaScript and TypeScript client SDK for verifying agent signatures in Node.js/web applications.
- creduent-python — Native Python client SDK for agent trust verification.
- creduent-cli — Developer CLI tool to initialize, sign, and verify
agent.jsonconfigurations.
- IdentaBar — The reference verification client suite, containing the Manifest V3 browser extension and the VS Code desktop IDE extension.
- Cryptographic Agent Identity: Establishing verifiable, host-independent identities using signatures over canonical records.
- Domain Ownership Binding: Verifying the controllers of AI agents via cryptographic DNS validation.
- Workflow Verification: Client verifier suites for browser and editor environments to inspect agent tasks in real-time.
IDevSec was founded by Kashish Kanojia (known online as CyberFascinate), a security researcher and practitioner.
"The security model of the web was designed for human-initiated browser sessions. But as autonomous agents begin handling transactions, generating code, and managing API workflows, we need a new trust model built for machine-speed interactions.
When agents have the authority to act, verifying their identity is the first line of defense. We built the Creduent Protocol to provide simple, cryptographic verification of who controls an agent and what it is authorized to do. Let's build the infrastructure that lets autonomous systems interact safely and reliably."
— Kashish Kanojia, Founder & CEO, IDevSec
To report vulnerability findings, refer to our security policy or email security@idevsec.com. For general operations, contact hello@idevsec.com.