You're pledging to donate if the project hits its minimum goal and gets approved. If not, your funds will be returned.
AI agents already do things, not just say things. They write code, move money, and change production systems on behalf of people and companies.
So three questions matter: who authorized this, what was the agent allowed to do, and did the action match. Today the same operator usually writes the policy, runs the agent and produces the log. Everyone grades their own exam.
I built the Agent Passport System to fix that. Open, Apache 2.0. Agents get cryptographic identities tied to the person behind them. Delegated authority can only shrink as it passes along, never grow. Allowed actions produce a signed receipt. Denied actions produce signed evidence of the denial, so a refusal leaves a trace instead of silence.
A third party can check that evidence without trusting the system that produced it. That is the whole point.
Turn APS from something I built into something other people can verify without taking my word for it.
1. Attack my own claim. APS says authority can only narrow at each step. That is true locally. Whether a long chain of correct steps is safe end to end, I don't know. I'll build the adversarial tests that find out and publish the answer either way.
2. Get the conformance suite out of my hands, into the Agent Authority Conformance lab at LF Decentralized Trust, with a second committer who isn't me.
3. Push the Internet-Draft through more revisions under hostile review, with the review comments published alongside.
4. Ship cross language test vectors so two implementations either match byte for byte or they don't.
Done means someone else verifies an implementation using shared vectors and I'm not in the loop.
It buys time. APS currently competes with paid work for my hours and the standards and conformance work is what loses.
Most of it is my stipend for full time work. The rest covers hosting and CI, model API costs for the adversarial testing, one standards meeting and paying two outside contributors so the conformance suite stops being a one person artifact. At the top of the range I'd add an independent security review, because right now those claims rest on my own word
Solo. That's the weakness, and it's why a second committer is a funded deliverable rather than a hope.
Started February 2026. Since then: TypeScript and Python SDKs, an MCP server, delegation verification, signed receipts, a conformance suite, a reference gateway and an individual Internet Draft (draft-pidlisnyi-aps, not a working group document).
The work went outward instead of staying in my repos. 26 of my contributions merged into other people's projects. Another 20 merged PRs were written by other maintainers and carry my contributions inside them. 68 merges came back the other way. I've reviewed 59 pull requests
- goose, the Agentic AI Foundation's agent runtime, 52,000+ stars. I proposed and implemented a hook change so a denied tool call leaves an audit record instead of vanishing. Issue and PR both open.
- Microsoft Agent Governance Toolkit: three merges, all by the toolkit's creator.
- OWASP Agentic Skills Top 10: merged by the project leader.
- LF Decentralized Trust merged the proposal establishing the Agent Authority Conformance lab on 31 July 2026.
Five independent papers cite the protocol, including one from UBC. I've published nine of my own with DOIs.
Before this I founded and scaled products, including one to $3M ARR. This one is deliberately not a product.
Project remains a single maintainer project and does not achieve enough independent adoption.
If that happens, the code and research will still remain publicly available, but the protocol may not become a shared standard.
Another risk is that the security model does not hold under more complex multi agent scenarios. Finding those limitations is also valuable, because it is better to discover them early through open testing than after widespread adoption.
$0, entirely self funded.
There are no bids on this project.