Rider already does
Who
A short-lived signed credential. L0–L4. Operator, agent id, scopes. Issued at agentrider.fly.dev.
Agent stack · pairs with Rider · $29 / mo · $290 / yr
Agent-Rider is signed identity: which agent acted. That is not an audit trail by itself. Warrant is the other half — a signed mandate (hosts, actions, spend cap, expiry) bound to that Rider, then a receipt when the action happens. Gates check both headers: X-Agent-Rider and X-Agent-Warrant.
Rider already does
A short-lived signed credential. L0–L4. Operator, agent id, scopes. Issued at agentrider.fly.dev.
Warrant adds
Allow these hosts. These actions (spend, fetch, publish, compress, invoke). This many calls. This many dollars. Then it expires or you revoke it.
Then
After the job: host, action, hashes of request and result, dollars used. Remaining budget ticks down. Quiet agents are Rider Ops. Overreach is Warrant.
Mint identity with a Rider seat, then attach a Warrant. Dual license: AGPL-3.0-or-later, or a Warrant seat for closed shipping. Ops watches silence. Warrant files the work.
Verify is free. Issuing and filing receipts: first 3 issues and 10 receipts per operator per day are free. Above that, a Warrant seat.
Month $29 Year $290 Open Agent-Rider
This issues a 10-minute demo warrant (no Rider required) so you can see the token and a receipt. Real jobs send a live X-Agent-Rider instead of demo.
No warrant yet.
POST /api/warrant/issue — header X-Agent-Rider, body { actions, allow_hosts, max_usd, max_calls, ttl_seconds }. Or { "demo": true }.
POST /api/warrant/verify — header X-Agent-Warrant, optional { host, action }.
POST /api/warrant/receipt — same header, body { action, host, usd, request_sha256, result_sha256 }.
GET /api/warrant — discovery. GET /api/warrant?id=wrt_… — public record.