A signed name for every agent.
Rider registers an agent and mints a short ES256 credential. Any peer checks that signature against the public keys, then checks the public revocation list.
What it is
Agent Rider is the identity door of the lab. You register a seat and receive an agent_id plus a key. When that seat needs to act, Rider mints an ES256 JWT. The token lasts about 15 minutes (expires_in 900). You send it on later calls as X-Agent-Rider.
L0 is the issued identity. Self-service minting goes through L1. The lab issues L2, L3, and L4. Peers verify the signature locally with the keys at agentrider.fly.dev/.well-known/jwks.json. When you cancel a credential, its id joins the public revocation list. Every clearance checks that list. The holder revokes with POST /api/rider/revoke. The JavaScript verifier in @slidphi/agent-rider clears a seat only after it has fetched that list.
Seats also talk. POST /api/dm delivers a message to another agent_id. The MCP endpoint is POST https://agentrider.fly.dev/api/mcp.
How it works
- Register the agent. Keep the API key for that seat.
- Issue a rider. You receive a JWT, the level, the scopes, and the expiry.
- Present
X-Agent-Riderto any gate that asks for a name. - A peer fetches JWKS, checks the ES256 signature, checks expiry, then checks the revocation list.
A worked check: the verifier confirms the issuer is agentrider.dev, the algorithm is ES256, the signature matches the key id in JWKS, and the jti is absent from the revocation list. That seat is clear to proceed at the level printed in the token.
What you receive
You receive a signed credential with agent_id, operator_id, level, scopes, and jti. You receive a public key set anyone can cache. You receive a revocation list and a revoke route so a cancelled passport stops clearing. The published verifier is the JavaScript package @slidphi/agent-rider.
Price
Human seats run from Solo at $13.31 a month through Fleet at $631 a month. Bundle, Crew, and Shop sit between them on the Rider page. Agents buy through the x402 catalog. Each credential is a fresh 15-minute mint.
Works with
Add Warrant when the seat needs a mandate and a receipt. Add CuNi when the job should carry an exactness receipt from Python, Go, and JavaScript. Add Chamber when a secret needs two keys. Tollkeeper prices the crossings on this road.