Shared credentials
Actor hidden- Owner
- you
- Acted
- you ✕ wrong
Agentic World gives every AI agent its own permanent identity. It signs in to services as itself, on your recorded approval, and never touches your password, API key or session.
“Here are my credentials. Be me.”
“Here is your identity. Act for me, under my rules.”
Install it into Claude Code or Codex, then create your agent. Its key is made on your device's secure chip, and you approve it with your wallet.
Needs Node 22+, a Mac with Secure Enclave or a PC with TPM, and a wallet with Sepolia test ETH.
Setup guide on GitHubnpx agenticworld install
agentic-world:init
agentic-world:create -a "Research"
✓ Research Agent · 0xAGENT · approved on record
$ in your terminal · > in Claude Code or Codex
The agent gets a permanent address on Ethereum and signs in with it. You record, once, that it acts for you. Services check both on their own, and finally see two parties where there used to be one.
The agent's own address. It never changes, even when its keys do.
You write it on-chain yourself. The agent can't forge it or edit it.
Small payments go through alone. Bigger ones wait for your signature.
Every service applies its own rules. Nothing is granted by default.
The identity travels with the agent. The permissions stay with each service.
The agent gets a permanent address. The master key that created it is used at setup and then locked away. The agent never holds it.
For day-to-day sign-ins, the agent gets a separate working key. It can ask a secure key vault to sign with that key, but it can never read the key itself.
You send one transaction that says “this agent acts for me.” Only you can write it, and only you can withdraw it.
It lives in a shared on-chain registry, outside the agent's own account, so the agent can't fake it even by rewriting its own settings.
The service sends a one-time challenge. The agent signs it with its working key. The service asks the agent's account on Ethereum whether that signature is valid right now.
If it is, the agent gets a short login pass, about a minute in the demo, then signs in again.
The service now knows two things: which agent is asking, and who it acts for. It applies its own rules from there.
Your Pro plan at Docs can let the agent read your reports without letting it edit them, touch billing or delete anything.
Access lives with each service, so taking the agent out of one leaves its identity, your account and every other service untouched.
If a working key leaks, you replace it. The old key is refused at its next sign-in. The address and your approval stay the same.
The agent's own account enforces your rules, and anything you haven't allowed is refused. Each limit applies per payment, not as a running budget.
Claude Code and Codex connect through a local connector that keeps the key on your device's secure chip. With your own signer, it's the agent library:
import { createAgentSdk, sessionProofHeaders } from "agentic-world/agent"; const agent = createAgentSdk({ agentId, chainId, signDigest, }); const proof = await agent.answerChallenge( challenge, "https://docs.example", ); await fetch(url, { headers: sessionProofHeaders(proof), });
Keep your database, your plans and your rules. The library checks the agent against Ethereum; you decide what it may do.
import { AgenticWorld } from "agentic-world/service"; const agentic = new AgenticWorld({ client, chainId, audience, challenges, sessions, association: { mode: "owner", resolveUser: owner => db.user.findByWallet(owner), }, }); // guard only the routes you open to agents const requireReport = agentic.middleware({ authorize: ({ user }) => user.report, });
We're not in the sign-in path. Services check the agent against Ethereum themselves, so there's no login server to trust or take down.
ERC-4337 · ERC-7579 · EIP-712 · ERC-1271Its own identity. Your recorded approval. Each service's own rules.
View on GitHub