Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
authproof-sdk — Cryptographically signed delegation receipts for AI agents. Define exactly what an AI can and can't do — signed, verifiable, tamper-proof. | Kitploit
Tools/GitHubGitHub/commonguy25/authproof-sdk
Authentication & AuthorizationCryptographyIdentity & Access Management (IAM)Supply Chain SecurityAPI SecurityAI Security
GitHubcommonguy25/authproof-sdk

authproof-sdk

Cryptographically signed delegation receipts for AI agents. Define exactly what an AI can and can't do — signed, verifiable, tamper-proof.

View Repository
6203 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

AuthProof SDK

AuthProof is a cryptographic delegation protocol for agentic AI. Most protocols in this space enforce against an operator-defined policy -- giving the operator authority to expand or reinterpret the user's original intent after the fact. AuthProof is built around a different trust model: the user's own private key signs the authorization object that gates execution, and the live model state is verified at both authorization time and immediately before execution. The combination of user-signed authority and live model-state gating is the specific claim -- not a broad enforcement story.

What makes it different:

  • The user is the signing authority. Every competing protocol (AIP, AITH, OAP, SAGA, AgentSpec) enforces against a policy the operator defines. In AuthProof, the user's private key signs the authorization object directly. The operator cannot widen scope after the user has signed.

  • Two-phase model-state commitment. The model is measured at authorization time and re-measured immediately before execution. If the model has drifted between those two points, execution is blocked at pre-execution verification.

  • Provider update versus malicious substitution, distinguished. The protocol classifies model-state changes into two categories: legitimate provider updates (PROVIDER_UPDATE_REQUIRES_REAUTH) and unauthorized swaps (MALICIOUS_MODEL_SUBSTITUTION). Each produces a machine-readable denial reason code identifying which components changed.

Pre-Execution Verifier

The deterministic gate that runs before any agent action executes.

The PreExecutionVerifier sits outside the agent runtime. The runtime never gets control until the verifier passes. A compromised or malicious agent cannot skip it — it runs before the runtime starts.

Why it matters

Traditional authorization checks happen inside the agent runtime. If the runtime is compromised, those checks can be skipped, reordered, or bypassed. PreExecutionVerifier eliminates this attack surface by moving authorization outside the runtime entirely. The agent only executes if — and only if — all six sequential checks pass first.

Quickstart

import { PreExecutionVerifier, DelegationLog } from 'authproof-sdk/pre-execution-verifier'
import { RevocationRegistry } from 'authproof-sdk'

// 1. Set up the gate
const delegationLog      = new DelegationLog()
const revocationRegistry = new RevocationRegistry()
await revocationRegistry.init({ privateKey, publicJwk })

const verifier = new PreExecutionVerifier({ delegationLog, revocationRegistry })
await verifier.init({ privateKey: verifierKey, publicJwk: verifierPub })

// 2. Register your delegation receipt
delegationLog.add(receiptHash, receipt)

// 3. Gate every action — before the agent runs
const result = await verifier.check({
  receiptHash,
  action:               { operation: 'read', resource: 'calendar' },
  operatorInstructions: 'Summarize meetings. Stay within scope.',
  programHash,          // optional: prevents code substitution attacks
})

if (!result.allowed) {
  throw new Error(`Blocked: ${result.blockedReason}`)
}
// Agent runtime only reaches here after all six checks pass

Six sequential checks (stops at first failure)

#CheckBlocks when
1Receipt signatureECDSA P-256 signature invalid or receipt tampered
2RevocationReceipt has been revoked via RevocationRegistry
3Time windowReceipt expired or not yet valid (log timestamp oracle, not client clock)
4ScopeAction not in ScopeSchema.allowedActions or fails text-based scope matching
5Operator instructionsCurrent instructions don't match the hash locked into the receipt at issuance
6Program hashProvided programHash doesn't match the committed executes hash (code substitution prevention)

Every check result — pass or fail — is automatically logged to an immutable ActionLog signed with the verifier's own key.

Middleware integrations

Drop-in wrappers for common frameworks. Each wrapper gates every call through PreExecutionVerifier before the wrapped code executes.

  • LangChain — wraps any agent with an invoke() method
  • Express/HTTP — request middleware for any Express-compatible framework
  • Generic function wrapper — wraps any async function
// LangChain
import { authproofMiddleware } from 'authproof-sdk/middleware/langchain'
const guardedAgent = authproofMiddleware(agent, { receiptHash, verifier })

// Express
import { authproofMiddleware } from 'authproof-sdk/middleware/express'
app.use(authproofMiddleware({ verifier, getReceiptHash: (req) => req.headers['x-receipt-hash'] }))

// Any function
import { guardFunction } from 'authproof-sdk/middleware/generic'
const guardedExecute = guardFunction(executeAction, { receiptHash, verifier, action })

The Problem

Every existing IETF framework for agent identity — AIP, draft-klrc-aiagent-auth, WIMSE — addresses service-to-agent trust: how a downstream service verifies that an agent is authorized to call it. None of them address user-to-operator trust.

The delegation chain in current agentic systems is:

User → Operator → Agent → Services

The user instructs the operator. The operator instructs the agent. But no cryptographic record of the user's original intent exists at the moment of delegation. The operator becomes a trusted third party with unchecked authority to expand, distort, or omit the user's instructions before they reach the agent.

The consequences:

  • Users cannot prove what they authorized.
  • Regulators have no audit trail.
  • Courts have no evidence chain.
  • Agents cannot distinguish legitimate operator instructions from compromised or rogue ones.

AuthProof fills this gap.


The Core Primitive: Delegation Receipt

A Delegation Receipt is a signed Authorization Object anchored to a decentralized append-only log before any agent action begins. It contains four required fields:

Scope

An explicit allowlist of permitted operations. Everything not listed is denied by default. Expressed in structured format — not natural language. Operation classes:

ClassDescription
readsRead access to specified resources
writesWrite access to specified resources
deletesDeletion of specified resources
executesExecution of a specific program, referenced by its static capability signature hash

executes is the most dangerous class. It must reference the cryptographic hash of a Safescript program's static capability DAG — not a name, URI, or description. No hash match means no execution.

Boundaries

Explicit prohibitions that cannot be overridden by operator instructions under any circumstances. User-defined hard limits that survive any subsequent operator instruction.

Time Window

Validity period of the authorization. The log timestamp is the time oracle — not the client clock. Client clocks are explicitly excluded from time validation.

Operator Instruction Hash

A cryptographic hash of the operator's stated instructions at delegation time. If the operator subsequently instructs the agent differently, the discrepancy is detectable from the log without any additional trust assumptions.

Download Tool