
Cryptographically signed delegation receipts for AI agents. Define exactly what an AI can and can't do — signed, verifiable, tamper-proof.
AuthProof is a cryptographic delegation protocol for agentic AI. Most protocols in this space enforce against an operator-defined policy -- giving the operator authority to expand or reinterpret the user's original intent after the fact. AuthProof is built around a different trust model: the user's own private key signs the authorization object that gates execution, and the live model state is verified at both authorization time and immediately before execution. The combination of user-signed authority and live model-state gating is the specific claim -- not a broad enforcement story.
What makes it different:
The user is the signing authority. Every competing protocol (AIP, AITH, OAP, SAGA, AgentSpec) enforces against a policy the operator defines. In AuthProof, the user's private key signs the authorization object directly. The operator cannot widen scope after the user has signed.
Two-phase model-state commitment. The model is measured at authorization time and re-measured immediately before execution. If the model has drifted between those two points, execution is blocked at pre-execution verification.
Provider update versus malicious substitution, distinguished. The protocol classifies model-state changes into two categories: legitimate provider updates (PROVIDER_UPDATE_REQUIRES_REAUTH) and unauthorized swaps (MALICIOUS_MODEL_SUBSTITUTION). Each produces a machine-readable denial reason code identifying which components changed.
The deterministic gate that runs before any agent action executes.
The PreExecutionVerifier sits outside the agent runtime. The runtime never gets control until the verifier passes. A compromised or malicious agent cannot skip it â it runs before the runtime starts.
Traditional authorization checks happen inside the agent runtime. If the runtime is compromised, those checks can be skipped, reordered, or bypassed. PreExecutionVerifier eliminates this attack surface by moving authorization outside the runtime entirely. The agent only executes if â and only if â all six sequential checks pass first.
import { PreExecutionVerifier, DelegationLog } from 'authproof-sdk/pre-execution-verifier'
import { RevocationRegistry } from 'authproof-sdk'
// 1. Set up the gate
const delegationLog = new DelegationLog()
const revocationRegistry = new RevocationRegistry()
await revocationRegistry.init({ privateKey, publicJwk })
const verifier = new PreExecutionVerifier({ delegationLog, revocationRegistry })
await verifier.init({ privateKey: verifierKey, publicJwk: verifierPub })
// 2. Register your delegation receipt
delegationLog.add(receiptHash, receipt)
// 3. Gate every action â before the agent runs
const result = await verifier.check({
receiptHash,
action: { operation: 'read', resource: 'calendar' },
operatorInstructions: 'Summarize meetings. Stay within scope.',
programHash, // optional: prevents code substitution attacks
})
if (!result.allowed) {
throw new Error(`Blocked: ${result.blockedReason}`)
}
// Agent runtime only reaches here after all six checks pass
| # | Check | Blocks when |
|---|---|---|
| 1 | Receipt signature | ECDSA P-256 signature invalid or receipt tampered |
| 2 | Revocation | Receipt has been revoked via RevocationRegistry |
| 3 | Time window | Receipt expired or not yet valid (log timestamp oracle, not client clock) |
| 4 | Scope | Action not in ScopeSchema.allowedActions or fails text-based scope matching |
| 5 | Operator instructions | Current instructions don't match the hash locked into the receipt at issuance |
| 6 | Program hash | Provided programHash doesn't match the committed executes hash (code substitution prevention) |
Every check result â pass or fail â is automatically logged to an immutable ActionLog signed with the verifier's own key.
Drop-in wrappers for common frameworks. Each wrapper gates every call through PreExecutionVerifier before the wrapped code executes.
invoke() method// LangChain
import { authproofMiddleware } from 'authproof-sdk/middleware/langchain'
const guardedAgent = authproofMiddleware(agent, { receiptHash, verifier })
// Express
import { authproofMiddleware } from 'authproof-sdk/middleware/express'
app.use(authproofMiddleware({ verifier, getReceiptHash: (req) => req.headers['x-receipt-hash'] }))
// Any function
import { guardFunction } from 'authproof-sdk/middleware/generic'
const guardedExecute = guardFunction(executeAction, { receiptHash, verifier, action })
Every existing IETF framework for agent identity â AIP, draft-klrc-aiagent-auth, WIMSE â addresses service-to-agent trust: how a downstream service verifies that an agent is authorized to call it. None of them address user-to-operator trust.
The delegation chain in current agentic systems is:
User â Operator â Agent â Services
The user instructs the operator. The operator instructs the agent. But no cryptographic record of the user's original intent exists at the moment of delegation. The operator becomes a trusted third party with unchecked authority to expand, distort, or omit the user's instructions before they reach the agent.
The consequences:
AuthProof fills this gap.
A Delegation Receipt is a signed Authorization Object anchored to a decentralized append-only log before any agent action begins. It contains four required fields:
An explicit allowlist of permitted operations. Everything not listed is denied by default. Expressed in structured format â not natural language. Operation classes:
| Class | Description |
|---|---|
reads | Read access to specified resources |
writes | Write access to specified resources |
deletes | Deletion of specified resources |
executes | Execution of a specific program, referenced by its static capability signature hash |
executes is the most dangerous class. It must reference the cryptographic hash of a Safescript program's static capability DAG â not a name, URI, or description. No hash match means no execution.
Explicit prohibitions that cannot be overridden by operator instructions under any circumstances. User-defined hard limits that survive any subsequent operator instruction.
Validity period of the authorization. The log timestamp is the time oracle â not the client clock. Client clocks are explicitly excluded from time validation.
A cryptographic hash of the operator's stated instructions at delegation time. If the operator subsequently instructs the agent differently, the discrepancy is detectable from the log without any additional trust assumptions.