Identity Engine
Issues each agent a verifiable, self-certifying DID and proves control of its key — the root every other engine trusts.
What it does
The Identity Engine gives every agent a persistent, verifiable, self-certifying DID — did:hedera anchored on an HCS registry, or a self-certifying did:key you bring yourself. It proves the agent controls its own key (verify-key / proof-of-possession), resolves any DID through a public resolver, and is the identity root every other engine trusts.
Inside Identity Engine
The core functions this engine provides across the Trust Fabric.
Identity Engine composes with the Trust Fabric
Every engine is independently useful and interoperates through one API-first Trust Fabric — so identity, evidence, policy, risk and certification stay consistent across your AI estate.
Related engines
Ownership & Delegation
Binds an agent to its owner and to a VC-issued mandate — with instant revocation.
- Verified principal (KYC/KYB), or a disclosed free-tier allowance
- VC-issued mandate (scope, caps, merchants)
- Resource scope — which systems and data
- Sub-delegation that can only narrow
- Delegated issuance
Agent Passport
A signed, portable snapshot of an agent's identity, ownership, declared purpose and current capabilities — composed from data the platform already tracks.
- Signed identity + capability snapshot
- Composed from existing identity/version/assurance data
- Independently revocable from containment
- Reissued as the agent's profile changes
Credential Authority
Issues, presents and verifies W3C Verifiable Credentials — with selective disclosure and on-chain anchoring.
- Verifiable Credentials (identity, entity, mandate)
- BBS selective disclosure
- Ed25519 platform issuer
- Anchoring & revocation
See Identity Engine in action
Book a demo and see how the platform establishes trust across your AI systems.
