Skip to content

Latest commit

 

History

5 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

wayid-verify

Verify the WayID of an AI agent at your gateway, reverse proxy, or API backend.

WayID is provenance and trust infrastructure for AI agents — it binds a verified human or business identity to their agents. This SDK lets a relying party answer "what kind of agent is calling me?" in one call, with no user flow and without standing up its own crypto.

This repo hosts the language packages:

  • js/@lineagelabs/wayid-verify (TypeScript / NPM). Express + Cloudflare Worker adapters. See js/README.md.
  • python/wayid-verify (PyPI). FastAPI / Starlette + Flask adapters. See python/README.md.

The Nginx integration lives in its own repo: lineagelabs/wayid-nginx.

npm install @lineagelabs/wayid-verify     # Node / Bun / Cloudflare Workers
pip install wayid-verify                  # Python 3.9+

Install without a registry (straight from GitHub)

The packages aren't on npm / PyPI yet — until they are, install them directly from this repo.

Python installs from the repo subdirectory in one step (it's pure-stdlib, zero deps):

pip install "git+https://github.com/LineageLabs/wayid-verify.git#subdirectory=python"

JavaScript can't be npm installed from a git subdirectory, so each tagged release attaches a packed tarball you can install from its URL (no registry, no clone):

npm install https://github.com/LineageLabs/wayid-verify/releases/download/js-v0.1.0/lineagelabs-wayid-verify-0.1.0.tgz

Or build it from a clone:

git clone https://github.com/LineageLabs/wayid-verify.git
cd wayid-verify/js && npm install && npm run build
npm install /abs/path/to/wayid-verify/js   # from your project

How it works (v1 — passive)

An agent declares its identity with a request header:

WayID: wayid:agent:{24-char-base58}      # full DID or the bare 24-char tail

The gateway extracts the header, resolves it via the public GET {issuer}/api/v1/agent/{did} endpoint, caches the result, and applies a policy. By default the SDK fails open — a verifier outage or unknown DID never blocks traffic; the request is served and tagged unknown.

Identification, not authentication. The v1 WayID header is self-asserted: it proves the named DID exists and is owner-verified, not that the caller holds the agent's private key. That is the right tool for attribution. Cryptographic proof-of-possession is a planned v2 layer built on Web Bot Auth / RFC 9421 HTTP Message Signatures.

Status

Prototype for WayID issue #373. The canonical wire contract lives in the way-id repo: .specs/product-spec.md §4.6 and .specs/tech-spec.md §5.5.

Releasing

Both packages are publish-ready (tag-driven GitHub Actions) but not yet published — see PUBLISHING.md for the npm / PyPI setup and release steps.

License

MIT © Lineage Labs — see LICENSE.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages