ID MCP

Your AI acts for you. It never becomes you.

ID MCP is an open identity layer for AI agents: one identity you own, limited permissions you grant, and a signed record of everything they do.

How it works

Four steps between you and any AI you use, in Claude, GPT, Gemini or anything that speaks MCP.

You hold the root key

Created from a seed phrase and kept away from the machine where the AI runs.

You grant a permission

A delegation names the scopes, the service and the expiry. One hour, one task, one site.

The AI gets a sub-key

It can only act inside that delegation. Every request is written to a signed log first.

The service verifies

Signature, scope, audience, freshness and revocation are checked. You can cancel any time.

Built for the agent era

Today each AI tool locks you into its own account. This is a different model.

You own the identity

No email, no phone number, no platform that can delete you. The identity is a key you hold.

Scoped and short-lived

Permissions are named, bound to a service and expire within 24 hours by policy.

Revocable

Signed revocations cancel a delegation. A broken revocation list stops signing instead of being ignored.

Audit trail

Each signing request lands in a hash-chained log before anything is signed. If logging fails, nothing is signed.

Hybrid post-quantum

Ed25519 together with ML-DSA. Both signatures must verify, so one broken algorithm is not enough.

Made for MCP and A2A

An identity layer for the agent protocols that already exist, not a replacement for them.

What an AI can and cannot do

Designed so a compromised agent has a small, time-limited blast radius.

It can

  • Sign a request inside the scopes you granted
  • Prove who it is acting for
  • Ask you for more permission

It cannot

  • Sign arbitrary data
  • Approve its own permission request
  • Outlive the expiry you set or ignore a revocation

Status

Open and early.

Early prototype. The specification is a draft and the cryptography library used for ML-DSA has not been independently audited. Do not use this to protect anything of real value. It does not stop prompt injection that misuses a permission you granted, or a person approving blindly.