Your agent needs an identity, not your API keys.
Interagentic is four open protocols for software that runs unattended. A namespace it proves with a keypair. Any API it can discover and call. Credentials it never holds. A budget you approve.
No account. No dashboard. No API key to copy.
$npx interagentic init✓ Ed25519 keypair written to ~/.interagentic/✓ namespace registered — brave-fox-a3f2 identity interagentic://id.interagentic.dev/brave-fox-a3f2 $npx interagentic curl https://api.example.com/v1/orders signed key_V1StGXR8 · exp 5m verified via /.well-known/interagentic/jwks.json 200 OK — 14 ordersThe protocols
Four problems an unattended process runs into.
Each one is a small, separately adoptable protocol. Implement the one you need and ignore the rest — nothing here requires the others.
Identity
An agent claims a namespace, keeps the private key, and publishes the public one. Any server verifies its tokens against a JWKS it fetches itself. No shared secret, no registration on your side.
The agent's identity, in full
interagentic://id.interagentic.dev/brave-fox-a3f2
Services
Publish two static JSON files describing what your API can do. Every Interagentic client can then discover and call it — with help, types and examples — without you writing an SDK.
Discover and call any compatible API
$ npx interagentic example.com orders list
$ npx interagentic example.com orders ship --id 42
Credits
A service answers 402 when work costs money. The agent hands its human a link, the human sets a budget once, and the agent gets on with it. Prepaid access to curated services — not a currency.
Payment required, human decides
HTTP/1.1 402 Payment Required
X-Payment: interagentic-credit; amount=2.50
Secure calls
Ask for an outcome with a provider action, or write the HTTP request yourself. Either way a proxy adds the credential in transit, after a human connected the account — the agent never sees a key, so a prompt injection has nothing to steal.
Two ways in, one proxy
$ npx interagentic providers gmail messages list
$ npx interagentic curl … -H "Authorization: Bearer {{OAUTH2_ACCESS_TOKEN}}"
How it works
Three commands, and a human only when it matters.
The agent runs on its own until it hits something that genuinely needs a person. Then it hands over a link and waits.
Claim a namespace
First come, first served, like a domain. The private key is generated on the machine and never leaves it — the broker only ever sees the public half and a signature proving you hold the other one.
$npx interagentic init acme-worker→ challenge issued, signing…✓ acme-worker · key_V1StGXR8 · EdDSACall things
A compatible API verifies the agent's signature itself, against a JWKS it fetches directly. Everything else goes through the credential proxy, where the real secret is substituted at call time and never reaches your process.
$npx interagentic mongo \ databases create --slug orders✓ orders — ready in 4.1s MONGODB_URI written to .envEscalate to a human
When a call needs a person — a connected account, a spending limit, a permission — the agent gets a link instead of a dead end. The human decides once, and every later call just works.
$npx interagentic curl \ https://api.stripe.com/v1/charges403 — connect Stripe to continueid.interagentic.dev/link/9f2c…Worked examples
Four things this actually does.
Real commands and real payloads. Every response shape on this page is the one the protocol specifies.
# the agent has never signed up for anything$npx interagentic extraorbital add mongo --slug orders provisioning…✓ mongo/orders — 512 MB, free allowance MONGODB_URI appended to .env $npx interagentic extraorbital ls mongo orders active 0 / 512 MB s3 assets active 0 / 1 GBMONGODB_URI=mongodb+srv://orders:…@c0.interagentic.dev/orders
S3_BUCKET=assets-8f2a
S3_ENDPOINT=https://s3.interagentic.dev
S3_ACCESS_KEY_ID=IA3E…
S3_SECRET_ACCESS_KEY=…Credentials land where your code already looks for them. Nothing is printed to a dashboard you then have to copy from.
# the agent writes a placeholder, never a secret$npx interagentic curl https://api.github.com/user/repos \ -H "Authorization: Bearer {{OAUTH2_ACCESS_TOKEN}}"403 permission_denied — github.com::repo Ask your human to connect it: https://id.interagentic.dev/link/9f2c… # …human clicks, approves, and you re-run$npx interagentic curl https://api.github.com/user/repos200 OK — 42 repositories{
"error": "permission_denied",
"authorizationUrl": "https://id.interagentic.dev/link/9f2c…",
"missingScopes": [
{ "provider": "github.com", "scopes": ["repo"] }
]
}A refusal is machine-readable. The agent is told exactly which scopes are missing and where a human can grant them — so it can wait instead of guessing.
# you already have an API. describe it once.$curl https://popcorn.club/.well-known/interagentic/services.json Popcorn Club · 6 actions · auth: interagentic # every agent on the network can now do this$npx interagentic popcorn.club orders list List your orders create Place an order [$] ship Mark an order as shipped $npx interagentic popcorn.club orders create --qty 2✓ ord_8fJ2 — 2 × Classic, $9.00{
"name": "Popcorn Club",
"auth": "interagentic",
"baseUrl": "/api/v1",
"groups": [
{ "command": ["orders"], "description": "Place and track orders" }
],
"actions": [
{
"command": ["orders", "create"],
"endpoint": "/orders",
"method": "POST",
"description": "Place an order",
"payment": "fixed"
}
]
}Commands are declared as arrays, so a chain of any depth is just a longer array. Your handlers, routes and auth stay exactly as they are.
# your API decides this call costs money$npx interagentic popcorn.club orders create --qty 2402 Payment Required — 9.00 credits Your human can approve a budget here: https://id.interagentic.dev/approve/4c7e… # human sets a $50 monthly cap, once$npx interagentic popcorn.club orders create --qty 2✓ ord_8fJ2 — 9.00 credits · 41.00 remainingHTTP/1.1 402 Payment Required
X-Payment: interagentic-credit; amount=9.00
Link: <https://id.interagentic.dev/approve/4c7e…>; rel="approve"
{
"error": "payment_required",
"amount": "9.00",
"asset": "interagentic-credit",
"description": "2 × Classic popcorn"
}Credits are prepaid access to services The Interagentic Company resells — a closed loop with a single issuer. They are not a currency and cannot be transferred or cashed out.
Every protocol here is a spec you can implement yourself.
There is no gatekeeper. Run your own broker, publish your own service manifest, or point the CLI at a network that has nothing to do with us. The specs are the product.