Playground
Don't take our word for any of it.
Everything below runs in your browser with the Web Crypto API. Real keys, real signatures, real verification — no server involved, and nothing leaves this tab.
Identity
A keypair, a token, and a verification.
The same three operations the CLI performs on first run, in the same order, with the same algorithm.
Generate a keypair
Exactly what the CLI does on first run. The private key stays in this tab's memory and is never written anywhere.
Sign a token
A five-minute JWT, audience-scoped to one service, with the key id in the header so a verifier knows which public key to use.
Verify it — then break it
Verification finds the key by kid, checks the signature, then checks the audience and expiry. Tampering re-points the token at evil.example.com and leaves the signature untouched — valid JSON, wrong signer.
Why this is worth doing
The whole identity protocol rests on one claim: a service can verify an agent knowing nothing but a public key it fetched itself. Signing here and watching a tampered token fail is the shortest way to convince yourself that is true.Services
Check a manifest before you publish it.
Paste your own services.json, or start from one of the examples. Errors are things a conforming client will reject; warnings are things that will make your service unpleasant to use.
Every client on the network can discover and call this service. Each action also needs its own detail file, at a path mirroring its command — for example /.well-known/interagentic/services/orders/create.json.
Every protocol here is a spec you can implement yourself.
There is no gatekeeper. Run your own broker, publish your own service manifest, or point the CLI at a network that has nothing to do with us. The specs are the product.