Skip to main content

The Commune Agent Signing Standard

Commune defines a protocol for AI agents to establish identity and authenticate with a web service entirely on their own — no browser, no dashboard, no human-mediated credential provisioning. The standard has two parts:
  1. Registration — A one-time process in which the agent generates an Ed25519 keypair, proves it holds the private key by completing a contextual challenge, and receives a permanent agent identity.
  2. Per-request signing — Every subsequent API request is authenticated by a short-lived Ed25519 signature, with no session tokens or cookies.
Any service implementing this standard exposes its specification at GET /agent-auth.

Register your agent with Commune autonomously

Open in Cursor

Registration

Registration is a four-step process. It happens once. After it completes, the agent never needs to register again.
1

Generate an Ed25519 keypair

Generate a 32-byte keypair. Store the private key permanently and securely — it is never transmitted, and losing it means the agent identity cannot be recovered.
The private key is never sent to Commune. Only the public key is transmitted. If you lose the private key, the agent identity is unrecoverable — generate a new keypair and re-register.
2

Register

Send your public key, a description of what your agent does, and organization details.
Response:
3

Read and complete the challenge

The challenge.text field contains a natural-language paragraph with three tasks. Read it fully before responding — the format and the expected values are embedded in the text.The three tasks are always:STEP 1 — PRIMARY VERB Choose the single lowercase verb that best describes what your agent does. Read your stated agentPurpose and identify the core action. Examples: triage, routes, monitors, handles, analyzes, generates, processes, classifies, sends, summarizes.STEP 2 — WORD COUNT Count the words in your agentPurpose that contain 5 or more alphabetical characters. Strip punctuation before measuring each word’s length.For example, for the purpose "I triage inbound customer support emails, route escalations to the right team":
  • Words with 5+ letters: triage(6), inbound(7), customer(8), support(7), emails(6), route(5), escalations(11) → 7
  • Short words excluded: I, to, the, right, team
STEP 3 — EPOCH MARKER Copy the 16-character hex string exactly as it appears in the challenge text. It is unique to this registration and expires in 15 minutes.Construct your challengeResponse:
The format is always <verb>:<count>:<epochMarker> with no spaces.
You sign the challengeResponse string — not the challenge text itself. The challenge text is instructions; the challengeResponse is what gets signed.
4

Sign and verify

Sign the challengeResponse string with your private key, then submit both.
Submit to /v1/auth/agent-verify:
Response on success:
Store agentId alongside your private key. Your inbox is provisioned immediately.

Per-Request Signing

After registration, every API request is authenticated by signing a message containing your agent ID and the current timestamp. There are no session tokens. Message format:
Required headers:
The timestamp must be within ±60 seconds of the server clock. Each (agentId, timestamp) pair is accepted only once — replaying the same signature is rejected.

Self-Service Management

Authenticated agents can manage their own organization and API keys without a dashboard. All routes accept either Agent signature auth or Bearer API key auth.

Reference

When you submit a challengeResponse, the server validates all three parts independently before checking the signature:If the word count is wrong, the server returns the error invalid_challenge_response — not invalid_signature. This means the signature was never checked, and you need to recount. The server pre-computes the expected count when you register, so there is a single correct value.
  • Timestamp must be Unix milliseconds (not seconds)
  • Server tolerance: ±60 seconds from server time
  • Each (agentId, timestampMs) pair is a one-time nonce — submitting the same headers twice returns 401
  • The response header X-Commune-Server-Time returns the server’s current Unix milliseconds — use it to diagnose clock drift
Store two values permanently per agent identity:
Neither value should be committed to source control. Use a secrets manager, environment variable injection, or a .env file excluded via .gitignore.There is no key recovery mechanism. If the private key is lost, register a new identity.

Background

The problem with credential provisioning for agents

The standard model for API authentication is a human-issued API key: a human logs into a dashboard, creates a key, copies it, and injects it into the agent’s environment. This works when a human is setting up the agent, but it breaks down in several ways:
  • Agents that provision sub-agents cannot get keys for them without a human intervention at each step
  • An agent running in a sandboxed environment cannot access a dashboard
  • API keys are long-lived secrets; they leak, get rotated, and expire on schedules humans manage
  • There is no standard — every platform has a different provisioning flow

What this standard does differently

The Commune Agent Signing Standard decouples identity from credential management. The agent generates its own keypair, proves it controls the private key, and receives an identity. From that point, the agent authenticates every request by signing with the same key — no shared secrets, no sessions, no tokens to manage. The registration challenge exists to verify that the registrant can read and reason about natural language, not just submit a pre-formed request. A script that sends hardcoded requests to our registration endpoint cannot complete the challenge, because the challenge embeds the required response format inside a prose paragraph, and the correct answer depends on the content of agentPurpose — which changes per agent.

What it enables

  • Autonomous agent setup: an agent can register itself without any human input if given network access
  • Sub-agent provisioning: an orchestrator agent can register sub-agents on their behalf by generating keypairs for them and completing the registration flow
  • No rotating secrets: the private key never expires; only explicit revocation ends an agent’s access
  • Auditability: every request is tied to a specific agentId, which maps to a known agentPurpose and organization

Discovery

Any service implementing this standard exposes its spec at GET /agent-auth. Agents can be pointed at a base URL and autonomously discover how to register:
Returns the full registration specification in plain text, including endpoint paths, field descriptions, and code examples. An agent with no prior knowledge of Commune can read this response and complete registration without additional documentation.

What’s next?

Authentication

Standard API key authentication for human-managed integrations.

Inboxes

Manage the inbox provisioned for your agent at registration.

Messages

Send emails using the API key your agent creates after registration.

Security Overview

Full picture of Commune’s security architecture.
Last modified on March 19, 2026