The short answer
Agent authentication is a cryptographic method for AI agents to register themselves and authenticate API requests without any human in the loop. It uses Ed25519 digital signatures — the same primitive as SSH keys.The problem it solves
Every API authentication method assumes a human at some point:
Autonomous agents can’t do any of this. They can’t open a browser, navigate a dashboard, or click a link.
How Commune agent authentication works
One-time registration (two API calls):- Agent generates an Ed25519 keypair locally
- Agent sends public key + purpose description to
/v1/auth/agent-register - Server returns a natural-language challenge (proves the registrant can reason, not just script)
- Agent reads challenge, constructs response, signs it with private key
- Agent sends signed response to
/v1/auth/agent-verify - Server returns
agentId+ auto-provisioned inbox
{agentId}:{timestamp} with its private key before every request. No token exchange. No session. Stateless.
Why Ed25519
- Private key never leaves the agent — only signatures are transmitted
- No rotation needed — unless key is compromised (same as SSH)
- Replay-proof — timestamp is part of the signed message, each pair accepted once
- Fast — microsecond signing and verification
- Standard — RFC 8032, supported in every crypto library
Compared to API keys
Quick start
Related
Agent Authentication Standard
Complete technical spec with Python, Node.js, and Go implementation examples.
Agent Auth
API reference for the Ed25519 challenge-response agent authentication flow.

