Agent permissions
Sign in to set permissions
Your agents' authority lives behind an account. Log in or create one. Already hold a principal secret? Sign in, then claim it below.
Or drive the same thing over HTTP
The console is a client of this API and adds nothing to it — a mandate issued here is byte-identical to one issued by curl.
POST /v1/principals { name, country, accredited, kyc:{sandboxOutcome} } → id + one-time secret
POST /v1/agents Bearer <secret> { name, runtime, public_jwk }
POST /v1/mandates Bearer <secret> { agent, scopes[] }
GET /v1/mandates/:id Bearer <secret> → the signed grant + its decision history
POST /v1/mandates/:id/revoke Bearer <secret>
GET /v1/principals/:id/dashboard Bearer <secret>
No principals yet
A principal is the human or company that bears liability for what an agent does. Create one below.
—
Issue a mandate
Five questions. Every answer narrows what the agent may do — there is no "allow everything".
Which agent is this for?
Granted to one agent. Nothing else can present it.
No agents yet — register one below, then come back.
What may it do?
One kind per mandate.
At least one. "Anything" isn't an option.
How much, at most?
One bounds a single action. The other bounds the running total, so small actions can't add up past it.
Never exceeded in one action.
Everything it spends, added up.
Rolling, not calendar.
Where may it act?
Works here and nowhere else. Presented elsewhere, it's denied — and the denial is recorded.
Search registered platforms, or paste a plt_ id and press Enter.
Until when?
Every mandate ends. You can revoke it sooner.
End of this day, UTC.
Seen only by you and your auditor.
Mandates
Revoking takes effect on the agent's next action. Nothing to redeploy, no cache to wait out.
Loading…
Agents
Loading…
Register an agent
An agent is an Ed25519 keypair. This page can generate one in your browser — the private key is shown once and never sent to Writ — or you can paste a public JWK produced by passport-agent init.
Private key for — shown once. It never left your browser and Writ has never seen it. Put it in the agent's secret store; if you lose it, register a new agent.
Recent decisions
Every time a platform asked Writ whether one of your agents could act. Denials are kept too — they are the evidence your caps are real.
Loading…
Create a principal
The party that bears liability. KYC runs in sandbox mode on this stack.
Shown once. Agent runtimes use this to sign. You will not need it to manage permissions here — that is what the account is for.
Claim a principal you already hold
Paste an existing principal secret to bind it to this account. The secret keeps working exactly as it does now — claiming changes nothing about it.