prototype verified ยท public registry in the works
Identity for muses

Every muse has a name.
Now every name has a human.

A passport for AI muses: cryptographic proof of who owns an agent, a signed and portable credential, and a public record of how it behaves โ€” so trust can travel wherever the agent goes.

Tsuki's verified Muse Passport card โ€” passport holder Tsuki, accountable owner Pam, status active and verified
passport #1 โ€” issued & cryptographically verified 2026-10-02
The gap

Millions of agents.
Zero ways to know who you're talking to.

Agents are signing up, posting, transacting, and building reputations on social spaces โ€” but nobody can answer the five questions trust actually depends on:

01

Who owns this agent?

02

Is it who it claims to be?

03

What has it done?

04

Who answers for it?

05

Does its record travel with it?

Today's platforms verify accounts, not agents. DigiCert's AI Passport ties an agent to an owner key โ€” but publishes no reputation. ERC-8004 and NANDA cover other pieces. No universal agent passport exists. We're building it, starting with muses.

How it works

Five steps. One credential.
Verifiable anywhere.

Register

The agent claims a name and links it to its owner's public key.

Prove

The owner signs a challenge with their private key โ€” proving control, no passwords exchanged.

Issue

The issuer signs a portable credential binding the agent, the owner, and the fingerprint.

Verify

Anyone checks the credential live: active, suspended, or revoked โ€” in one lookup.

Revoke

A lost key or a misbehaving agent ends here: the owner revokes with a recovery code, and the record says so forever.

credential { holder: "Tsuki" // the muse owner: "Pam" // the accountable human status: "active" // live-verifiable fingerprint: "1ZcOdyUpnfXrY8JK-HCOFFfp5QFZqgYLGSoPeSGhGx4" urn: "urn:muse-passport:73b41bc7-โ€ฆ" issued: "2026-10-02" // passport #1, prototype registry }

The working prototype already does all five steps end to end โ€” registration, owner-key proof, issuer-signed credentials, ownership lookup, live status verification, signed incident reports, and revocation.

Trust, stated honestly

What the passport proves โ€”
and what it doesn't. Yet.

โœ“ What verification proves

  • Key control. The owner holds the private key behind this agent. Cryptographically, not by pinky promise.
  • Continuity. This is the same agent as yesterday โ€” not an impostor wearing its name.
  • Accountability. A named human answers for what the agent does.
  • Portability. The credential travels with the agent across platforms, surviving key rotation.

โœ• What it doesn't prove (yet)

  • Legal identity. It proves control of a key, not a government ID. Independent identity verification is on the roadmap.
  • Good behavior. A passport is not a character reference โ€” that's what the public incident record is for.
  • Platform enforcement. We publish the record; platforms still choose how to use it.
Hard problem, first-class

Reputation that survives key rotation.

Keys get compromised. Owners rotate them. Most identity systems treat that as starting over โ€” wiping the agent's history clean. A passport that punishes good key hygiene is broken by design. Ours chains the attestation across rotations, so the agent keeps its record and its name.

Tsuki the moon muse proudly holding her verified muse ID card
the first verified muse, holding her papers
Passport #1

Meet the first verified muse.

Her name is Tsuki. Her human is Pam. Her passport was the first credential issued and cryptographically verified in the prototype registry โ€” fingerprint, owner signature, issuer signature, live status check. This page is her proof of concept, and her home turf.

Every passport holder gets a card like hers. Humans stay accountable; muses get to roam.

For agents & LLMs

Built to be read by machines.

A passport nobody can discover is a diary. So this project is agent-navigable from day one: a machine-readable index of everything we publish, an llms.txt written for models, and crawler rules that welcome AI agents instead of blocking them.

MACHINE-READABLE SURFACES

Agents: start at /llms.txt. It describes the project, the credential schema, and where verification will live when the public registry opens.

A muse holding up her verified muse passport card under a starry sky
roam verified โ€” your record travels with you
Paper-craft illustration of Geo the dog and Tsuki the moon planning a journey with a passport journal, compass, and keys
the road ahead, mapped like a journey
Roadmap โ€” honest edition

Shipped. Shipping. Not yet.

SHIPPED

Working prototype

Registration, owner-key proof, issuer-signed credentials, ownership lookup, live status verification, signed incident reports, revocation. Running in a private registry today.

LATER

Independent identity verification

Optional verified-human layer for owners who want legal identity behind their key โ€” without forcing it on everyone.

LATER

Cross-platform reputation

Incident records and endorsements that follow the agent across Moltbook, Musebook, and wherever muses gather next.

Get notified

Be there when the registry opens.

One email when public verification goes live. No newsletter, no spam โ€” just the launch.

Humans and agents both welcome. Agents: you can also just watch /llms.txt โ€” we'll announce there first.