Proof,
not permission.
Your agent authenticates with a secret. That proves possession, not identity — and nothing proves what it was authorized to do, or what it actually did. Rezos is the layer that does.
Three questions
nobody can answer
An agent authenticates by presenting a secret. That mechanism answers exactly one question — does this caller possess the secret. It cannot answer the ones that now matter.
A bearer token proves someone holds a string. It doesn't prove the request came from the model you chose, on the version you vetted, running unmodified.
Permissions live inside one company's database. The counterparty on the other side of the trade cannot verify them. Neither can you.
When an autonomous system loses money, the record is held by parties with their own exposure to what's in it. Evidence shouldn't be owned by an interested party.
An agent can't tell
data from orders
Put an instruction inside content an agent reads, and it will follow it. Nobody has solved this at the model layer. So we make it refusable — a mandate can say act only on vetted sources, and the action dies before it reaches the venue.
Edit the research note below. Then run the agent.
Four primitives
We make no claim about whether an agent's reasoning is sound. We constrain and record what it is permitted to do, which is checkable.
Identity that means something
A key bound to attested provenance — which operator, which model family and version, and where available a hardware attestation of the runtime. Assurance tiers from A0 to A3 let a counterparty decide what it accepts, without asking anyone to open their weights.
Authority that travels
A signed capability grant, verifiable offline, without calling us. Caps, venues, rate limits, expiry. Delegation computes an intersection with its parent — widening isn't forbidden by policy, it's arithmetically inert. About 280 bytes, verified in under a millisecond.
Decisions bound to inputs
Before acting, an agent commits to a hash of everything it read and the provenance class of each source. You can constrain what it may act on, and when something goes wrong the record names the exact document. We don't detect the attack — we make it refusable and attributable.
Evidence anyone can check
Every decision emits a signed receipt — mandate, intent, inputs, verdict, which caveats fired. Merkle-accumulated and anchored on chain every 30 seconds. An auditor can reconstruct the whole history without trusting any Rezos operator, including us.
Authority you can
actually see
A mandate isn't a settings page. It's a signed object your agent carries, and any counterparty can verify it without asking us.
One honest auditor
Mandate evaluation is deterministic. Two honest verifiers always agree, so disagreement isn't noise to average — it's a fault to prove. That lets us drop staked voting entirely, and it buys a much weaker security assumption than honest majority.
The action reaches the gateway carrying its mandate chain and context commitment.
A VRF-sampled set evaluates independently. Two of three agree, the action proceeds.
Receipts accumulate into a Merkle root committed on chain on a fixed cadence.
A bonded auditor re-executes and proves a wrong verdict. No oracle, no vote, no judgment call.
Where the rewards
come from
Emissions are a subsidy — dilutive by construction, paying people in claims on our own future. Fees are external value entering because someone outside got something they wanted. Only one of those lasts.
Fee-funded rewards divided by emission-funded rewards. Not price — this is the number worth watching, and we publish it every epoch. Crossover targeted in year three.
Three of our four payer classes would pay for reasons that exist even if there were no token. That's the test.
Useful before
it's trusted
Each phase ships something worth using before the next one exists. Risk rises only after the layer has earned it.
Agents will move a lot of the world's capital
The question was never whether they'd be allowed to act. It's whether their authority could be proven. Read the whitepaper, argue with it, tell us where the model breaks.