Now in public beta — free to use

Give every agent its own
identitypolicyaudit trail
identity.

The control plane that gives every agent its own credentials and audit trail — governed by signed mandates you control and can revoke in one step.

No shared secrets.  ·  No loose scripts.  ·  One control plane.

app.agenttag.me/overview

Built for:

Claude Desktop
CrewAI
LangChain
Any MCP or A2A client
01The shift

AI delegation didn’t get harder.
It got stuck.

Wrapper scripts work in a sandbox, but collapse once agents touch money or production systems. AgentTag replaces keys with governed identities, ensuring execution compounds safely instead of drifting.

Your journeys are a mess
Clean them up with AgentTag
02The platform

How does a single control plane govern every agent?

AgentTag sits between your agents and the world. Every action flows through one policy engine, one identity layer, and one tamper‑evident ledger — whatever framework, tool, or cloud you use.

Your agents
CrewAI
LangChain
Claude Desktop
+ any MCP / A2A client
request
AgentTag Control PlaneGOVERNING
Policy engine
Evaluates every call against your mandates and returns allow, step‑up, or deny.
Identity & mandates
Issues DID‑signed passports and scoped, expiring capability tokens for each agent.
Audit ledger
Hash‑chains every action into a tamper‑evident record.
signed action
Real-world tools
Pay
Comms
Deploy
Vault
across every cloud
Policy engine
Evaluates every call against your mandates and returns allow, step‑up, or deny.
Identity & mandates
Issues DID‑signed passports and scoped, expiring capability tokens for each agent.
Audit ledger
Hash‑chains every action into a tamper‑evident record.
Sandboxed compute
Runs actions in isolated environments with narrow access.
03The tool surface

One MCP server. Eight tools.

Drop AgentTag into Claude Desktop or any MCP‑compatible agent. The agent sees only governed tools; every call goes through policy, vault, and audit, and no capability runs without a verdict.

agenttag · tools
browse(action, target)// drive the browsercomms.send(channel, to, body)// email / smscomms.verify(sess)// read OTP / linkpay(amount, merchant, card?)// virtual carddeploy(project, files, env)// build & hostprovision(kind)// new inbox / phonevault.use(handle, …)// use, never readapprove(action, ctx)// ask the human
Connect in 30 seconds.

Add the server to your MCP client and the tools appear in the agent automatically. The agent can request actions, but nothing completes unless policy allows it.

$

The agent can request actions, but nothing completes unless policy allows it.

04Platform governing

Everything you need to govern AI action.

Track, analyze, and authorize every request made by your autonomous agents across tools, hosts, and networks in real time.

Every node in any cloud

Govern execution across private microVMs, secure credential enclaves, and KMS-backed environments.

Govern any agent

Apply the same rules across CrewAI, LangChain, Claude Desktop, and any MCP or A2A client.

CrewAI
Governed
LangChain
Governed
Claude Desktop
Governed
9 more · any MCP / A2A client

Connect your tools

Bind third-party credentials behind secure, sandboxed API surfaces.

Stripe Payments

Process virtual cards

Connected

GitHub Actions

Scoped deploy tokens

Connected

Biometric consent

Fails closed on timeouts. Authorizations require on-device biometric check signed by your key.

Passkey Ready

Durable mandates ledger

Every decision is logged and cryptographically verifiable.

governance-logs.jsonLIVE
saas-spend-limit.jsonACTIVE
mcp-tools-allowlist.jsonACTIVE
eval: {pay $5.00 → vercel · saas}ALLOW
The human holds the pen

Interrupted only when it genuinely matters.

Routine work runs untouched. When the agent reaches a new payee, a spend over your threshold, or anything irreversible, it pauses and asks — and your approval is signed on-device, never a blank cheque.

Always-allow learns your boundariesFails closed on timeout
AgentTagAgentTagSTEP-UP

Agent Research wants to pay $840.00 to Acme Data Inc

category: data · new merchant · mnd_01H…

Signed with your passkey · on-device

05Audit ledger

How does the audit ledger secure agent actions?

A tamper‑evident ledger records every request, decision, and approval. Hash‑chaining makes quiet rewrites impossible.

agenttag · audit ledgerlive
#1304policypay $5.00 → vercel · saasALLOW0x476e0c…
#1305actiondeploy thing.agents.hostNOTICE0x986cdb…
#1306cred_usevault → github_agentALLOW0x3a9b1c…
#1307policybrowse linear.app · signupALLOW0x8f2d4e…
#1308commsawait_verification · inboxOK0x5c7b9a…
#1309policypay $840 → acme data · newSTEP-UP0x1d4e6f…
#1310approvaloperator signed envelope0x7a8b9c…
✓ Chain verified1,311 entries · prev_hash linked
AgentTagThe Passport

Every agent gets its own cryptographic DID and signing key. Revoke it once and its authority stops.

Agent DIDdid:key:z6Mk…AGENT
Operatordid:key:z6Mk…HUMAN
Signing keyEd25519
StatusActive
Operator proofsigned
The Mandate

A human‑signed mandate defines what an agent can do, what it can spend, when it must ask, and when access expires.

Capabilitypay
Per-transaction cap$50.00
Billing period30 days
Step-up above$100.00
Expires2026-12-31
06Why AgentTag

Why choose delegated identity over shared keys?

Password managers share secrets. DIY scripts skip governance. AgentTag is identity-first, MCP-native, and accountable by construction.

Cryptographic agent
identity & delegation
AliasKit
anima
AgentWallet
AgentTag
DID-anchored agent passports
Cryptographic, attenuable mandates
Real-world primitives (pay, comms)
On-device passkey approvals
Hash-chained, offline-verifiable ledger
07Pricing

Free while we’re in beta.

All primitives, policy, and the hash‑chained ledger are unlocked for public beta. No card. No seats. No hidden catch.

Public beta
Live now
$0for everyone, right now

Bring your first agent online and govern it end to end.

  • All five primitives, live
  • Multiple agent passports
  • Full policy engine and step-up
  • Passkey approvals on-device
  • Hash-chained audit ledger
  • Direct line to the founders
Get beta access

No credit card. Cancel anytime. Your data stays yours.

Fair usage-based pricing

When we reach general availability, you’ll pay for autonomy, not seats.

  • 30 days’ notice before any new plan starts
  • A generous free tier that stays free
  • Founding-user pricing locked in
  • Enterprise SSO, SLA, and on-prem support when needed
Talk to the team
07FAQ

Questions, answered.

Everything you need to know about giving an agent its own governed identity.

An agent passport is the agent's own cryptographic identity — an Ed25519 keypair bound to a W3C DID. It signs requests and audit entries so permissions can be scoped and revoked cleanly, and so every action is attributable to a specific agent rather than to whoever has your API key.

Read more in Support Center →
[ get started ]

Give your agent a passport.

Bring your first agent online with governed identity, signed permissions, and a verifiable audit trail.