Who is acting
A verifiable identity connected to a responsible party — not an API key that anyone could be holding.
Regent is the financial authorization and compliance layer for AI agents that move money: a verifiable identity for every agent, limits it cannot exceed, risk signals watched in real time, and tamper-evident audit evidence for every action.
Issue an AgentID, create a mandate, and authorize your agent's first governed action against it — then watch the audit evidence anchor. The quickstart walks the whole loop.
Read quickstartGeneric gateways help manage what an agent can access. Regent is designed to govern and prove what an agent is authorised to do with money.
A verifiable identity connected to a responsible party — not an API key that anyone could be holding.
Amount, destination, time window, and approval conditions are enforced before the action executes, not reviewed after.
Rule and risk signals can allow, hold for a human, or stop an action that is technically permitted but behaviourally wrong.
Every decision leaves tamper-evident evidence that an auditor can check without trusting the operator.
Each one is a plain answer to a question a financial agent forces you to ask.
Gives an agent a verifiable identity connected to a responsible party. Technical issuance is included; optional human verification is a separate, pass-through step.
Defines what an agent may do with money: amount, destination, time, conditions, and approvals.
Evaluates rules and behavioural risk signals, then allows, holds, or stops a risky action.
Creates tamper-evident evidence through cryptographic hashes, Merkle batches, and chain anchoring.
Gives human operators monitoring, investigation, policy, and intervention surfaces.
Together they implement KYA — Know Your Agent: Regent's framework for connecting an autonomous agent to a responsible context, financial mandate, and verifiable audit history. KYA is Regent's product framework; it is not a formal regulatory standard or regulatory approval.
Most "agent identity" is a row behind someone's login: credentials in a vault, permissions in a dashboard. When that vendor is down, gone, or simply not asked — it proves nothing. Nobody outside can check it.
Every Regent agent signs its requests (RFC 9421 — Web Bot Auth and AAuth dialects) and has a public registry entry: status, responsible owner, behaviour tier. Any bank, merchant, or platform can check it — without asking us.
Lookups key on the RFC 7638 thumbprint of the agent's signing key. Behaviour tiers appear once a signed evaluation lands and vanish when it expires. The same registry powers Agent Validation.
An agent initiates a payment. The mandate bounds amount and destination before execution; approval conditions can require a human; the evidence pack shows exactly why it was allowed.
A platform issues AgentIDs for customer-facing agents and applies account-specific controls — every customer's agent runs under that customer's limits.
Policies on transaction value, counterparty, account, time window, and multi-party approval — enforced before movement, evidenced after.
Case reconstruction from a single record: action → responsible context → policy → decision → evidence. Evidence packs are exports and mappings for internal review.
The public site is deliberately more precise than a pitch deck — every claim below carries its state.
Register an agent, bound it with a mandate, authorize an action against it, and log the evidence — the full loop, from the real quickstart.
# pip install regent auth = await r.payment.authorize( mandate_id=MANDATE_ID, request=AuthorizeRequest(amount=Decimal("25"), currency="USD"), ) # the mandate says yes — or this raises await r.audit.ingest_event(IngestEventRequest( event_id=f"action-{auth.jti}", agent_id=AGENT_ID, event_type="action.completed", payload={"authorization_jti": auth.jti}, )) # evidence queued for anchoring
No bearer secrets on agents; identity is proof-of-possession. Mandates fail closed — if the control layer is unreachable, the money action is refused. Evidence verifies against published keys, so an auditor does not have to trust the operator. Independent audit and SOC 2 are on the roadmap and will be stated here only when the reports exist.
The essentials on Know Your Agent, spending controls, and agent identity.
Developer tier with devnet access. Issue AgentIDs, write mandates, authorize actions, watch evidence anchor — before you talk to anyone.
Start buildingA pilot conversation with an architect: your workflow, where the mandate gate sits, and what the evidence pack contains for your reviewers.
Apply for a pilot