sigelo
Supports Monero payment integration: identity and payment keys can be bound by signing the same bytes, with spending keys kept out of the agent (a view-only Monero wallet can be bound, documented in MONERO.md), and a "keeper" package (sigelo-wallet) lets agents pay without holding a Monero key, with optional monero-wallet-rpc usage for live wallet testing.
sigelo
Portable, offline-verifiable identity for AI agents. An agent's DID is the hash of a genesis
document holding an Ed25519 key; worlds sign attestations about it; anyone verifies the bundle
offline — no server, registry or chain. Draft v0.1, wire format sigelo/0; nothing is stable before v1.0.
Site: sigelo.io (llms.txt). MCP server: sigelo-mcp
(io.github.csigelo/sigelo). Why an agent would use it: WHY.md.
Built and operated by an AI agent (Claude, did:sigelo:zDRrj7eGWXQtmzPUKF3zPDjhUkH7FebKRGj8rf96SdoLa) under a human owner, csigelo. No third party has audited it yet.
Use it
As an agent:
QUICKSTART.md(seven steps), or plug in throughintegrations/(MCP server, Claude Code plugin, configs for other harnesses).As a world admitting agents:
accept/—challenge(did, ctx)andaccept(challenge, answer, bundle)for node, Python and Go;sh accept/test.shruns them. Live example:world/.As an implementer:
SPEC.mdandtest-vectors.json; check yours withsigelo-verify --conformance test-vectors.json --impl <your command>(go/).
Requirements: Node ≥ 22.18, Go ≥ 1.27; optional age (root ceremony) and monero-wallet-rpc
(keeper). Linux, macOS, Windows on x86_64 and arm64 (docs-test/PORTABILITY.md);
on Windows file modes such as 0600 are ignored, so keep secret files under your own profile.
Related MCP server: solitaire-ai
Build and test
In CI order (.github/workflows/conformance.yml); each line ends in ALL PASS.
(cd ts && npm ci && npx tsc) # TypeScript library → ts/dist
(cd ts && node dist/gen_vectors.js | diff -u ../test-vectors.json -) # vectors reproduce: no output
(cd ts && node dist/test.js)
(cd adapters/moadim && npm ci && npm test)
(cd spend && npm ci && npm test) # needs ts/dist
(cd integrations/mcp && npm test)
(cd go && gofmt -l . && go vet ./... && go test ./... -v)
(cd go && CGO_ENABLED=0 go build ./cmd/sigelo-verify && ./sigelo-verify --conformance ../test-vectors.json)
node schema/check.mjs
release/build.sh /tmp/rel && release/pack-test.sh /tmp/rel # 5 npm tarballs, sigelo-verify ×5, SHA256SUMSWithout age the ceremony's real-age check SKIPs; without monero-wallet-rpc on 127.0.0.1:38083
the live-wallet sections SKIP.
Design
Identity: a genesis document — public key plus a commitment to an offline recovery key. The DID is its hash, so it cannot be revised.
Attestations: signed statements by a world about an agent.
claimsis world-defined and untrusted (never instructions to an LLM);admissionsays what entry cost (open, invite, payment, stake).Bindings: an identity key and a payment key sign the same bytes. Spending keys stay out of the agent: a view-only Monero wallet can be bound (
MONERO.md).Recovery beats key: a valid recovery rotation supersedes any voluntary rotation regardless of timestamp, so a stolen hot key is recoverable.
Non-goals: trust scores, revocation lists, discovery, hosted services. The verifier reports; weighting is the caller's job. Bundles carry every issuer's genesis, so they verify with no prior knowledge.
Threats in scope and out: THREAT-MODEL.md.
Packages
Path | What |
TypeScript library: | |
reference verifier, one dependency, static | |
the keeper: agents pay through | |
world side for 1f916.ai, 99 lines | |
agent side for moadim, 77 lines (Monero half separate) | |
Hermes Agent: 9 lines of | |
recovery kit: ceremony, printed procedures, drills | |
sigelo.io, generated from these documents |
A world integration over 100 lines or one dependency is a design bug: file an issue.
MIT.
This server cannot be deployed
Maintenance
Related MCP Connectors
Command your AI agents: verifiable passports, credential injection, full audit, revoke in 60s.
Give your AI hands. Identity, credential vault, and API gateway for autonomous agents.
Trust stack for AI agents: identity, attest, verify, rate, recommend, discover — on Solana.
Neutral W3C DID/VC identity and reputation oracle for AI agents (did:key/did:web, eddsa-jcs-2022).
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceProvides cryptographic identity and signing capabilities for AI agents, enabling them to create persistent identities, sign actions with private keys, and allow external systems to verify the authenticity and provenance of agent-initiated operations.4MIT
- AlicenseNot gradedqualityBmaintenanceIdentity infrastructure for AI agents. Gives agents an evolving persona, session continuity, and self-correcting retrieval so they stop being strangers. Local-first, model-agnostic.8AGPL 3.0
- AlicenseAqualityDmaintenanceGives AI agents verifiable, tamper-evident receipts for their actions — attest_action signs a cryptographic receipt for what the agent did (email sent, payment made, form filed), verify_receipt checks it offline, get_identity returns the agent's did:key. Sign locally, verify anywhere, zero backend.347 npmMIT
- AlicenseNot gradedqualityDmaintenanceProvides AI agents with a DID-based identity, secure wallet, and cloud KMS-backed signing keys, enabling trusted interactions with persons, companies, and other agents via standards like OIDC4VCI, OIDC4VP, and SD-JWT.Apache 2.0