From nothing to a live, verifiable badge in about five minutes
Four steps. No framework rewrite, no gateway to route traffic through — your agent keeps running where it runs and reports what it does with one HTTP call.
- Create a free workspaceSign up with
?product=atf— 10 agents free, no card. Agentic Trust & Protection Platform is on from the first request. - Register the agentName it and declare its scopes. You get a
spiffe://identity, a per-agent key (shown once) and the badge embed. - Report actionsOne
POSTper tool call. In scope → a signed ledger entry. Out of scope → the identity is revoked and the badge turns red. - Embed and verifyDrop the badge in a README or trust page. Anyone can check the signed document offline with your public key.
Create a workspace
Sign up at app.redthreadsec.com/app?product=atf. Or from a terminal:
Register the agent
Console → Agents → Issue identity, or:
Scopes are yours to name — read:ledger, crm:export, * for everything. They are checked on every reported action, not once at deploy.
Report every action
Wrap your tool calls so each one reports itself with the agent key. In scope: a signed action event lands in the append-only ledger. Out of scope: the same signed record, plus the identity is revoked with a signed policy_violation event, webhooks fire, and the badge turns red within a minute.
- One helper, called around each toolimport os, requests ATPP=dict(sid=os.environ["ATF_SPIFFE_ID"], key=os.environ["ATF_AGENT_KEY"]) def report(tool, scope): r = requests.post("https://app.redthreadsec.com/api/trust-signal/actions", headers={"Authorization": f"Bearer {ATPP['key']}"}, json={"spiffe_id": ATPP["sid"], "tool": tool, "scope": scope}, timeout=5) if not r.json().get("in_scope"): raise PermissionError(f"{tool} is out of scope — identity revoked") # LangGraph: call report(tool.name, tool.metadata["scope"]) in your tool node # CrewAI: call it at the top of each Tool._run # AutoGen: register it as a function-call hook
- Report the server call as the toolUse the server's
namespace/nameastooland the permission it needs asscope. A server reaching for a scope you never declared revokes the agent's identity — the failure mode static secrets can't catch. - Restore after reviewThe workspace owner lifts a revocation from the Agents view. The out-of-scope count stays in the ledger; that history is the point.
Embed the badge, let anyone verify it
Markdown for a README, HTML for a trust page. The badge prints the level and the “as of” date; unknown or expired renders grey; red only on proof.
The verify page shows the last ledger events and their signatures. The .json next to it is signed over its canonical JSON — sorted keys, no spaces, signature removed — with the workspace key at /api/trust-signal/keys/public/<tenant>:
Webhooks, SPIRE, and what the levels mean
POST /api/trust-signal/webhooks {"url","secret"?} — every trust-state change is delivered as the signed event, with an X-Redthread-Signature HMAC when a secret is set. Test one with /webhooks/<id>/test.
Deploy the SPIRE engine in your own cloud (GET /api/trust-signal/spire gives the Terraform) and identities become real, auto-rotating SVIDs issued by you. The badge says attested instead of verified.
unknown grey · scanned amber (public MCP servers, unasked) · verified green · attested green, filled · revoked red. Read the charter.