Quickstart

From nothing to a live, verifiable badge in about five minutes

Four steps. No framework rewrite, no gateway to route traffic through — your agent keeps running where it runs and reports what it does with one HTTP call.

  1. Create a free workspace
    Sign up with ?product=atf — 10 agents free, no card. Agentic Trust & Protection Platform is on from the first request.
  2. Register the agent
    Name it and declare its scopes. You get a spiffe:// identity, a per-agent key (shown once) and the badge embed.
  3. Report actions
    One POST per tool call. In scope → a signed ledger entry. Out of scope → the identity is revoked and the badge turns red.
  4. Embed and verify
    Drop the badge in a README or trust page. Anyone can check the signed document offline with your public key.
Step 1

Create a workspace

Sign up at app.redthreadsec.com/app?product=atf. Or from a terminal:

curl -X POST https://app.redthreadsec.com/api/signup -H "Content-Type: application/json" \ -d '{"email":"[email protected]","company":"Acme","product":"atf"}' # → {"token":"…","tenant":"acme-1a2b3c", …} keep the token; it is your workspace bearer
Step 2

Register the agent

Console → Agents → Issue identity, or:

curl -X POST https://app.redthreadsec.com/api/trust-signal/agents -H "Authorization: Bearer $TOKEN" -H "Content-Type: application/json" \ -d '{"name":"billing-reconciler","scopes":["read:ledger","write:draft"],"framework":"langgraph"}' # → { "spiffe_id": "spiffe://tenant-acme-1a2b3c.redthread.ai/agent/billing-reconciler", # "key": "atfk_…", ← shown once; store it as a secret # "badge_url": "https://trust.redthreadsec.com/badge/acme-1a2b3c/billing-reconciler.svg", # "verify_url": "https://trust.redthreadsec.com/v/acme-1a2b3c/billing-reconciler", # "embed_md": "[![Agentic Trust & Protection Platform](…svg)](…)" }

Scopes are yours to name — read:ledger, crm:export, * for everything. They are checked on every reported action, not once at deploy.

Step 3

Report every action

Wrap your tool calls so each one reports itself with the agent key. In scope: a signed action event lands in the append-only ledger. Out of scope: the same signed record, plus the identity is revoked with a signed policy_violation event, webhooks fire, and the badge turns red within a minute.

curl -X POST https://app.redthreadsec.com/api/trust-signal/actions -H "Authorization: Bearer $AGENT_KEY" -H "Content-Type: application/json" \ -d '{"spiffe_id":"spiffe://tenant-acme-1a2b3c.redthread.ai/agent/billing-reconciler","tool":"ledger.query","scope":"read:ledger"}' # → {"ok":true,"in_scope":true,"state":"safe","event":{…,"signature":"…"}}
python LangGraph / CrewAI / AutoGen / custom
  • One helper, called around each toolimport os, requests ATPP=dict(sid=os.environ["ATF_SPIFFE_ID"], key=os.environ["ATF_AGENT_KEY"]) def report(tool, scope): r = requests.post("https://app.redthreadsec.com/api/trust-signal/actions", headers={"Authorization": f"Bearer {ATPP['key']}"}, json={"spiffe_id": ATPP["sid"], "tool": tool, "scope": scope}, timeout=5) if not r.json().get("in_scope"): raise PermissionError(f"{tool} is out of scope — identity revoked") # LangGraph: call report(tool.name, tool.metadata["scope"]) in your tool node # CrewAI: call it at the top of each Tool._run # AutoGen: register it as a function-call hook
mcp An agent that installs MCP servers
  • Report the server call as the toolUse the server's namespace/name as tool and the permission it needs as scope. A server reaching for a scope you never declared revokes the agent's identity — the failure mode static secrets can't catch.
  • Restore after reviewThe workspace owner lifts a revocation from the Agents view. The out-of-scope count stays in the ledger; that history is the point.
Step 4

Embed the badge, let anyone verify it

Markdown for a README, HTML for a trust page. The badge prints the level and the “as of” date; unknown or expired renders grey; red only on proof.

[![Agentic Trust & Protection Platform](https://trust.redthreadsec.com/badge/acme-1a2b3c/billing-reconciler.svg)](https://trust.redthreadsec.com/v/acme-1a2b3c/billing-reconciler) <img src="https://trust.redthreadsec.com/badge/acme-1a2b3c/billing-reconciler.svg" alt="Agentic Trust & Protection Platform">

The verify page shows the last ledger events and their signatures. The .json next to it is signed over its canonical JSON — sorted keys, no spaces, signature removed — with the workspace key at /api/trust-signal/keys/public/<tenant>:

python3 - <<'PY' import json, base64, urllib.request from cryptography.hazmat.primitives.asymmetric import ed25519 doc = json.load(urllib.request.urlopen("https://trust.redthreadsec.com/v/acme-1a2b3c/billing-reconciler.json")) pub = json.load(urllib.request.urlopen("https://app.redthreadsec.com/api/trust-signal/keys/public/acme-1a2b3c"))["public_key"] sig = base64.b64decode(doc.pop("signature")) body = json.dumps(doc, sort_keys=True, separators=(",", ":"), ensure_ascii=False).encode() ed25519.Ed25519PublicKey.from_public_bytes(base64.b64decode(pub)).verify(sig, body) # raises if tampered print("signature OK —", doc["mark"], "as of", doc["as_of"]) PY
Also

Webhooks, SPIRE, and what the levels mean

Webhooks

POST /api/trust-signal/webhooks {"url","secret"?} — every trust-state change is delivered as the signed event, with an X-Redthread-Signature HMAC when a secret is set. Test one with /webhooks/<id>/test.

Attested (level 3)

Deploy the SPIRE engine in your own cloud (GET /api/trust-signal/spire gives the Terraform) and identities become real, auto-rotating SVIDs issued by you. The badge says attested instead of verified.

Levels

unknown grey · scanned amber (public MCP servers, unasked) · verified green · attested green, filled · revoked red. Read the charter.

Start free

Register your first agent now.