Skip to content

Agent Registry

Agent Registry

Register AI agents with the control plane. Each agent accumulates an adaptive trust level, clean records earn fast-path clearance, blocks reduce trust.

POST /v1/enforce/agents Register a new agent. GET /v1/enforce/agents List all registered agents. GET /v1/enforce/agents/{agent_id} Get agent details including trust level and action history. GET /v1/enforce/agents/{agent_id}/history Get trust history and decision timeline for an agent.

One revoke, everywhere

DELETE /v1/enforce/agents/{agent_id} only deactivates the registration; since Phase 0 of the Authorisation Layer programme a deactivated agent is refused at the control plane with decision_path: "revoked", but the authority it lent to others stays until it is revoked. Use the revoke endpoint below, which is the recommended path.

Deactivating an agent is not enough when it also holds sessions, credentials, grants it gave to other agents, temporal windows, intent contracts, federation tokens and MCP tool policies. POST /v1/enforce/agents/{agent_id}/revoke removes all of them in one operation and returns a signed Revocation Certificate listing exactly what was revoked and when:

cert = client.enforce.revoke_agent("agt_payments", reason="credential suspected compromised")
# cert["counts"] → {"sessions": 1, "credentials": 1, "grants_given": 2, "grants_received": 1,
#                   "temporal_windows": 0, "intent_contracts": 1, "federation_tokens": 0, "mcp_tool_policies": 1}
# cert["signature"] → ECDSA P-256 over the canonical certificate body, with the public key

The cascade, in order: the registration is deactivated; every active session is killed (in-flight runs stop); every credential is revoked; every delegation grant the agent gave or received is revoked, cascading to child grants; temporal windows, intent contracts and federation tokens are revoked; MCP tool policies are disabled. From that moment any action by the agent is refused at the choke point with decision_path: "revoked", and any delegate acting on its behalf is refused because a revoked principal lends no authority.

The certificate is sealed to the Provenance Vault, an incident records every step, an agent.revoked webhook fires, and the certificate can be fetched later (GET /v1/enforce/revocations/{revocation_id}, which also reports whether its signature still verifies). In the dashboard the Registry has a Revoke everywhere action per agent.

Adaptive Trust

Event Trust Change Description
Action allowed +0.2 Clean record builds trust over time
Action blocked -2.0 Policy violations significantly reduce trust
Action escalated -0.5 Uncertain decisions slightly reduce trust

Register Agent Example

# Register a trading agent
agent = requests.post(
    "https://www.xybern.com/api/v1/enforce/agents",
    headers={"X-API-Key": API_KEY},
    json={
        "name": "Trading Agent Alpha",
        "framework": "langchain",
        "description": "Automated equity trading agent",
        "capabilities": ["execute_trade", "read_data", "send_email"],
        "permissions": {
            "allowed_action_types": ["execute_trade", "read_data"],
            "denied_action_types": ["delete_data", "admin_action"]
        }
    }
).json()

agent_id = agent["agent"]["agent_id"]
print(f"Registered: {agent_id}, trust: {agent['agent']['trust_level']}")