Skip to content
Evoliv Core

Resources

Guides and downloads

Everything needed to understand AIAF, verify agents on your own site, and run agents with Project AIDR.

Quick start · Relying parties

Verify an agent on your site

The verifier checks the agent's credential and its request signature locally. It needs the registry's public keys (refresh hourly) and its signed revocation feed (refresh every 60 seconds), fetched in the background — nothing in the request path contacts the registry. Endpoints are in the registry's discovery document.

Node.js · Express
import { AgentVerifier, buildTrustStore, NonceCache,
  expressMiddleware } from './node/index.mjs';

// jwks and the revocation delta, refreshed in the background
const trust = buildTrustStore(jwks, {
  deltaToken, expectedIssuer: 'https://api.evolivcore.com' });
const verifier = new AgentVerifier(trust, {
  policy: { minAssurance: 1 }, nonceSeen: new NonceCache() });

// req.agent: the verified agent, or null when unidentified
app.use(expressMiddleware(verifier, { optional: true }));
Python · FastAPI / any ASGI app
from aidr_verifier import AidrMiddleware, RelyingPartyConfig

# keeps keys and revocation state in sync by itself
app.add_middleware(AidrMiddleware, config=RelyingPartyConfig(
    issuer="https://api.evolivcore.com",
    min_agal=1,
))

@app.get("/whoami")
async def whoami(request):
    identity = request.state.aidr    # .is_agent, .aid, .agal, .org_domains
    ...
  • Fail closed by default. If revocation state cannot be determined, requests are refused (503, not 401) unless you choose otherwise.
  • Key trust on the domain. Make identity decisions on the registry and the agent's verified domains, not its namespace string.
  • Unidentified is not hostile. Serve anonymous traffic what you already serve it; require an agent only where identity matters.

Downloads

Each file is listed with its SHA-256, so you can check what you received. Every verifier includes the shared cross-language test vectors and passes them.

Relying Party plugin — verifier SDKs

Node.js @aidr/verifier 0.1.0

Zero dependencies — Node's built-in crypto only. Node 18+. Includes Express/Connect middleware.

30 KB · SHA-256 77a1af4f4e7165ab20d78aecf571ed134de60066ab95f811c2ef4351db90bf84

Download for Node.js

Python aidr_verifier 0.1.0

ASGI and FastAPI middleware with background sync and shared replay protection. Python 3.10+; needs cryptography and httpx.

107 KB · SHA-256 f70beadf902ac6272db780be96b7a621206da3d77e068282f3b651d9d1b858ef

Download for Python

Go aidr-go 0.1.0

Standard library only. Go 1.21+.

30 KB · SHA-256 3458fef61d21a51133c96c5295c8c7a0dc24056c4944e7102cd4fe76527a5636

Download for Go

Desktop app — Evoliv Core Gateway

Evoliv Core for Windows, macOS and Linux Coming soon

Keeps your agent's key in the operating system's credential store and runs the local gateway that signs its requests. Signed installers will be published here.

Not yet available

Standard and policy

AIAF draft 0.1 Markdown

66 KB · SHA-256 78dcfea0ef7d458fa2e07b84032cece7fe4df226bd73dcd9bca0465594dbe772

Download

Registry authorization policy OPA / Rego

8 KB · SHA-256 5b7a06a0b87f0fa1777f66f5c848de901f02e99d1c52e81936923427fdfbabca

Download