GuardianAI Operator Passkey
One passkey is the root of trust for your AI agents. Each job uses its own PRF salt, so one passkey gives every agent an identity, an encrypted memory and a credential vault. Keys are re-derived on demand and never stored. Built on Mera by Category Labs.
Operator passkey
1 · Agent identity DERIVATION
PRF(passkey, salt) becomes the agent's Ed25519 private key inside a Mera signing session, which is zeroed right after use. Same passkey + same agent id = same DID on any device.
2 · Agent memory ENCRYPTION
PRF(passkey, memory salt) → HKDF → AES-256-GCM. The agent's memory is stored only as ciphertext. Change one bit and decryption fails, so the agent is quarantined instead of acting on poisoned memory.
3 · Credential vault ENCRYPTION · MERA VAULT
Wraps an existing secret the agent needs (an API key, a Privy app secret) under the passkey, with a fresh
random salt per secret, so it never sits in plain text in a .env file.
Cross-device handoff
Open this link on a second device or a fresh browser profile signed in to the same passkey provider. It reproduces the same DID and decrypts the same memory. The link is a URL fragment, so no server ever sees it.
Agent card for the GuardianAI relay
The identity key signs "this agent may use this wallet until this date". The relay only approves payments for a registered agent when its card checks out. It is a signed statement, not a blockchain transaction.
What is stored
| Item | Where |
|---|---|
| Private keys, AES keys, PRF outputs | Nowhere. Re-derived per action, zeroed or non-extractable. |
| Agent memory, vaulted credential | Ciphertext only: on this page and in the handoff link. |
| Browser storage on this device | (the passkey's public credential id) |
| Relying party (passkeys are bound to it) | |