GuardianAI Operator Passkey

One passkey is the root of trust for your AI agents. Each job uses its own PRF salt, so one passkey gives every agent an identity, an encrypted memory and a credential vault. Keys are re-derived on demand and never stored. Built on Mera by Category Labs.

Operator passkey

Checking passkey support…

1 · Agent identity DERIVATION

PRF(passkey, salt) becomes the agent's Ed25519 private key inside a Mera signing session, which is zeroed right after use. Same passkey + same agent id = same DID on any device.

2 · Agent memory ENCRYPTION

PRF(passkey, memory salt) → HKDF → AES-256-GCM. The agent's memory is stored only as ciphertext. Change one bit and decryption fails, so the agent is quarantined instead of acting on poisoned memory.

3 · Credential vault ENCRYPTION · MERA VAULT

Wraps an existing secret the agent needs (an API key, a Privy app secret) under the passkey, with a fresh random salt per secret, so it never sits in plain text in a .env file.

Cross-device handoff

Open this link on a second device or a fresh browser profile signed in to the same passkey provider. It reproduces the same DID and decrypts the same memory. The link is a URL fragment, so no server ever sees it.

Agent card for the GuardianAI relay

The identity key signs "this agent may use this wallet until this date". The relay only approves payments for a registered agent when its card checks out. It is a signed statement, not a blockchain transaction.

What is stored

ItemWhere
Private keys, AES keys, PRF outputsNowhere. Re-derived per action, zeroed or non-extractable.
Agent memory, vaulted credentialCiphertext only: on this page and in the handoff link.
Browser storage on this device (the passkey's public credential id)
Relying party (passkeys are bound to it)

Ceremony log