Skip to content
AIDR Go to Console

Project AIDR · by Evoliv Core

The Zero-Trust Identity Layer for AI Agents

Secure your enterprise AI infrastructure. Issue verifiable cryptographic identities that every web service and application can instantly trust, verify, and enforce in real-time.

Signatures
RFC 9421
Agent keys
Ed25519
Step-up
Passkey, AAL3

The problem

Agents act on your behalf. A shared secret can't say which one.

An API key proves only that someone has a copy of it. Evoliv Core gives every agent an identity it proves with a signature, on every request.

Legacy

Static API Keys

  • Vulnerable to leaks. Copied into config files, logs and prompts; anyone holding a copy is the agent.
  • Hard to rotate. Every consumer must be updated at once, so keys live for years.
  • Lacks context. No record of which agent, which organisation, or who is accountable for it.

Evoliv Core

Dynamic Cryptographic Identity

  • Generated locally. Ed25519 keys are created on the agent's device; the registry also accepts ECDSA P-256.
  • Never transmitted. Only the public key is registered. Short-lived credentials renew automatically.
  • Instantly revocable. One action in the console, and the agent gets no new credential.

Platform

Built for the security review, not around it

Device-Bound Keys

Keys are generated on the device and kept in the OS credential store: Windows Credential Manager, macOS Keychain or Secret Service. The private key never leaves the agent's environment. TPM and Secure Enclave backends are on the roadmap.

Streaming Gateway

Zero-buffer streaming architecture. Request and response bodies stream through in constant memory with no size cap, so large AI payloads pass untouched while every request is signed.

Instant Revocation

Full enterprise control. Revoke a compromised agent from the passkey-protected (AAL3) console: its gateway stops at once, and relying parties see it on the revocation list within a minute.

Developer experience

Your agent keeps speaking plain HTTP

Start the local gateway from the Evoliv Core app. Your agent sends requests to 127.0.0.1; the gateway signs each one as the agent and attaches its credential. The agent software never holds the key.

  • Loopback only, with a per-start gateway token
  • HTTPS upstreams on your allowlist
  • No SDK, no code change in the agent
agent@workstation — evoliv gateway
# Evoliv Core app → Gateway → Start[INFO]    Agent key loaded from OS credential store (ed25519)[INFO]    Credential issued · renews automatically[SUCCESS] Secure gateway established on 127.0.0.1:8765
# Your agent, unchanged: plain HTTP to the gateway$ curl http://127.0.0.1:8765/v1/orders \    -H "X-Evoliv-Gateway-Token: $EVOLIV_TOKEN" \    -H "Evoliv-Target: https://shop.example"→ signed as agent-01 (RFC 9421) · Agent-Credential attachedHTTP/1.1 200 OK

Give every agent an identity you can revoke.

Create an organisation, prove your domain, and register your first agent.

Go to Console