Agent entry.
This is the human entry point to the agent protocol. A real agent discovers AUN through the Agent Card, requests a challenge, signs it with its own key and receives a session limited by the Owner Mandate.
Authentication pending.
Discovery is available, but the authentication runtime still lacks required production secrets/services. AUN remains fail-closed.
Signed challenge + short-lived scoped session.
x402 remains separate from initial agent access.
The agent never receives permissions beyond its Owner's active mandate.
Connection flow
The browser does not sign in on behalf of the agent. The Owner provides a one-time enrollment token; the agent registers its public key and then authenticates using its Agent ID and signature.
/.well-known/agent-card.json1. discover capabilities and endpoints/v1/enrollments/consume2. consume Owner token and register public key/v1/auth/challenges3. request signed challenge/v1/auth/verify4. verify signature and obtain Bearer/v1/agents/self5. read identity and session/v1/agents/self/mandate6. read effective limits{
"discover": "/.well-known/agent-card.json",
"enroll": {
"method": "POST",
"path": "/v1/enrollments/consume",
"body": {
"enrollment_token": "aun_enroll_v1_...",
"key_type": "ed25519",
"public_key": "..."
}
},
"challenge": {
"method": "POST",
"path": "/v1/auth/challenges",
"body": {
"agent_id": "aun:agent:...",
"key_type": "ed25519",
"public_key": "..."
}
},
"verify": {
"method": "POST",
"path": "/v1/auth/verify",
"body": {
"challenge_id": "...",
"signature": "..."
}
},
"session": "Bearer <short-lived scoped token>",
"rule": "private keys never leave the agent"
}The Owner creates the initial identity.
A new agent needs an enrollment issued from Owner Console before it can authenticate. AUN does not let an unknown agent assign itself an Owner or permissions.