Agent KYC · live in production

You gave it the keys.
Claw gives you the kill switch.

Trusted Agents. Trusted Vendors. Receipts as math. Every autonomous agent carries a cryptographic credential bound to its operator, leashed by policy, with a tamper-evident receipt of every action. Verify in three lines. Free forever for vendors.

// hub live at api.holdtheleash.id · SDK on GitHub · Apache 2.0

verified. A crab on a leash — your agent, collared and under your control
// live

Watch them check in.

Every action, gated the instant it happens. Green clears the leash. Amber waits for you. Red never lands.

claw://check-in · global stream LIVE
// the flow

Four moves. The whole system.

Identity that can't be faked, action that gets logged, a record nobody can rewrite, and a stop you can hit any time.

01

Issue

The hub signs a credential to your agent's key. Unforgeable — nobody mints a Claw without the hub. This is the part that can't be faked.

02

Check in

Before it acts, the agent presents its Claw and proves it owns the key. Valid, scoped, not revoked → pass. Every check-in is logged.

03

Anchor

The log is fingerprinted and anchored — tamper-proof receipts. We prove what happened without ever exposing the contents.

04

Revoke

Flip a token and it's dead — instantly, everywhere it's checked. The kill switch you hold over your own agents.

// programmable token

The token is a leash. You set how long it is.

A Claw isn't just an ID badge. It carries the rules you wrote. The hub enforces your config — it never makes the call for you.

A crab holding the ID badge — the Claw credential
Spend ceilingmax the agent can burn / month
$50.00
Active windowwhen the token is live
09:00 — 17:00
Allowed surfaceswhat it's permitted to touch
4 approved
Escalate to humanping me to approve over $20
Auto-revoke triggerkill on first off-leash action
  • Budget caps, rate limits, and hard expiry — the agent can't outspend or outlive its leash.
  • Scope it to exactly the services it needs. Everything else is a closed door.
  • High-stakes actions bounce to you for a yes/no before they ever land.
  • Set a trip-wire: one off-leash move and the token revokes itself.
  • Real control, not control theater — every switch here actually fires.

One agent goes rogue at 3am. Cut it off from your phone.

// the passport

The Claw goes everywhere the agent goes.

A Claw isn't an ID badge that stays at the door. It's a passport — your agent carries it to every service it visits. Anyone can verify it (signature, scope, status, owner) in one round trip. The leash travels with it. The kill switch travels with it. Every verified service it touches adds a stamp to its record. Agent KYC: cryptographic, instant, permissionless.

// about

What we built. What it solves. How it's secured.

The agent economy is being built on a layer that doesn't exist yet: identity, accountability, and a kill switch. People are letting AI agents loose with their credentials, their inboxes, their wallets, their shell access — usually because the agent said "sure!" once during testing. No record of what it did. No way to stop it mid-action. No recourse when something goes wrong.

Claw is that missing layer. Cryptographic identity for every agent. A programmable leash the owner sets. A kill switch that propagates in real time. A tamper-proof receipt for every action — at every service the agent ever touches.

If you can't revoke it, you don't own it — it owns you. Claw is what owning an agent actually feels like.

The Claw ID — a crab holding a gold ID badge

How the technology works

How it's secured

// for owners

What you get when you Claw your agent.

  • Mint a Claw for any agent you own — CLI or dashboard.
  • Set the leash: budget caps, allowed surfaces, time windows, escalation thresholds, auto-revoke trip-wires.
  • Watch a live feed of every action the agent takes — pass, hold, deny — in real time.
  • Revoke from the dashboard or your phone. Propagates to every verifier on earth in seconds.
  • Tamper-proof receipts of everything the agent did, at every vendor it ever touched.
  • Passkey login + offline backup codes. No email recovery — we can't reach you that way and neither can your agents.
  • Multiple agents, multiple leashes, one account.

// for vendors

What you get when you accept Claws.

  • Add claw.verify(token, request) to your code in three lines — Python, JS, Go SDKs.
  • Free to verify, forever. No fees, no plans, no API limits.
  • Know exactly who owns each agent hitting your API — and what its owner permitted.
  • Read the leash and decide whether to serve — before serving.
  • Cryptographic proof the agent presenting the Claw actually holds the key. No stolen-token attacks.
  • Live revocation. If an owner kills a token mid-call, you see it before completing.
  • Free listing in the verified-vendor directory at holdtheleash.id. KYB verification required; never a fee.
// for vendors

Free forever. Three lines of code.
A Claw'd agent is a customer worth having.

Verify any agent hitting your API in three lines. You learn who owns it, what its leash allows, and a tamper-evident record exists of every interaction — on your side too. Free to verify. Free to list. Forever. No paid tier to "be found." We monetize the operator side, never the verifier. The network effect requires zero friction on yours.

EXAMPLEverify in 3 lines

Your payments API

Agent-native payments. Verifies every transaction against the owner's leash before clearing.

EXAMPLEscoped tokens

Your storage API

Scoped storage for agent workloads. Honors the leash's allowed-surfaces, refuses what isn't.

EXAMPLElive revocation

Your outbound network

Outbound network for agents. Polls revocation live — the owner's kill switch stops a call mid-flight.

// example vendors shown · apply to be a Verified Vendor →

// the difference matters

Eight platforms tried to solve agent identity in 2026.
None watch what agents do after they're given a token. We do.

Static OAuth issues a credential and walks away. AI firewalls filter prompts. Wallet-tied identity ships you to a checkout page. ClawID requires the agent to check back in on every action — proof of possession, leash policy, signed receipt, one round trip. The market is still writing the IETF draft for what we already ship.

capability
ClawID
Okta for AI Agents
Stytch Connected Apps
Skyfire / KYA
Runtime check-in / agent leash
Cryptographic receipts (hash chain)
Free for the verifying side, forever
Free tier for operators (10k/mo)
Three-line verify SDK
Status
Live · paying customers
GA Apr 30 2026
GA
GA
implements it partial / adjacent not in their model

// vendor capabilities reflect publicly available product information as of June 2026. The "none watch what they do" framing is independently sourced — a May 2026 MarkTechPost roundup of 8 leading platforms concluded "none implement periodic check-ins, cryptographic receipts, or 'agent leash' mechanics." The Cloud Security Alliance reached the same conclusion in their May 2026 critique of the static-OAuth approach.

// pricing

Vendors verify free, forever.
Operators meter by the check-in.

Infrastructure pricing, not SaaS pricing. We meter by the unit of work — every check-in your agent makes. No seat tax. No per-agent fee. Vendors pay nothing to verify, ever — that's the architecture, not a launch promo.

// vendors Verification is permissionless and free, forever. Three lines of code, no key, no contract, no per-call fee. KYB-gated directory listing is also free.
Get the SDK →
Solo
$0 / to start
  • 1 agent license
  • 10k check-ins / mo free
  • Leash builder + kill switch
  • 72h rolling audit window
  • Downloadable receipts (CSV / JSONL)
Mint free →
MOST OPERATORS
Operator
$0.005 / check-in
  • Unlimited agents
  • First 10k check-ins / mo free
  • Cryptographic anchor + chain-head receipts
  • Dual-chain audit (operator + vendor verifiable)
  • Instant global revocation
  • Volume tier: $0.003 over 1M / mo
Start metering →
Sovereign
Custom
  • Private hub / dedicated signing key
  • BYO KMS / HSM
  • On-prem audit chain export
  • Zero-trust deployment review
  • SLA-backed verification
Talk to us →

// comparable infrastructure: Twilio Verify is $0.05 / verification (SMS OTP only) · Persona KYC is $1.50+ / verification (humans, docs) · ClawID at $0.005 / check-in is 10× cheaper, for cryptographic agent identity with leash and live revocation

// get started

Live in production. Three lines to verify.

The hub runs at api.holdtheleash.id with the root signing key in Cloud KMS — zero-trust, production posture. SDKs are open source under Apache 2.0. Vendors verify in three lines, free forever. Operators mint and manage from the dashboard.

// vendors · verify a Claw
# install the SDK
$ pip install clawid

# three lines — done
import clawid

result = clawid.verify(token)
if result.valid:
    serve(result.agent_id, result.tenant_id)
else:
    deny(result.status, result.reason)

// free forever · github.com/projectblackboxllc/claw-sdk-python

// operators · mint a Claw
# 1. sign in to the dashboard with a passkey
$ open https://app.holdtheleash.id

# 2. set the leash:
#    spend cap, allowed surfaces,
#    active hours, escalation,
#    auto-revoke trip-wire

# 3. mint — token shown ONCE
#    private key generated locally,
#    hub never sees it

// passkey-only · no email recovery · app.holdtheleash.id

Live now — mint your first Claw or wire the SDK in.

// production hub at api.holdtheleash.id · SDKs Apache 2.0 · verification permissionless and free

We're not responsible for your agent.
You are.

Claw is the road and the license — not the driver. We give you the rails, the leash, the kill switch, and the receipts. What your agent does is on you. We just make sure it can't do it as a ghost.