The open standard for AI agent identity, accountability, and content provenance. Vouch v1.6 is a complete end-to-end implementation: W3C Verifiable Credentials secured by Data Integrity proofs (eddsa-jcs-2022 cryptosuite), Decentralized Identifiers, and Multikey verification methods. An optional post-quantum profile adds a second, independent ML-DSA-44 proof (mldsa44-jcs-2024) beside the Ed25519 one on the same credential, a proof set aligned with NIST CNSA 2.0 / NSM-10 timelines in which either proof can be checked on its own. The Python, TypeScript, and Go implementations produce byte-identical canonical form, verified against shared RFC 8785 JCS test vectors.

Where comparable FLOSS projects address a single layer - media-only content provenance, agent runtimes without identity, hallucination guards without cryptographic accountability - Vouch provides the underlying identity-and-liability layer those projects build on or complement.

Covered in one coherent codebase: agent identity (DIDs + Multikey), intent attestation, delegation chains, the identity sidecar pattern (LLM-isolated keys), the heartbeat protocol for continuous trust renewal, federated validator quorum, behavioral attestation, content provenance via C2PA and CAI, audio watermarking and voiceprint enrollment, model lineage and cryptographic weight binding, retrieval-anchored proof of non-hallucination, and 47 defensive prior-art disclosures published CC0 so the core mechanisms cannot be patent-captured by any single vendor.

Distribution: Python SDK (PyPI), TypeScript SDK (npm), Go sidecar, Rust mobile core, browser extension, GitHub App, Cloudflare Workers verification gateway, native Model Context Protocol integration, and adapters for LangChain, CrewAI, AutoGPT, AutoGen, Vertex AI, Google ADK, and n8n.

Fund this project

Unverified URL

The funding manifest has not provided proof via wellKnown that this link is associated with it. Learn more.

Continue