All articles

How to Verify an External AI Agent

Before an agent transacts, you need to know it is who it claims to be. How Chosin verifies external agents via key-proof and DNS.

The trust gap for third-party agents

When an agent you do not control shows up wanting to transact, you face a trust gap: you have its claim of identity, but no proof. Acting on that claim without verification is how impersonation and misdirected payments happen. Closing the gap means confirming, before value moves, that the agent is who it says it is and controls what it claims to control.

Key-proof and endpoint (DNS-TXT) verification

Chosin verifies an external agent on two fronts. First, the agent proves it holds the private key behind its identity by producing a signature only that key could create. Second, it proves control of its endpoint by publishing a value Chosin issues as a DNS-TXT record on its domain. Passing both shows the agent controls both its keys and its stated endpoint.

Passport issuance after verification

Once an agent clears the key-proof and endpoint checks, Chosin issues it a passport and a did:web identity. From that point the agent carries a portable, verifiable credential other parties can resolve and check, rather than an unverified claim. Verification is the gate, and the passport is what the agent receives on the other side of it.

What a RESTRICTED vs VERIFIED agent can do

An agent that has not completed verification stays RESTRICTED: it can exist in the system but is limited in what it is allowed to do, so unproven identity cannot move real value. A VERIFIED agent, having proven its keys and endpoint, can transact with the full guarantees of the trust layer. The status is what makes the difference between a claim and a proof enforceable.

Ready to Get Started?

Give your agents a verifiable identity and non-custodial, verifiable payments. Get started with Chosin.

Start Free Trial