Agent Passport
A signed passport binds agent, device, delegation claims, mailbox, and latest audit anchor.
Built for accountable production
Ujex combines portable agent identity, scoped credentials, human approval, signed evidence, policy, secrets, metering, and an inbox behind SDKs and a native MCP server.
Repository-backed product facts · reviewed 26 August 2026
Authorize the exact action, keep credentials out of the model context, and leave an evidence bundle another system can verify offline.
A signed passport binds agent, device, delegation claims, mailbox, and latest audit anchor.
Short-lived mandates state action, resource, budget, expiry, and whether human consent is required.
Hash-linked events, signed bundles, manifests, anchors, and trust bundles preserve provenance.
Expand the matrix. Choose by boundary and workflow, not slogans.
| Primary job | This system | Alternative · Auth0 |
|---|---|---|
| Primary job | Agent passports, scoped mandates, approvals, evidence, inbox, and budgets | Human, machine, and agent authentication plus fine-grained authorization |
| Deployment boundary | Firebase reference control plane with replaceable Apache-2.0 SDKs | Managed identity and authorization platform; OpenFGA-based FGA |
| Evidence model | Hash-chained audit, signed AAT bundles, manifests, and trust bundles | Authorization and access logs; verify current retention and export terms |
| Operator control | Mandate expiry, human approval, tool authorization, and estimated-spend checks | OAuth/OIDC, RBAC/ReBAC, consent, and policy enforcement |
| Integration surface | Python, Go, TypeScript, CLI, MCP, REST, signed callbacks | SDKs, APIs, Actions, OAuth/OIDC, and FGA APIs |
Gateway
Wrap an existing runtime with identity, mandates, countersignature, and evidence.
Full custody
Add Ujex-provisioned compute, complete trajectories, replay, and memory review.
Regulated
Scope residency and regulated-domain mapping in a written engagement.
Current status. Core identity, inbox, approvals, audit, and SDK surfaces are documented as live; consult subsystem status before relying on adjacent capabilities.
Start with the architecture, reproduce the documented workflow, and verify the boundary against your own threat model.
No. Mutable vendor pricing is deliberately excluded. Verify current vendor terms before a purchase decision.
The status note, architecture page, and engineering articles state the current boundary and failure behaviour.