OATI是一个开放标准,用于识别企业代理、授权短期委托、强制执行交易约束,并跨组织边界生成可验证的操作收据。

Stars

12

7 天增长

暂无数据

Fork 数

0

开放 Issue

1

开源协议

Apache-2.0

最近更新

2026-07-28

AI 仓库情报摘要
FR-AI / ANALYSIS

为什么值得关注

它提供了一个可移植的交易模型,将身份、权限、策略和证据绑定在一个系统中,旨在补充OAuth、OIDC和SPIFFE等现有标准而不取代它们,并包含针对商业和现实世界资产的领域配置文件。

适合谁使用

  • 构建代理系统的企业开发者
  • 集成多方信任的平台工程师
  • 设计委托授权的安全架构师
  • 需要可验证交易证据的合规团队

典型使用场景

  • 在API访问前验证企业代理身份和委托权限
  • 在买方签发的采购委托下购买API请求并遵循约束
  • 根据资产状态声明控制代币铸造并满足批准阈值
  • 生成签名的操作收据用于审计和争议解决

项目优势

  • 开放标准,Apache 2.0许可,无需供应商锁定即可实现
  • 确定性非放大不变性防止静默权限升级
  • 领域配置文件在保留核心模型的同时增加严格语义
  • 全面的CLI、SDK(TypeScript、Python、Go)和一致性测试套件用于验证

使用前须知

  • 目前处于早期开发者预览阶段,需要独立的加密审查
  • 生产查找服务和商业控制平面未开源
  • 额外的SDK语言正在积极开发中,尚未完成

README 快速开始

OATI

Trusted transactions between enterprise agents.

Open Agent Trust Infrastructure (OATI) is an open standard by Intelliger for identifying enterprise agents, expressing short-lived delegated authority, enforcing transaction constraints, and producing verifiable action receipts across organisational boundaries.

An API credential can show that an agent may connect. OATI describes who owns the agent, on whose authority it acts, what it may do now, and what evidence proves the transaction.

  • Website: https://intelliger.ai/oati
  • Public lookup: https://intelliger.ai/oati/lookup
  • Machine API: https://api.intelliger.ai/oati/v1
  • Licence: Apache 2.0
  • Status: developer preview

Why OATI

Enterprise controls are split across identity providers, gateways, policy engines, data platforms, contracts, payments, and audit systems. A valid token alone does not reveal the responsible organisation, current delegated purpose, downstream data restrictions, commercial authority, or mutually verifiable evidence.

OATI binds those concerns into one portable transaction model:

Verified organisation + Agent Passport + short-lived Mandate
        + Transaction Envelope + deterministic decision
        + signed Action Receipt

OATI complements OAuth, OIDC, SPIFFE, AuthZEN, Cedar, OPA, MCP, and A2A. It does not replace them.

Core objects

ObjectAnswers
Agent PassportWho is this agent, who operates it, and how is that claim verified now?
Agent MandateWhat exact authority was delegated, by whom, for what purpose, and until when?
Transaction EnvelopeWhat action, resource, destination, context, and proof are being evaluated?
Authorisation DecisionWas the transaction allowed, denied, transformed, or sent for approval—and under which policy?
Action ReceiptWhat happened, under which authority and controls, and what signed evidence can be checked later?

The central invariant is non-amplification: a delegated Mandate may preserve or reduce authority, but it must never silently expand it.

Domain profiles

OATI profiles add strict domain semantics while preserving the same core identity, authority, policy, and evidence model.

Commerce 0.1 — paid APIs and digital services

The first Commerce workflow lets an enterprise agent p

项目描述

Open Agent Trust Infrastructure (OATI) — an open standard for verifiable AI agent identity, delegated authority, policy enforcement, and signed action receipts.

相关仓库与替代方案

根据分类、Topic 和编程语言匹配的相似项目。

mereyabdenbekuly-ctrl
精选
mereyabdenbekuly-ctrl GitHub avatar

clodex-ide

Clodex is an open-source, local-first agentic IDE that combines persistent AI tasks, code, terminal, browser, Git, models, memory, and governed execution in one Electron workspace, currently in technical preview.

AI 与机器学习AI 智能体
859
0xwilliamortiz
精选
0xwilliamortiz GitHub avatar

openclaude-improved

OpenClaude is an open-source CLI coding agent that runs on any platform and supports a wide range of LLM providers, offering the same tools and workflows as Claude Code.

AI 与机器学习大语言模型
577
deerwork-ai
精选
deerwork-ai GitHub avatar

deer-workflow

An open-source Dynamic Workflow runtime that combines deterministic TypeScript orchestration with replaceable Agent runtimes.

AI 与机器学习大语言模型
312