BUILDERS.KYA-OS.ORG

BUILD ON KYA-OS

Verifiable identity, delegated authority, and signed proofs for AI agents.

Two lines of code give your MCP server a verifiable cryptographic identity and a signed receipt for every tool call. The identity is a did:key generated in-process and never shared. The receipt binds each request to its response, so any client or auditor can verify what your server did: no logs to trust, nothing to impersonate.

before · a standard MCP server, no identity or proofs
import { McpServer } from '@modelcontextprotocol/sdk/server/mcp.js';const server = new McpServer({ name: 'my-server', version: '1.0.0' });server.registerTool('greet', { description: 'Say hello' }, async (args) => ({  content: [{ type: 'text', text: `Hello, ${args.name}!` }],}));
after · every tool response carries a signed proof
import { McpServer } from '@modelcontextprotocol/sdk/server/mcp.js';import { withKyaOs, NodeCryptoProvider } from '@kya-os/mcp';  // +1 lineconst server = new McpServer({ name: 'my-server', version: '1.0.0' });await withKyaOs(server, { crypto: new NodeCryptoProvider() }); // +1 lineserver.registerTool('greet', { description: 'Say hello' }, async (args) => ({  content: [{ type: 'text', text: `Hello, ${args.name}!` }],}));

How it works

That's it. withKyaOs auto-generates an Ed25519 identity, registers the _kyaos protocol tool, and wraps the transport so every tool response includes a detached JWS proof in _meta. Invisible to the LLM, verifiable by anyone.

From there, one wrapper at a time:

  • Gate tools behind explicit human consent and scoped, revocable authority carried as W3C Verifiable Credentials (wrapWithDelegation).
  • Publish an Entity Card so MCP server.json, A2A AgentCards, and NANDA AgentFacts all project the same verifiable identity (the rails).

Your path, in order

  1. Get listed One JSON file and one pull request; the entry builder writes the file for you. build your entry ->
  2. Run the suite and submit your claim The starter takes you from clone to report in under an hour; the claim is one issue. how verification works ->
  3. Earn the credential and the badge An independent re-run issues a signed, revocable credential; the badge re-verifies it on every render. the badge ->

Define once, project anywhere

Your Entity Card is written once. KYA-OS projects it onto every discovery rail your agent needs, so the same identity appears wherever it is looked up. It does not ask the ecosystems you already speak to migrate: it projects your identity onto them.

  • Verified before it runs: the receiving server checks the proof and delegation constraints in-process, before the tool executes.
  • No migration: it wraps the transport you already have.
THE RAILS
how one proof reaches every protocol ->

Explore

Who is building on KYA-OS: implementations, services, templates, examples. One JSON file and one pull request to be listed.

conformance ->verifiable

Verified, not self-asserted. Run the pinned vector suite, submit your claim, and an independent re-run attests exactly the bytes it observed.

Define your Entity Card once; it projects onto MCP, A2A, and NANDA.

Every standard KYA-OS provides, carries, or projects: 19 rows with evidence, and an impl link into the reference implementation for everything shipping. Each row is dated, grounded in a W3C or IETF specification, and open to correction.

What people build: the on-chain kill switch (REVOKED), consent-gated tools, delegated spend budgets. Every recipe opens a real example.