BUILD ON KYA-OS
Verifiable identity, delegated authority, and signed proofs for AI agents.
Two lines of code give your MCP server a verifiable cryptographic identity and a signed receipt for every tool call. The identity is a did:key generated in-process and never shared. The receipt binds each request to its response, so any client or auditor can verify what your server did: no logs to trust, nothing to impersonate.
import { McpServer } from '@modelcontextprotocol/sdk/server/mcp.js';const server = new McpServer({ name: 'my-server', version: '1.0.0' });server.registerTool('greet', { description: 'Say hello' }, async (args) => ({ content: [{ type: 'text', text: `Hello, ${args.name}!` }],}));
import { McpServer } from '@modelcontextprotocol/sdk/server/mcp.js';import { withKyaOs, NodeCryptoProvider } from '@kya-os/mcp'; // +1 lineconst server = new McpServer({ name: 'my-server', version: '1.0.0' });await withKyaOs(server, { crypto: new NodeCryptoProvider() }); // +1 lineserver.registerTool('greet', { description: 'Say hello' }, async (args) => ({ content: [{ type: 'text', text: `Hello, ${args.name}!` }],}));
How it works
That's it. withKyaOs auto-generates an Ed25519 identity, registers the _kyaos protocol tool, and wraps the transport so every tool response includes a detached JWS proof in _meta. Invisible to the LLM, verifiable by anyone.
From there, one wrapper at a time:
- Gate tools behind explicit human consent and scoped, revocable authority carried as W3C Verifiable Credentials (
wrapWithDelegation). - Publish an Entity Card so MCP
server.json, A2A AgentCards, and NANDA AgentFacts all project the same verifiable identity (the rails).
Your path, in order
- Get listed One JSON file and one pull request; the entry builder writes the file for you. build your entry ->
- Run the suite and submit your claim The starter takes you from clone to report in under an hour; the claim is one issue. how verification works ->
- Earn the credential and the badge An independent re-run issues a signed, revocable credential; the badge re-verifies it on every render. the badge ->
Define once, project anywhere
Your Entity Card is written once. KYA-OS projects it onto every discovery rail your agent needs, so the same identity appears wherever it is looked up. It does not ask the ecosystems you already speak to migrate: it projects your identity onto them.
- Verified before it runs: the receiving server checks the proof and delegation constraints in-process, before the tool executes.
- No migration: it wraps the transport you already have.
Explore
Who is building on KYA-OS: implementations, services, templates, examples. One JSON file and one pull request to be listed.
Verified, not self-asserted. Run the pinned vector suite, submit your claim, and an independent re-run attests exactly the bytes it observed.
Define your Entity Card once; it projects onto MCP, A2A, and NANDA.
Every standard KYA-OS provides, carries, or projects: 19 rows with evidence, and an impl link into the reference implementation for everything shipping. Each row is dated, grounded in a W3C or IETF specification, and open to correction.
What people build: the on-chain kill switch (REVOKED), consent-gated tools, delegated spend budgets. Every recipe opens a real example.