The trust authority for AI agents.
MeshKor proves what an agent is and what it may reach — provably, across organizational boundaries.
It certifies agents built anywhere, on any stack, so an agent representing a real party can prove it is genuinely who it claims to be when it shows up to transact with someone who didn't build it. Think of it as the passport office for agents, and the AIN as the passport.
Everybody is building agents. Almost nobody is building the layer that lets you trust one when it leaves home.
An agent inside your own system runs on trust you already granted it. The hard part starts when an agent from outside your walls shows up to transact — place an order, make a commitment, move money — and you have no way to know it is genuinely who it claims to be, or what it is actually allowed to do.
Impersonation
A stranger agent can claim to represent a real business and there is no authority to check it against. A certificate is only worth as much as the check behind it.
Too much reach
Agents with production access and standing credentials can take destructive, irreversible actions — with no attacker required. The blast radius is the risk.
Shared runtimes
When agents share an environment, one loose permission can let one reach another's data or code. Shared space should never mean shared authority.
A bot joins the Trusted Bot Programme by getting certified — and gets an AIN.
Membership is not a name on a list. A certified bot carries a full envelope that travels with it: a structured identity, a tamper-evident history, encryption, and the ability to prove itself in a single pass. Getting in is meant to be easy so millions do it; membership is meaningful so receivers can rely on it.
Easy to join
Enrollment runs on an automated check — a business identifier plus a domain-verified email. No heavy personal data to hold, and cost per issuance stays near zero, which is what makes verifying at volume work.
Two births, one lineage
Every release gets a Build AIN that seals what the software may ever do; every running instance gets a Deployment AIN whose reach is a provable subset of it. Both read like a UPC, are sealed into signed birth records so they can't be forged, and bind the real-world identity by hash rather than in the clear.
One authority
Every verification traces back to MeshKor. Builders and receivers each talk only to the authority, never to each other, so trust has a single, consistent root instead of a web of private arrangements.
One side enrolls agents. The other validates them. Neither has to touch the other.
Builders certify the agents they run and receive AINs. Receivers accept transactions from agents they didn't build, and check each incoming agent against the authority. Both talk only to MeshKor.
Enroll your agents, get AINs
Give every agent you run a provable identity and a history that can't be quietly rewritten — so it's trusted the moment it leaves your systems.
- Certify agents built on any framework or stack
- Attach the credential with a drop-in client, no rebuild
- Carry a sealed identity and a tamper-evident history
- Prove authenticity in a single pass, even for sleeping agents
// start here — builders come first
Validate incoming agents
When an outside agent transacts with you, confirm it's genuine and see exactly what it's permitted to reach — with one lookup against the authority.
- Check any incoming agent against MeshKor
- Tell an identified agent from an audited one
- See the declared blast radius before you act
- No integration with the builder's stack required
// as certified agents spread, ignoring them gets riskier
Proof of who an agent is, and a record of what it has done — cheaply, at scale.
The pedigree is a sealed birth record plus a tamper-evident history chain. Birth alone would miss later tampering; history alone could be anchored to a forged origin. The point is the unbroken line from a verified origin through a verified history.
A constant-size summary keeps verification flat no matter how long the history grows. A cheap FAST check serves the routine many; a deep FULL walk is there for the rare few. Verification is single-pass and asynchronous, so it fits event-driven agents that spend most of their time asleep.
Capability manifest
The rules an agent is born with become machine-readable: the tools it may call, the endpoints it may reach, the credential scopes it may hold, and a declared blast radius. Sealed into the signed birth, so an agent can't widen its own reach later without breaking its pedigree.
Runtime sandbox
A wrapper verifies the agent, loads its sealed manifest, and refuses anything outside it. Any blocked attempt is a clean, binary divergence between what was permitted and what was tried — a sharp signal, not a fuzzy threshold.
Credential root
MeshKor issues short-lived, scoped tokens — only against a passing verification, and only for scopes already in the manifest. No standing secrets left lying around for a rogue agent to steal and no way to reach past the declared blast radius.
Identity is the base. Some receivers will want more, and can pay for more.
The base AIN certifies who stands behind an agent and that its history is intact. It doesn't claim the agent has been inspected. That deeper assurance is a separate rung, kept deliberately distinct so a receiver can always tell which one they're looking at.
Identified
The base AIN. A real party stands behind this agent, and its origin is cryptographically authentic.
Accountable
Identity plus a tracked, tamper-evident history and behavioral monitoring that watches conduct separately from authenticity.
Audited
A deeper examination of what the agent actually does, scoped to what it can affect — from answering questions to moving money.
Capable projects govern agents inside their own walls. None proves a stranger agent is genuine across them.
Orchestration frameworks coordinate the agents you built. Development-security tools govern what your coding agents do inside your pipeline. Self-improving harnesses make a single agent better over time. Each of them governs agents inside its own trust boundary — and that's exactly the boundary MeshKor works across. An agent that changes month to month is precisely the one a receiver would most want a verifiable pedigree for. That cross-boundary trust is an open lane, and it's the one we're building in.
Prove your agents are who they say they are.
MeshKor is in preview. Join the waitlist and we'll reach out as we open enrollment to the first builders.
No spam. We'll only email you about preview access.