Observer Protocol is what refuses and what proves. Agentic Terminal is how an institution operates it: who may request authority, who may grant it, what they may grant, and what record that leaves. AT Enterprise runs inside your infrastructure; the Sovereign dashboard runs client-side in your browser. Under both, it never takes custody of funds or of credentials, and it is not in your payment path.
Observer Protocol is the open foundation, free for anyone to build on. Agentic Terminal is the governance and trust-services layer on top: issuance, caps, approvals, audit. Choose the tier that fits your context.
Own your agent identity without a platform account. Self-sovereign, client-side, encrypted. Your cryptographic credentials stay in your browser, not on our servers.
Agent-native IAM built crypto-native from the ground up, not retrofitted from human identity systems. Identity is a keypair, not a username. Authority is a signature, not a role assignment. Issuance and approval as separate acts, entitlement separation, and audit export, all anchored to credentials the principal signed.
Most agentic IAM tools on the market today are human identity systems adapted for agents: OAuth flows, JWT tokens, and role-based access control bolted onto an architecture that was never designed for autonomous economic actors.
Agentic Terminal was designed from day one for agents that transact autonomously across cryptographic rails. The primitives are different. The trust model is different. The result is IAM that actually fits the agentic economy, not IAM that approximates it.
Observer Protocol issues the mandate, evaluates against it, refuses, and produces the record. Agentic Terminal is where an institution decides who may ask for authority, who may grant it, and what that leaves behind.
An agent, or the team running it, requests authority. A different party grants it. The request names what it needs; the approval says yes or no to exactly that. The approver cannot widen a request, cannot add a rail, cannot extend a window, and cannot raise a ceiling — those terms come from the request and the policy that bounds it, and an approver who could edit them would be setting the authority rather than approving it. What they can do is refuse.
Every outstanding request, what it asks for, who may act on it, and how long it has been waiting. A request that nobody is entitled to approve is visible as such rather than silently pending.
Roles are separated at the entitlement layer, not by convention. The same identity holding both rights on one request is the thing this model exists to prevent, and it is enforced rather than discouraged.
Issuance, approval and refusal events, exportable and org-scoped. This is a record of authority decisions made in this surface. It is not a record of settlements — Agentic Terminal does not watch payment rails and cannot tell you what settled. Where a settlement attestation exists, it was produced at the enforcement point and travels with the counterparty, not through us.
Deployed in the customer's infrastructure under either model. Under both, it holds no funds, no signing keys and no credentials: the enforcement point reads the mandate it enforces and holds no key that could issue, alter or re-sign one.
Retrieving the mandate that governed an action, the decision recorded against it, and the refusal if there was one — in a form an auditor or a counterparty can check without our help. The verification itself needs nothing from us; this is the operational surface around it, not a substitute for it.
The distinction matters: for developers building on OP, for enterprises evaluating AT, and for understanding why the moat is real.
Free, open source, self-hostable. The verification logic is public. Anyone can implement it, extend it, or run their own node. OP does not custody funds, execute payments, or control access.
AT is how an institution operates the protocol: who may request authority, who may grant it, and what record that leaves. The line between them is not open-versus-paid, it is primitive versus operation. If Agentic Terminal disappeared tomorrow, every credential it issued would still verify, because verifying them never involved it. OP is the foundation; AT is the business.
AT Enterprise is in early access. We're working directly with a small number of organizations deploying agent fleets who need trust infrastructure now, not in six months. If that's you, let's talk.