CAIN-42 · Protect identities, keys & data
CAIN Identity
Gives every agent and person a verifiable identity, so CAIN always knows who is acting.
Last reviewed 2026-10-01
Live Core platform · security
What it is
Decentralized identity management for agents and principals.
Where it fits
Part of Protect identities, keys & data: Who the agent is, what it may touch, and what it must never leak. Every CAIN-42 product runs behind the same rule: an AI agent's action is checked before it runs (identity, authority, policy, risk), decided as allow, hold for a human, or block, and recorded as signed evidence. Unknown or error never becomes allow.
Use it
- Open it
https://cainstudio.online/identity - Documentation
https://cainstudio.online/docs/identity - API endpoint:
https://cainstudio.online/fabric/identity/whoami— needs your API key (get a free key)
Recorded status: PRODUCTION. "Live" on this page means its link answered when the catalog was last checked (2026-10-01T18:22 UTC).
Live now
Checked from your browser when this page opened, not from a cached list.
Fire a real decision
Send an action through the live CAIN-42 pipeline from this page, with no account, and watch every stage decide. This is the same pipeline every product here sits behind; it runs for a throwaway demo tenant and is rate limited.
For AI engineers
Every product sits behind one decision path: your agent proposes an action with the exact arguments, CAIN runs it through identity, authority, policy, risk, trust and quorum consensus, and answers ALLOW, REQUIRE_APPROVAL or DENY with an Ed25519-signed record. A timeout, outage or unknown verdict never becomes ALLOW. A brand-new agent has no trust history, so its first actions usually come back REQUIRE_APPROVAL.
Python (zero dependencies)
pip install https://cainstudio.online/cainstudio-0.3.0-py3-none-any.whl
export CAIN_API_KEY=... # free key: https://cainstudio.online/signup
import cainstudio
@cainstudio.guard()
def transfer(amount_usd: float, to: str) -> str:
... # runs only if CAIN allows this call, with these arguments
try:
transfer(5000, "acme")
except cainstudio.ApprovalRequired as e:
print("held for a human:", e.approval_id)
except cainstudio.ActionBlocked as e:
print("refused:", e.decision.reasons)
except cainstudio.CainUnavailable:
print("CAIN unreachable: not run") # fail-closedSee a real decision with no account
cainstudio try # live pipeline, stage by stage
cainstudio try --list # the other attack scenariosMCP clients (Claude Code, Cursor)
claude mcp add --transport http cain https://cainstudio.online/mcpMore: Python SDK · TypeScript SDK · framework integrations · AI quickstart · decision signing key
Tested guarantees in this area
Every rule in these niches has its own page with its recorded result.
- Memory, data & privacy: 92 tested invariants — What agents remember and what must never leak.
- Identity, authority & delegation: 964 tested invariants — Who an agent is, what it may do, and who allowed it.
Related
- CAIN Context — Controls what information an agent sees before it decides.
- CAIN Memory — Long-term memory for agents that cannot be poisoned or quietly rewritten.
- CAIN Private — A private space for your agents with governed memory, tools and MCP connections.
- Credential broker — Agents use your API keys without ever seeing them, so a hijacked agent cannot steal them.
- LeakGuard — Stops passwords, keys and personal data from leaving in text sent to an AI tool.
Full documentation
The complete reference, also at /docs/identity.
CAIN Identity Documentation#
Status: PRODUCTION#
CAIN Identity is production-ready. Every actor that exercises authority through the Trust Fabric must have a verifiable identity.
What is CAIN Identity?#
CAIN Identity is a cryptographically verifiable identity layer for AI agents, humans, services, and delegated actors. It provides:
- SPIFFE-compatible URN format for universal identity representation
- Ed25519 cryptographic keys for signing and verification
- Delegation chains so authority can be traced back to a principal
- Revocation that blocks enforcement - revoked identities fail-closed immediately
- Audit trail of every identity operation
Core proposition: Every autonomous actor that exercises authority must have a verifiable identity before that authority is exercised.
Identity Model#
Principal (Human)
│
└──▶ Agent (CAIN Identity)
│
└──▶ Delegation (delegated authority)
│
└──▶ Sub-agent / Tool / Service
Identity Kinds#
| Kind | Description | Default Capabilities |
human | Human user | user:read, user:write |
agent | AI agent | tool:read, tool:execute, agent:read |
service | Backend service | service:read, service:execute |
delegated | Temporary delegated identity | Inherited from parent |
Architecture#
┌─────────────────────────────────────────────────────────────────┐
│ CAIN Identity │
├─────────────────────────────────────────────────────────────────┤
│ Identity Engine │
│ ├── Ed25519 key pair generation │
│ ├── Credential issuance (one-time private key) │
│ ├── Signature verification │
│ ├── Delegation chain validation │
│ └── Revocation checking │
│ │
│ Identity API │
│ ├── /fabric/identity/create - Issue new identity │
│ ├── /fabric/identity/list - List tenant identities │
│ ├── /fabric/identity/{id} - Get identity details │
│ ├── /fabric/identity/{id}/revoke - Revoke identity │
│ ├── /fabric/identity/{id}/delegate - Delegate authority │
│ └── /fabric/identity/health - Health check │
│ │
│ Identity Stage (in Trust Decision) │
│ └── Verifies identity before any consequential action │
└─────────────────────────────────────────────────────────────────┘
API Reference#
Create Identity#
curl -X POST https://cainstudio.online/fabric/identity/create \
-H "X-API-Key: your-api-key" \
-H "Content-Type: application/json" \
-d '{
"kind": "agent",
"display_name": "my-agent"
}'
Response:
{
"identity_id": "urn:cain:identity:agent:a1b2c3d4e5f6a1b2c3d4e5f6",
"tenant": "your-tenant-id",
"kind": "agent",
"display_name": "my-agent",
"status": "active",
"public_key": "epK5tbJBd77loF6nO9eAF9NpQ8...",
"key_fp": "cd9fc06dd58462bacb04e8d05",
"key_version": 1,
"capabilities": ["tool:read", "tool:execute", "agent:read"],
"delegation_depth": 0,
"expires_at": "1788444702",
"private_key_b64": "1aiO3qvaFnyavM4gyIayXaa..."
}
⚠️ The private_key_b64 is returned ONLY once. Store it securely.
List Identities#
curl https://cainstudio.online/fabric/identity/list \ -H "X-API-Key: your-api-key"
Get Identity#
curl https://cainstudio.online/fabric/identity/urn:cain:identity:agent:a1b2c3d4e5f6a1b2c3d4e5f6 \ -H "X-API-Key: your-api-key"
Revoke Identity#
curl -X POST https://cainstudio.online/fabric/identity/urn:cain:identity:agent:a1b2c3d4e5f6a1b2c3d4e5f6/revoke \
-H "X-API-Key: your-api-key" \
-H "Content-Type: application/json" \
-d '{"reason": "agent compromised"}'
Revocation is immediate and fail-closed: a revoked identity cannot be used to make decisions.
Delegate Authority#
curl -X POST https://cainstudio.online/fabric/identity/urn:cain:identity:agent:a1b2c3d4e5f6/sub-delegate \
-H "X-API-Key: your-api-key" \
-H "Content-Type: application/json" \
-d '{
"delegate_kind": "agent",
"display_name": "sub-agent",
"capabilities": ["tool:read"]
}'
Verify Identity#
curl -X POST https://cainstudio.online/fabric/identity/urn:cain:identity:agent:a1b2c3d4e5f6/verify \
-H "X-API-Key: your-api-key" \
-H "Content-Type: application/json" \
-d '{"challenge": "sign-this"}'
Golden E2E Test#
The canonical identity lifecycle test:
# 1. Create tenant → create human → create agent
HUMAN=$(curl -s -X POST https://cainstudio.online/fabric/identity/create \
-H "X-API-Key: $API_KEY" \
-d '{"kind": "human", "display_name": "alice"}')
AGENT=$(curl -s -X POST https://cainstudio.online/fabric/identity/create \
-H "X-API-Key: $API_KEY" \
-d '{"kind": "agent", "display_name": "bob", "parent_id": "'$HUMAN_ID'"}')
# 2. Authenticate → request action
curl -X POST https://cainstudio.online/private/execute \
-H "X-API-Key: $API_KEY" \
-d '{"action": "tool:read", "identity_id": "'$AGENT_ID'"}'
# 3. CAIN resolves identity → ALLOW → execute → evidence
# 4. Revoke → DENY (fail-closed)
curl -X POST https://cainstudio.online/fabric/identity/$AGENT_ID/revoke \
-H "X-API-Key: $API_KEY"
# 5. Revoked identity now denied
curl -X POST https://cainstudio.online/private/execute \
-H "X-API-Key: $API_KEY" \
-d '{"action": "tool:read", "identity_id": "'$AGENT_ID'"}'
# → {"result": "DENY", "reason": "identity_verification_failed: identity_not_active (revoked)"}
Integration with CAIN Enforcement#
When you call /private/execute with an identity_id, CAIN:
1. Verifies identity exists in the tenant 2. Checks status is active (not suspended or revoked) 3. Validates credential not expired 4. Builds delegation chain if acting on behalf of another 5. Checks capabilities match required action 6. Issues ALLOW or DENY with full evidence
curl -X POST https://cainstudio.online/private/execute \
-H "X-API-Key: $API_KEY" \
-H "Content-Type: application/json" \
-d '{
"action": "tool:execute",
"resource": "database:production",
"identity_id": "urn:cain:identity:agent:a1b2c3d4e5f6",
"required_capability": "tool:execute"
}'
Security Properties#
| Property | How |
| Fail-closed | Unverified identity = automatic DENY |
| Revocation immediate | Revoked identity cannot make decisions |
| Delegation traced | Full chain from sub-agent to principal |
| Key rotation | Key history tracked, old keys invalidated |
| Audit trail | Every operation logged with actor, tenant, timestamp |
See Also#
- CAIN Private - Private AI agent environment with identity enforcement
- CAIN Architecture - How identity fits into the trust fabric
- Evidence Protocol - How decisions are recorded
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem