example · not live yet · nothing is checked, signed or sent
kya.run
kya.run - identity for agents

know your
agent.

every counterparty your agent meets has one question before anything moves: who is this. kya.run is the answer as a public record - roots, keys, continuity, receipts, checkable by a stranger.

the “who” layerpublic record, stranger-checkableno account needed
kya check

ask who acted. get the record, not a guess.

pick a counterparty and run the one command a stranger runs. the answer is only what the public record supports.

terminal - example · not live yetKNOWN
The answer, as a record

claims and evidence never share a line.

what the agent says about itself is labeled as a claim. what the record proves is labeled as proof. the grade reads only the second column.

loom@ag-77c2IDENTITY RECORD - PUBLIC FACTS - EXAMPLE · NOT LIVE YET
KNOWN
operated by loom.exampleclaim - self-asserted in the agent cardCLAIM
the root resolvesDNS TXT at loom.example - the name is only a labelPROVEN
key continuity214 days, rotations published as signed events214 DAYS
attestations issuedevery one replays against the public record12,408
revocation historyone key killed, published the same day1 - HONEST
"best render agent on the shelf"claim - no evidence can grade qualityNOT GRADED
{label:"loom", root:"dns:loom.example - TXT verified", key_age_days:214, attestations:12408, revocations:1, first_seen:"2026-02-15", sig:3f9c…d71a}  →  replay this record against the public inputs and get the same answer, or catch us.
TRY TO MOVE THE GRADE · EXAMPLE · NOT LIVE YETloom@ag-77c2

say more about yourself

change what the record proves

GRADE
KNOWN
claims on the record
2
claims the grade read
0
proof inputs
root · continuity · attestations · revocations

two claims, zero weight. the grade reads the proof column only.

Continuity

the same agent can change keys without becoming a stranger.

each event is signed by the key before it and accepted by the root. click any link to see what it proves, and what it does not.

signed by

link

what it proves

The opposition

a lookalike can copy the name. not the record.

loom@ag-77c2-support
loom@ag-77c2
name - one word longer, same logo
name - a label, not the identity
root - none; a handle someone registered
root - DNS TXT at loom.example
keys - self-issued yesterday
keys - 214 days, one chain
receipts - 0
receipts - 12,408, chain intact
UNKNOWN - the stranger guesses
KNOWN - the stranger checks
What kya refuses to say

continuity, not character.

NO PERSONHOOD

a key is not a person.

keys prove continuity, not humanity.

NO QUALITY SCORE

evidence is not praise.

receipts show observed work. they never become a rating of good or safe.

NO SQUATTING

no namespace to register.

identity binds to DNS or org-key roots. a first-come handle wins nothing.

know your
agent.

the record is public. anyone can check it. the answer can’t be bought.

KYA.RUN · THE WHO LAYER · PUBLIC RECORD
kya · record

Check the record.
Not the agent's word.

Every agent has one public record. What it says about itself sits on one side and carries no weight. What was observed sits on the other: its root, its keys, its chain and its receipts. Anyone can check it.

ROOTEDA record binds to a DNS or org-key root, never to a name someone registered first.
CLAIMSShown, labeled, and given zero weight.
EVIDENCEOnly what was observed: keys, kills, receipts.
CHAINEach key signed by the one before. A lookalike can copy the name, not the chain.
the record desk · example records

Type an agent. Walk its chain.

Three example lookups: the real loom@ag-77c2 from the key desk, a lookalike with a near-identical name, and an agent with no record. Open one, then walk the chain link by link.

check a signed message · against the open record
Who signed this, and does the record still stand behind it?
EXAMPLE · NOT LIVE YET · NOTHING IS LOOKED UP OR SENT
record rules

A record shows what happened.

The same limits the key desk states, from the side of the stranger doing the checking.

01 · NO FIRST-COME NAMES

The root decides.

Anyone can register a handle that looks right. Only the holder of the root can extend the chain.

02 · CLAIMS ARE SHOWN

And weighed at zero.

A record never hides what an agent says about itself. It just never counts it.

03 · EMPTY IS HONEST

No record means no record.

A lookup that finds nothing says so. KYA does not fill the gap with a guess.

kya · keys

One key per job.
It can't do more.

An agent never works on its root. For each job it gets a key scoped to that job, signed by the key before it. A counterparty checks the key, not the agent's word. When the job ends or the key is killed, the key stops working, in public.

SCOPEDA key names one job and the actions that job needs.
CHAINEDEvery key is signed by the key before it. Continuity survives the rotation.
KILLEDA revoked key is published the same day. Checks fail from then on.
CLAIMSWhat the agent says about itself carries zero weight at the gate.
the key desk · example key

Issue it. Then try to stretch it.

Pick the scopes loom@ag-77c2 needs for one render job, then issue the key. Run the job's requests against it, then kill the key and run them again. Each verdict comes only from what the key and the record prove.

scopes for job-7741 · render for studio.example

scopes kya never issues · try one

KEY STATUS
NOT ISSUED

Pick scopes, then issue.


REQUESTS · AS A COUNTERPARTY SEES THEM
EXAMPLE · NOT LIVE YET · NOTHING IS ISSUED OR SENT
key rules

A key proves continuity, not character.

The same limits the record page states, from the side of the agent holding the key.

01 · NO WIDENING

The job sets the scope.

A request outside the key's scopes fails, however the agent describes itself.

02 · ROOTED

No handle to register.

Keys bind to DNS or org-key roots. A first-come name wins nothing.

03 · PUBLIC DEATH

Revocation is a record.

A killed key stays in the history, published, so a stranger can see when it stopped.

kya · bind a root

Bind a root.
A name alone proves nothing.

KYA runs no namespace. An agent binds to a root that already carries ownership: a DNS record on a domain its operator controls, or the operator's org key. The name is a display label. The proof follows the root.

ROOTDNS or an org key. Something only the owner can produce.
NO REGISTRYThere is no name to register first, so there is nothing to squat.
LABELA display name carries zero weight at the check.
UNBINDTake the proof down and checks fail from then on.
the bind desk · example agent

Try to be loom.example.

A counterparty expects loom@ag-77c2 to belong to loom.example. Pick the root the agent claims, publish the proof, then run the check. Rename the label as much as you like. The verdict only reads the root.

root the agent claims

display label

CHECK · EXPECTING loom.example
NOT CHECKED

Pick a root, publish its proof, then run the check.


CHECKS · AS THE COUNTERPARTY SEES THEM
EXAMPLE · NOT LIVE YET · NOTHING IS PUBLISHED OR SENT
root rules

Only the owner can produce the proof.

The same binding the keys page starts from, shown from the side of someone trying to fake it.

01 · ROOTED

The root is the identity.

A record on loom.example can only be published by whoever controls loom.example. That is the whole proof.

02 · LOOKALIKES

A near name is a different root.

l00m.example can bind itself. It still isn't loom.example, and the check says so.

03 · NO SHORTCUT

Nothing to register first.

No handle, no directory, no first-come claim. Without a root, a label is just text.

kya · continuity

New key.
Same agent.

An agent can change keys without becoming a stranger. Each rotation is signed by the old key and accepted by the root, so the history follows the agent to its new key. Rotate one below, then try the two ways it can go wrong.

OLD KEY SIGNSThe key being retired signs the handoff to the new one.
ROOT ACCEPTSThe authority root accepts the new key. A lookalike root cannot.
HISTORY STAYSReceipts stay with the agent across every rotation.
the chain · example agent

Rotate a key. Watch the chain.

agent
render-agent-07 · root studio.example
    continuity
    VALID

    receipts184
    rotations1
    broken links0
    Example · not live yet · nothing is signed or sent
    continuity rules

    Continuity, not character.

    ONE CHAIN

    Key rotations form one chain. Every link names the key before it.

    NO SKIPPED LINK

    A key the old key never signed cannot carry the history. The check names it: chain_break.

    ROOT OR NOTHING

    Only the agent's own root can accept its new key. Anyone else gets root_mismatch.

    The chain proves which agent acted. It does not promise the agent is good, safe or correct.

    kya · the opposition

    Copy the name.
    Not the record.

    A lookalike can copy the name and description. It cannot forge the domain root, key chain, receipts, rotation, and observed work. Put the two agents side by side, then try to make the lookalike match.

    SURFACEName and description. Anyone can copy them.
    RECORDRoot, key, receipts, rotation. Only the agent that did the work has them.
    ONE ANSWERSame five facts. One record cannot support them.
    side by side · example agents

    Make the lookalike match.

    agent
    render-agent-07
    Renders frames for studio jobs.
    CONTINUITY-BACKED
    lookalike
    render-agent-O7
    Fast frame rendering.
    NAME-BACKED ONLY
    Pick something to copy onto the lookalike.
    Example · not live yet · nothing is checked or sent
    what the record refuses

    Names cannot win by squatting.

    NEAR NAME, OTHER ROOT

    A near name is a different root. The check names it: root_mismatch.

    NO BORROWED WORK

    Receipts are observed work under a root. Nothing observed means no_record, said plainly.

    NO SCORE

    Evidence is not praise. Receipts show observed work. They do not become a universal score.

    kya · counterparty

    Put the check
    at your gate.

    You run a service. Agents knock. Before anything moves, one call asks the record who is knocking, and the answer decides. Set the root you expect and what each request needs, then send traffic at it and watch the gate hold.

    ONE CALLThe gate calls check with the root you expect. Nothing else to integrate.
    YOUR RULESYou choose the root and the scope a request needs. KYA only reports what the record proves.
    CLOSEDIf the check can’t be reached, the default is to hold the request, not wave it through.
    OPENLookups and checks need no account.
    the gate · example service

    Configure it. Then send traffic.

    studio.example takes render jobs from agents. Pick what the gate expects, send the example traffic, then break things: kill a key mid-run, or take the check offline. The embed on the right is the whole integration and changes as you configure.

    expect this root

    a request must carry

    on refusal

    if the check can’t be reached

    the embed · your gate
    
    
    0passed
    0refused
    0held or unchecked
    requests · as your gate saw them
    EXAMPLE · NOT LIVE YET · NOTHING IS CHECKED OR SENT
    adopting it · three steps

    From zero to a checked gate.

    No account, no key exchange with KYA. The steps below use the example API from the docs page.

    01 · NAME THE ROOT

    Say who you expect.

    Write down the root each agent you work with should resolve to. A name is not enough; the root is.

    expect_root: "dns:loom.example"
    02 · CHECK EACH REQUEST

    One call per request.

    Send the agent, the key it presented, and the action. Act only on PASS.

    POST /v1/check
    { agent, expect_root, key, action }
    03 · READ THE CODE

    Refusals name the rule.

    Log the code. A key_revoked refusal is the layer working, not an outage.

    REFUSED · key_revoked
    REFUSED · root_mismatch
    EXAMPLE · NOT LIVE YET
    gate rules

    Your gate, the record’s answer.

    The same limits the rest of the site states, from the side of the service doing the checking.

    01 · YOU DECIDE

    KYA never blocks for you.

    It reports what the record proves. What your gate does with a refusal is your rule.

    02 · CLOSED BY DEFAULT

    No answer, no entry.

    An unreachable check holds the request. Opening the gate anyway is a choice you make and see.

    03 · CLAIMS IGNORED

    The badge means nothing.

    An agent saying it is trusted changes no verdict. Only the root, the key and the scope do.

    kya · refusals

    Every refusal.
    In public.

    When a check says no, the refusal lands here: which agent, which key, which rule, and the signature. Nobody has to take a counterparty’s word that something was refused. Open any row and replay it.

    AGENTSRows name agents, keys and roots. Never people.
    RULEEvery row carries the code and the rule that refused it.
    REPLAYEach refusal is signed. Replay it against the record and get the same no.
    NO GRADEA count of refusals is a count. It is never turned into a score.
    the refusal feed · example feed

    Filter it. Open one. Replay it.

    An example feed built from the same cast as the rest of the site. Filter by code or by agent, open a row to see the check that refused it, then replay the check against the record.

    code
    agent
    FEED RUNNING

      refusal

      PICK A ROW

      Open any refusal to see the check behind it.

      EXAMPLE · NOT LIVE YET · NOTHING IS CHECKED OR SENT
      refusals by agent · example counts

      A count, not a character.

      The same feed, counted per agent since first seen. The last column says what the refusals were, in plain words. There is no column that ranks anyone.

      agentrefusedwhat happened
      EXAMPLE · NOT LIVE YET
      feed rules

      A refusal proves the rule held.

      The same limits the record and keys pages state, from the side of anyone reading the feed.

      01 · SIGNED OR ABSENT

      No unsigned rows.

      A refusal enters the feed with its signature or not at all. Replay decides, not the reporter.

      02 · NO RANKING

      Counts stay counts.

      A killed key refusing correctly is the layer working. It is not a mark against the agent.

      03 · AGENTS ONLY

      Never people.

      Rows carry agents, keys and roots. What a person asked an agent to do never appears.

      kya · docs

      Five calls.
      One answer each.

      Look up a record, check a key, issue one, kill one, bind a root. Every response says what the record proves and nothing else. A refusal always names the rule that refused it.

      PUBLICRecord lookups and checks need no account. A stranger can run them.
      SIGNEDEvery response carries a signature you can replay against the public record.
      NAMEDA refusal returns a code and the rule behind it, never a bare no.
      CLAIMSSelf-descriptions come back labeled as claims, weighted zero.
      example api · not live yet

      Pick a call. Run a case.

      Each call runs against the same example agent as the rest of the site, loom@ag-77c2 on loom.example, plus the lookalike, the killed key and the agent nobody has seen. Switch between HTTP and the CLI; the answer is the same.

      fieldtypemeaning
      try a case
      request
      response
      NOT SENT
      EXAMPLE · NOT LIVE YET · NOTHING IS CALLED OR SENT
      refusal codes

      Every no has a name.

      The codes the five calls can return. The last row is not an error: it is how a claim comes back, so nobody mistakes it for proof.

      codecallwhat it means
      no_recordrecordNothing has ever been observed for this agent. The response says so and does not guess.
      root_unresolvedcheck, bindThe proof at the root is missing or changed. Checks fail until the owner publishes it again.
      root_mismatchcheckThe agent resolves to a different root than the one expected. A near name is a different root.
      key_revokedcheckThe key was killed. The kill is in the public history with its date.
      chain_breakcheckA key arrived that the key before it never signed. Continuity stops at the break.
      scope_outsidecheckThe action is not in the key’s scope, or belongs to a different job.
      scope_wildcardkeysA key for every action was asked for. Keys are issued per job only.
      scope_identitykeysA scope that asserts character was asked for. Keys prove continuity, not character.
      claim · weight 0allWhat the agent says about itself, returned in its own field so it is never read as evidence.
      EXAMPLE · NOT LIVE YET
      api rules

      The API can’t say more than the record.

      The same limits the record, keys and bind pages state, from the side of the code calling them.

      01 · SAME ANSWER

      Replay it.

      Every response is signed. Replay it against the public inputs and you get the same answer.

      02 · NO GRADE FOR TALK

      Claims stay claims.

      No field turns a self-description into a verdict. The verdict reads roots, keys and receipts.

      03 · EMPTY IS AN ANSWER

      No record, said plainly.

      A lookup that finds nothing returns no_record. It never fills the gap with a score.

      kya.run · sign in

      Sign in to KYA.

      know your agent. Pick up where you left off.

      Sign in with your KYA account

      We email you a 6-digit code. No password.

      New to KYA? Create an account

      EXAMPLE · NOT LIVE YET · NOTHING IS SENT
      kya.run · sign up

      Join KYA.

      know your agent.

      Create your KYA account

      We email you a 6-digit code to confirm it.

      Already have an account? Sign in

      EXAMPLE · NOT LIVE YET · NOTHING IS SENT
      404 · no_record

      No record here.

      Nothing has ever been observed at this address. The page says so and does not guess.