AI agents are starting to call APIs, read calendars, write code, and move money. WISeID Keystone is the identity, permission, and audit layer that decides which agents are real, what they're allowed to do, and who said so — backed by 25 years of WISeKey PKI.
Frameworks like MCP let agents call tools. They don't answer who is calling, on whose authority, or what actually happened. That gap is where credentials leak, blast radius grows, and trust breaks down.
Servers have no way to verify the agent calling them. A stolen API key or a spoofed client looks identical to a legitimate one.
The load-bearing gapsBroad OAuth scopes hand agents more access than they need. Users can't see which agent can use which account, and policies live in scattered dashboards.
The load-bearing gapsLogs are fragmented, missing context, or entirely absent. When something breaks, no one can reconstruct the chain from human intent to final action.
The load-bearing gapsEvery agent call passes the same four checkpoints — identity, authorization, execution, audit. The keystone locks them into one system. Scroll to build the arch.
Foundations only. Scroll, and the controls that make an agent trustworthy lock into place, one stone at a time.
The agent connects with a Keystone-issued JWT or X.509 certificate. Its waap:// URI is verified in the token's sub claim — no password, no static API key, no shared secret.
A human principal grants the agent a scoped, time-bound delegation per service and operation. Sensitive executions additionally require per-request human approval before anything proceeds — human-in-the-loop at two levels.
The Control Plane injects the downstream credential at the transport layer and runs the call. The agent sees the result — never the key. Out-of-scope attempts are blocked before they leave.
Every operation — granted, executed or denied — is written to an append-only, hash-chained log with full attribution. Cryptographic non-repudiation, exportable as a signed evidence pack for DORA, NIS2, SEC and HIPAA.
The four stones are the controls. The keystone is what turns them into a system — binding verifiable identity, human-authorised delegation, credential-opaque execution, and tamper-evident audit into one load-bearing whole. Remove it and the arch falls; lock it in, and agent trust finally stands.
Every agent call passes through the same pipeline: authenticate → authorize → execute → audit. Credentials never reach the agent. Every action is hash-chained.
Each component stands alone and composes with the others. Deploy Keystone Identity to issue identity. Add the Keystone Control Plane for policy and audit. Plug in the Consumer layer for individuals.
PKI for AI agents
Issue cryptographic identities to every agent and service. Short-lived X.509 client certificates, OAuth2 tokens, and a trusted root chain — the same pattern that secures the airline cargo network.
waap:// identity is also a deterministic spiffe:// peer for SPIRE / Firefly / TeleportAuthorization, audit & mediation
The mediator between agents and everything they try to touch. ABAC policies, delegation, credential injection, and a hash-chained audit log — so credentials never reach the agent, and every action is provable.
keystone-audit-verify CLI runs offlinePersonal trust layer inside My WISeID
Connect Google, Microsoft, GitHub, Slack, Notion, Dropbox. Decide which agents can use which account, set approval rules, and revoke in one tap — all from the WISeID portal and mobile app you already use.
Engineered on standards. No proprietary crypto. No vendor lock-in on the agent side — any MCP or REST client works.
Agents: 365-day X.509 certs. Servers: 90 days. OAuth2 tokens: 30 minutes. Limited blast radius by default.
Agents never see downstream tokens, keys, or certs. The Control Plane injects at the transport layer and zeroes memory.
Every request, approval, and execution is cryptographically linked to the prior entry. Tamper-evident by construction.
Permission grants expire by default. Renewals are explicit. Revocation propagates in seconds across active sessions.
Six first-class tools agents call directly: request, execute, check_approval, audit, and more.
Mark any operation as requiring approval. Principals get a plain-language prompt on the web, email, or My WISeID mobile push.
Plug in your existing IdP — Entra, Okta, Ping — for enterprise; WISeID OIDC for consumer. Agents & users stay separate by design.
Algorithm is a runtime parameter. Dual-stack JWKS ready for ML-DSA (FIPS 204), hybrid TLS with X25519+ML-KEM768 on the roadmap.
Hosted SaaS, self-managed on Kubernetes, or sovereign cloud. Same codebase; same standards; same audit semantics.
Keystone is neither a consumer toy nor an enterprise monolith. It's the same architecture repackaged for every place an AI agent can go.
"Every agent in my org has a verifiable identity and a policy. Every call is audited. Revocation is instant."
"I ship an MCP server or an autonomous agent and let Keystone handle identity, secrets, and permission."
"I know which agent can read my calendar, which can email my clients, and I approve what matters."
Keystone is assembled entirely from open, audited standards. No proprietary cryptography. No closed formats. No hidden trust anchors.
WISeKey has operated commercial certificate authorities, root-of-trust services, and identity infrastructure since 1999 — for governments, enterprises, and critical infrastructure. WISeID Keystone brings that same rigor to AI.
The 2026 agent-identity market is forming around five camps that overlap. Keystone sits at the intersection of three of them — and is the only platform that scores full marks across the entire architectural diagonal. No competitor lights up the whole column.
Keystone is the only player scoring three dots across the diagonal of PKI identity · MCP control plane · credential injection · per-call approval · tamper-evident audit · vendor-neutral · on-prem · dual delegation · PQC roadmap. The deficit rows — pre-built connectors, brand reach, pricing model — are real, and every one of them is addressable with execution and partnerships, not architecture.
Seven phases from working proof-of-concept to a sovereign, on-premise, post-quantum-ready platform.
Software CA · registries · OAuth2 · MCP server · basic ABAC · executors.
✓ DELIVEREDHSM-backed CA · full ABAC · production vault · consent UI.
▶ YOU ARE HEREmTLS-bound tokens · hybrid PQC TLS · multi-org SaaS v1.
Full OIDC + PKCE · Keycloak broker · enterprise UI federation.
My WISeID integration · agent directory · pre-built integrations.
Helm / Terraform packaging · multi-tenant isolation · SOC 2 Type II.
DID/VC interop · blockchain audit anchoring · agent-to-agent delegation.
Short, specific, and honest — including what Keystone doesn't do.
wiseid_* tools; the rest is invisible.POST /revoke). The CRL updates immediately; the Control Plane evicts every active session for that agent; downstream calls fail fast with a structured error — not silently.wiseid.com. Users who already trust WISeID for certificates, signing, and their encrypted vault get the agent permission layer as an integrated feature — no new account, no new app.keystone-audit-verify CLI checks offline.Keystone is in active private beta with WISeKey partners. We're onboarding the next cohort of early-access partners now — enterprises, agent builders, and integrators. Partners get hands-on beta access, a direct line to the engineering team, and a real say in the roadmap.