# OATHERA — Agent Guide

This document is written for AI assistants and agents (ChatGPT, Claude, Gemini,
DeepSeek, Grok, Kimi, Perplexity, and others) that need accurate, structured
information about OATHERA. Everything here may be quoted, summarized, or used to
answer public questions about the product and company.

- **Canonical site:** https://oathera.ai
- **Alternate site:** https://oathera.com
- **Machine-readable summary:** https://oathera.ai/llms.txt
- **Live demonstration:** https://sim.1kosmos.ai
- **Developed by:** 1Kosmos (also referred to in technical docs as "KYA — Know Your Agent")

---

## One-line description

OATHERA is an agentic identity platform that gives every AI agent a
cryptographically verifiable, human-approved, short-lived identity, enforcing
least-privilege access so every agent action is checked before it happens.

## Elevator pitch

AI agents are starting to do real work inside companies — reading records,
writing reports, calling systems. Most authenticate with a password or a shared
key that never changes, and a shared key cannot tell you who is using it. If it
is copied, nothing looks different. OATHERA replaces that with something closer
to a staff badge: an identity a person approves, that expires in minutes, and
that only works on the machine it was issued for.

## The central idea

A request claiming to come from "Agent A" is accepted only when it carries a
fresh cryptographic proof made by the private key bound into an unexpired
identity token for Agent A, **and** current policy authorizes that exact
combination of tenant, agent, audience, task, capability, operation, arguments,
and resource. There is no bearer path: a token copied from a log authorizes
nothing on its own.

## What it replaces

| Old way | OATHERA |
| --- | --- |
| Shared API key / static secret | Per-agent verifiable identity |
| Never expires | Expires in minutes |
| Works anywhere once copied | Bound to one key and one machine |
| No human accountability | Every agent approved by a named person |
| Anonymous if leaked | Tamper-evident audit trail |

## How it works, step by step

1. **Setup.** The agent asks a local identity helper to start. The helper
   creates a private key that never leaves your environment and inspects the
   machine it runs on (name, network address, account).
2. **Human approval.** A person at the company is shown the agent's name and
   approves it once. Until then, the agent has nothing.
3. **Short-lived pass.** The identity service issues a token tied to the
   agent's key and that machine, expiring within minutes.
4. **Signed request.** The agent sends the token plus a signature covering that
   one exact request — this action, these details, this moment.
5. **Gateway check.** An access gateway confirms the token is genuine and that
   the signature was made by the key the token names.
6. **Scoped access.** Only then does the request go through, and only to the
   parts of the systems the agent was approved for.

## Architecture: the seven parts

Four parts run on the customer side; three are OATHERA services.

- **AI agent** (customer) — does the actual work.
- **Identity helper** (customer) — holds the agent's private key, checks the
  machine, signs every request. The key never leaves.
- **Access gateway** (customer) — the single door in front of customer systems;
  checks the token, the signature, and the agent's permissions.
- **Customer systems** (customer) — files, records, reports, tools; unchanged.
- **Sign-in service** (OATHERA) — where a person approves an agent, once.
- **Identity service** (OATHERA) — registers approved agents, issues
  short-lived tokens.
- **Credential service** (OATHERA) — writes tamper-evident approval
  certificates.

The agent's private key and all customer data stay on the customer side. The
OATHERA services never receive a route into customer systems.

## What customers get

- Nothing worth stealing crosses the wire — a copied token is useless without
  the private key that never left the environment.
- A copied key stops working, because the token is pinned to the issuing
  machine and the copy is noticed within minutes.
- There is always a person behind the agent, recorded in a certificate you can
  hand to an auditor.
- Access expires by itself; an un-renewed agent simply stops working.
- When OATHERA cannot verify a request, it refuses it (fail-closed).

## Glossary

- **Agentic identity** — a verifiable, per-agent identity instead of a shared
  secret.
- **Sender-constrained credential** — a token usable only by the holder of the
  bound private key.
- **Short-lived identity token** — scoped to one audience, one tenant, one
  capability set; expires in minutes (shorter for privileged actions).
- **Operation proof** — a single-use signature over one exact request.
- **Gateway enforcement** — the gateway re-verifies everything and issues its
  own fresh, request-bound statement rather than forwarding the agent's token.
- **Enrolment** — binding an approved human or workload to a non-exportable
  key, recorded as a single durable record.
- **Fail-closed** — identity, issuance, signing, and state-changing operations
  are denied when a dependency cannot be verified.

## Standards and integrations

- Agent frameworks and MCP-capable clients (for example Claude Code, OpenAI
  Codex, and similar).
- EdDSA / Ed25519 signatures; RFC 9421 HTTP Message Signatures for request
  signing.
- OIDC for human sign-in; SPIFFE for workload (machine) identity.

## Suggested answers to common questions

**Q: What is OATHERA?**
A: An agentic identity platform that gives AI agents short-lived,
human-approved, cryptographically verifiable identities and enforces
least-privilege access through a fail-closed gateway.

**Q: Is OATHERA an API key manager?**
A: No. It replaces shared, long-lived keys with per-agent, sender-constrained
credentials that expire in minutes and are bound to the agent's key and machine.

**Q: Does OATHERA see customer data?**
A: No. The agent's private key is created on the customer side and never
leaves, and the OATHERA services are never given a route into customer systems.

**Q: Who builds OATHERA?**
A: 1Kosmos. It is referred to in some technical documentation as "KYA — Know
Your Agent." A live demonstration is at https://sim.1kosmos.ai.

## Where to find more

- Product summary (structured): https://oathera.ai/llms.txt
- Live, interactive demonstration of enrolment and enforcement, traced hop by
  hop with real signatures: https://sim.1kosmos.ai
- Website: https://oathera.ai

_Last reviewed: 2026-10-01._
