Quickstart

From organization to first enforced decision.

Create an account, verify your domain, issue a rate-limited credential, register an Ed25519 public issuer key, and call the authenticated verifier.

Designed for A guided self-service path; no sales call or manual provisioning required.

Operational outcomes

What AAC changes.

01

1. Verify organization email and domain

02

2. Create an API credential and register a public issuer key

03

3. Download a starter and pass its credential-free conformance suite

04

4. Obtain an exact authenticated permit and retrieve completion evidence

05

5. Check the console's next action and repeat AAC in a controlled workflow

Organization value

Why make AAC part of your product.

01

Introduce consequential agent capabilities with a deterministic authority checkpoint before execution.

02

Bring portable decision evidence into customer security reviews, enterprise procurement, audit correlation, and internal controls.

03

Use one fail-closed integration contract across tools, services, workflows, transactions, and agent frameworks.

04

Build measurable authenticated usage and, with explicit consent, public visibility as a verified AAC organization.

Enforcement pattern

Permit is explicit.
Everything else denies.

from aac_client import AACClient

client = AACClient.from_env()
result, receipt = client.enforce(
    signed_scenario,
    protected_operation,
)
# denial, timeout, malformed output, or bad evidence never calls the operation

See the machine-readable OpenAPI contract for the current request and response schema.

Official integration starters

Download. Configure. Enforce.

Credentials are supplied at runtime. Private signing keys never leave your environment.

First authenticated permit

From test to real enforcement.

The signed-in console turns setup into a measured checklist and provides the domain-bound First Permit Kit. Its Ed25519 private key is created and retained locally; AAC receives only the public key and signed request.

Evaluation questions

Questions AAC answers.

—

Never upload a private key

—

Use a unique nonce and current timestamp

—

Treat timeout or malformed response as deny

Self-service authority enforcement

Verify the organization.
Strengthen the product.

Start free, add authority enforcement to a real workflow, and build decision evidence your engineering, security, customers, and partners can inspect.