OATHERA emblem

AGENTIC IDENTITY PLATFORM

Every AI agent,
sworn in.

OATHERA gives every AI agent a cryptographically provable identity, a named human or organizational owner, and an operational boundary it cannot step outside. Enforced at every request, by policy, down to the kernel.

The only agentic identity platform that gives every agent an identity, an owner and a boundary.

AI agents now read records, move money, open tickets and call internal systems on their own, yet most still sign in with a shared API key. OATHERA is the first platform built to give every agent the three things that make it trustworthy — a provable identity, an accountable owner, and an enforced boundary.

Provable identity

Every agent is uniquely identifiable by its own cryptographic key, so OATHERA can always tell one agent from another.

Accountable owner

Every agent is bound to a named owner who approves it and answers for everything it does.

Enforced boundary

Every agent gets an operational boundary that defines exactly what it may reach, enforced on every request.

How OATHERA delivers it.

OATHERA replaces static secrets with per agent credentials that a person approves once, that expire in minutes, and that work only on the machine they were issued for. Every agent is tied to an accountable owner and an operational boundary. Every request is checked against that boundary before it reaches your systems, and every decision is recorded.

Identity

Provable, not presumed

Each agent holds its own Ed25519 key, created in your environment and never exported. Short lived tokens are bound to that key and that machine, so a copied credential is worthless.

Ownership

A name behind every agent

Every agent is enrolled by and bound to a named human or organizational owner. Approval is recorded in a tamper evident audit certificate.

Boundary

Least privilege by design

An operational boundary defines what an agent may touch at a high level. OPA refines it per request; NVIDIA OpenShell enforces it at the kernel.

Control plane

See every action, prove every decision

One control plane for enrolment, policy, revocation and telemetry, with a full trace of who did what, under which identity, and why it was allowed.

How it works

  1. 1

    Enrol

    A local identity helper generates the agent's private key and attests the machine it runs on. The key never leaves your environment.

  2. 2

    Approve

    A named owner approves the agent once and assigns its operational boundary.

  3. 3

    Act

    The agent receives a short lived, sender constrained token and signs each request with a single use proof over that exact action.

  4. 4

    Enforce and observe

    The gateway verifies identity, OPA evaluates policy, OpenShell confines the runtime, and the control plane records the outcome. Anything that cannot be verified is refused.

The three questions OATHERA answers

Who is this agent?

A cryptographic identity bound to its key and its machine.

Who answers for it?

A named human or organizational owner, recorded at enrolment.

What may it do?

An operational boundary, refined by OPA and enforced by OpenShell.

Frequently asked questions

What is an operational boundary?

It is the high level envelope of what an agent may do: the tenants, systems, data classes and operations in scope, and those that are always out of scope. It is set when the owner approves the agent and is enforced by OPA per request and by NVIDIA OpenShell at runtime.

Why does every agent need a named owner?

Because accountability cannot be delegated to software. A named human or organizational owner approves the agent, appears on every action it takes, and is the person to call when something looks wrong.

How does OATHERA work with NVIDIA OpenShell?

OATHERA turns an agent's boundary into the sandbox policy OpenShell enforces, so the agent's process can only reach approved files, hosts and privileges. Sandbox activity is tagged with the agent's identity and sent to the control plane.

Do I need to replace my existing OPA policies?

No. OATHERA supplies OPA with verified identity, owner and boundary data as policy input. Your existing bundles keep working and gain facts they can trust.

What happens when I revoke an agent?

Its tokens stop being renewed, the gateway refuses its requests, and its sandbox can be stopped. Revocation takes effect within one token lifetime, typically minutes.

Give your agents an identity you can prove.

See enrolment and enforcement traced hop by hop with real signatures, or talk to us about early access.