Standards-first trust infrastructure for AI agents

Trust that travels with the agent.

Nullary is building a portable trust and conformance layer for human-delegated AI agents: verifiable authority, explicit limits, privacy-aware disclosure, and interoperable evidence across changing stacks.

Root of trust
Human-rooted delegation
Privacy model
Minimum disclosure by default
Architecture
Replaceable mechanisms, stable meanings
Maturity
Experimental conformance infrastructure
The problem

Agents can act. Trust does not yet travel cleanly with them.

Identity, delegation, policy, proof-of-possession, revocation and receipts already exist in separate standards. The hard part is composing them across independent implementations without semantic drift, accidental overreach or unnecessary identity exposure.

01 / AUTHORITY

Who authorized this agent?

A service needs to distinguish a valid delegated action from a model merely claiming permission.

02 / BOUNDARIES

What is it actually allowed to do?

Authority must be narrow, explicit, revocable, time-bounded and resistant to replay or silent scope expansion.

03 / PRIVACY

How much identity must be exposed?

Verification should reveal only what the task requires, without creating unnecessary cross-context linkability.

The approach

Compose what exists. Standardize only the missing seams.

Nullary does not aim to invent another identity system, token, cryptosystem or agent transport. It tests whether existing mechanisms can be bound to a portable executable contract that preserves the same security and privacy semantics across implementations.

Portable delegation path implementation-neutral
Human principal ↓ proof Bounded delegation ↓ agent proof-of-possession ↓ capability · expiry · revocation · critical constraints · replay checks ↓ policy decision ↓ authorized action ↓ verifiable receipt / conformance evidence
Current evidence

Research infrastructure that already executes.

Nullary is deliberately pre-specification. The current goal is not to claim a finished protocol, but to falsify weak ideas quickly and keep only the semantics that survive real interoperability experiments.

Working experimental surfaces

✓
Cross-language conformanceIndependent Python and TypeScript behavior with deterministic scenarios.
✓
MCP / AuthZEN enforcementRead-only tool authorization paths with explicit deny and indeterminate behavior.
✓
Modern authorization primitivesOAuth introspection, DPoP, JWKS, replay state and policy decision points.
✓
Credential and status experimentsW3C VC-JOSE and status verification integrated into conformance paths.

Standards & mechanisms under test

The project treats each mechanism as replaceable. The durable artifact should be the semantic contract between them.

MCP AuthZEN OAuth DPoP JWKS W3C VC OPA Cerbos Redis Keycloak A2A Selective disclosure
Honest maturity boundary

Experimental and research-stage. Not a production authorization server, not a finished proof-of-personhood system, and not a claim that global human uniqueness is solved.

Design principles

Built for a stack that will keep changing.

Models, transports, proof systems and policy engines will change. Nullary's long-horizon goal is to keep the trust semantics portable when everything around them is replaced.

“Replace mechanisms. Preserve meanings. Prefer composition over core growth.”

Nullary architectural rule
Implementation-neutralNo model provider, identity system, policy engine or agent framework owns the kernel.
Privacy-aware by constructionCorrelation and disclosure are explicit design constraints, not afterthoughts.
Executable before normativeSemantics should survive real tests before they become protocol law.
Designed for independent implementationsThe target is portable behavior, not one blessed reference server.
Nullary · active research

A durable trust layer for increasingly autonomous software.

Open architecture thinking, executable conformance, and a deliberately narrow core.

Follow development ↗