All routes are org-scoped: https://api.regentprotocol.org/v1/organizations/{org_id}/…
with your rgnt_… bearer key (authentication).
Register an agent
Requires a verified email and completed KYC on your account (403 EMAIL_NOT_VERIFIED /
403 KYC_NOT_VERIFIED otherwise). The responsible party is always the authenticated
user — it cannot be supplied by the client.
curl -X POST https://api.regentprotocol.org/v1/organizations/<org>/agents \
-H "Authorization: Bearer rgnt_..." -H "content-type: application/json" \
-d '{"name": "demo-bot", "description": "what this agent does"}'The response is the identity record. Two identifiers come back — they are not interchangeable:
{
"id": "6a29b7b2-…", // record UUID — internal reference
"agent_id": "agent_688b10bc62aef…", // canonical identifier — use THIS everywhere
"did": "did:regent:solana:agent_688b…",
"responsible_party_id": "…",
"status": "active",
"settlement_chain": "solana",
"identity_payload": "…", // KMS-signed at registration
"identity_signature": "…"
}Every other endpoint — mandates, revocation, audit — takes the agent_… string.
Passing the record UUID returns 422 AGENT_ID_MALFORMED with a message naming the
mistake.
Registration queues a Solana anchoring transaction; the agent’s on-chain status flips
to anchored within a few seconds on devnet.
List / get
GET /v1/organizations/<org>/agents # all agents in the org
GET /v1/organizations/<org>/agents/<agent_id> # one agent (agent_… identifier)Revoke — the kill switch
POST /v1/organizations/<org>/agents/<agent_id>/revokeRequires the admin role. One-way: a revoked agent cannot be re-activated (register a
new key instead). All the agent’s active mandates are suspended via the agent.revoked
event — in our benchmarks the first refused authorize follows within ~0.5 s. A revoked
agent’s authorize calls fail with 402 MANDATE_SUSPENDED (or 402 AGENT_NOT_ACTIVE).