REST APIAgents

All routes are org-scoped: https://api.regentprotocol.org/v1/organizations/{org_id}/… with your rgnt_… bearer key (authentication).

Register an agent

Requires a verified email and completed KYC on your account (403 EMAIL_NOT_VERIFIED / 403 KYC_NOT_VERIFIED otherwise). The responsible party is always the authenticated user — it cannot be supplied by the client.

curl -X POST https://api.regentprotocol.org/v1/organizations/<org>/agents \
  -H "Authorization: Bearer rgnt_..." -H "content-type: application/json" \
  -d '{"name": "demo-bot", "description": "what this agent does"}'

The response is the identity record. Two identifiers come back — they are not interchangeable:

{
  "id": "6a29b7b2-…",                     // record UUID — internal reference
  "agent_id": "agent_688b10bc62aef…",     // canonical identifier — use THIS everywhere
  "did": "did:regent:solana:agent_688b…",
  "responsible_party_id": "…",
  "status": "active",
  "settlement_chain": "solana",
  "identity_payload": "…",                // KMS-signed at registration
  "identity_signature": "…"
}

Every other endpoint — mandates, revocation, audit — takes the agent_… string. Passing the record UUID returns 422 AGENT_ID_MALFORMED with a message naming the mistake.

Registration queues a Solana anchoring transaction; the agent’s on-chain status flips to anchored within a few seconds on devnet.

List / get

GET /v1/organizations/<org>/agents               # all agents in the org
GET /v1/organizations/<org>/agents/<agent_id>    # one agent (agent_… identifier)

Revoke — the kill switch

POST /v1/organizations/<org>/agents/<agent_id>/revoke

Requires the admin role. One-way: a revoked agent cannot be re-activated (register a new key instead). All the agent’s active mandates are suspended via the agent.revoked event — in our benchmarks the first refused authorize follows within ~0.5 s. A revoked agent’s authorize calls fail with 402 MANDATE_SUSPENDED (or 402 AGENT_NOT_ACTIVE).