{"repo":"chanceryhq/chancery","free":true,"listed":false,"github":"https://github.com/chanceryhq/chancery","clone":"git clone https://github.com/chanceryhq/chancery.git","description":"The identity provider for AI agents — registry, scoped delegation, in-path MCP enforcement, instant revocation, tamper-evident audit.","language":"Go","stars":25,"topics":["ai-agents","iam","identity","mcp","security","agents","credentials","tools","multi-agent","spawn"],"license":"Apache-2.0","category":"ai-agents","readme_excerpt":"The identity provider for AI agents. Every agent gets its own identity, authority that can only narrow when delegated, revocation that lands on its next action, and an audit trail it cannot write to. Self-hosted. Single Go binary. Apache-2.0. chanceryai.vercel.app Why Agents usually run on a shared API key, so you can't revoke one without breaking the rest and can't attribute an action to a specific agent. A prompt injection then isn't bad output — it drives every tool that key can reach. And the logs come from the agent itself, the one component you stopped trusting the moment it was compromised. Chancery moves all three outside the agent: identity it doesn't mint, authority it can't widen, and a record it can't write. Install Binaries are cosign-signed (keyless, GitHub OIDC) and ship an SBOM. Try it Full walkthrough: QUICKSTART · try every feature in order: testing playbook . What it does - Identity — agent → immutable content-addressed version → revocable running instance, each separately killable, all owner-attributed. - Writs — authority as a signed chain that can only add restrictions. Widening isn't forbidden, it's unrepresentable : the delegation block format has no field for it. - In-path enforcement — mcp wrap decides every tool call against fresh state, filters tools/list , and answers denials in-protocol. A prompt-injected agent can't talk its way around an out-of-process proxy. - Sealed credentials — injected into the tool server's environment, never the agent's ","default_branch":null,"files":null,"tree":[],"storefront":"/r/chanceryhq","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/chanceryhq/chancery/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}