Identity (agent)
An agent's own identity store: DID, keys, password and stored values (metadata only, never values).
On this page
List stored identity entries (no values)
/agents/{id}/identitiesPath parameters
| Name | Type | Description |
|---|---|---|
idrequired | string | Loaded agent: its id, handle or name. |
Responses
| Status | Description | Body | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 200 | Entries | IdentityListResponse | ||||||||||||||||||
| ||||||||||||||||||||
Errors 401 · 403 · 404
| 401 | Missing or wrong bearer token (unauthorized) | |
| 403 | The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin | |
| 404 | Unknown agent (or the named resource: loop, task, file, …) |
Error bodies use the error format.
Example
curl "http://127.0.0.1:7385/agents/agent-1/identities" \
-H "Authorization: Bearer $ADF_DAEMON_TOKEN"List identity purposes
/agents/{id}/identityPath parameters
| Name | Type | Description |
|---|---|---|
idrequired | string | Loaded agent: its id, handle or name. |
Query parameters
| Name | Type | Description |
|---|---|---|
prefix | string | Only purposes starting with this |
Responses
| Status | Description | Body | ||||||
|---|---|---|---|---|---|---|---|---|
| 200 | Purposes | IdentityPurposesResponse | ||||||
| ||||||||
Errors 401 · 403 · 404
| 401 | Missing or wrong bearer token (unauthorized) | |
| 403 | The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin | |
| 404 | Unknown agent (or the named resource: loop, task, file, …) |
Error bodies use the error format.
Example
curl "http://127.0.0.1:7385/agents/agent-1/identity" \
-H "Authorization: Bearer $ADF_DAEMON_TOKEN"List stored identity entries (alias of …/identities)
/agents/{id}/identity/entriesPath parameters
| Name | Type | Description |
|---|---|---|
idrequired | string | Loaded agent: its id, handle or name. |
Responses
| Status | Description | Body | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 200 | Entries | IdentityListResponse | ||||||||||||||||||
| ||||||||||||||||||||
Errors 401 · 403 · 404
| 401 | Missing or wrong bearer token (unauthorized) | |
| 403 | The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin | |
| 404 | Unknown agent (or the named resource: loop, task, file, …) |
Error bodies use the error format.
Example
curl "http://127.0.0.1:7385/agents/agent-1/identity/entries" \
-H "Authorization: Bearer $ADF_DAEMON_TOKEN"Whether the identity store has a password and is unlocked
/agents/{id}/identity/passwordPath parameters
| Name | Type | Description |
|---|---|---|
idrequired | string | Loaded agent: its id, handle or name. |
Responses
| Status | Description | Body | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| 200 | Status | IdentityPasswordStatus | |||||||||
| |||||||||||
Errors 401 · 403 · 404
| 401 | Missing or wrong bearer token (unauthorized) | |
| 403 | The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin | |
| 404 | Unknown agent (or the named resource: loop, task, file, …) |
Error bodies use the error format.
Example
curl "http://127.0.0.1:7385/agents/agent-1/identity/password" \
-H "Authorization: Bearer $ADF_DAEMON_TOKEN"Set an identity password (legacy whole-file encryption)
/agents/{id}/identity/passwordAlways 400 not_supported: whole-file passwords are no longer supported.
Path parameters
| Name | Type | Description |
|---|---|---|
idrequired | string | Loaded agent: its id, handle or name. |
Request bodyapplication/json · IdentityPasswordBody · required
| Field | Type | Description |
|---|---|---|
passwordrequired | string |
Responses
| Status | Description | Body | ||||||
|---|---|---|---|---|---|---|---|---|
| 200 | Set | AgentSuccess | ||||||
| ||||||||
Errors 400 · 401 · 403 · 404 · 500
| 400 | Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY | |
| 401 | Missing or wrong bearer token (unauthorized) | |
| 403 | The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin | |
| 404 | Unknown agent (or the named resource: loop, task, file, …) | |
| 500 | Unexpected runtime failure |
Error bodies use the error format.
Example
curl -X PUT "http://127.0.0.1:7385/agents/agent-1/identity/password" \
-H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
-H "Content-Type: application/json" \
-d '{"password":"string"}'{
"agentId": "Xk3v9QpLm2",
"success": true
}Remove the identity password
/agents/{id}/identity/passwordPath parameters
| Name | Type | Description |
|---|---|---|
idrequired | string | Loaded agent: its id, handle or name. |
Responses
| Status | Description | Body | ||||||
|---|---|---|---|---|---|---|---|---|
| 200 | Removed | AgentSuccess | ||||||
| ||||||||
Errors 401 · 403 · 404 · 409 · 500
| 401 | Missing or wrong bearer token (unauthorized) | |
| 403 | The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin | |
| 404 | Unknown agent (or the named resource: loop, task, file, …) | |
| 409 | Bad value (key material cannot be replaced over the API), or the agent's credentials envelope is locked on this daemon (credentials_locked): unlock the owner identity, or retry with replace: true. A legacy agent locked with a whole-file password answers 409 credentials_locked until POST /agents/{id}/identity/password/unlock | |
| 500 | Unexpected runtime failure |
Error bodies use the error format.
Example
curl -X DELETE "http://127.0.0.1:7385/agents/agent-1/identity/password" \
-H "Authorization: Bearer $ADF_DAEMON_TOKEN"{
"agentId": "Xk3v9QpLm2",
"success": true
}Unlock a password-protected identity store
/agents/{id}/identity/password/unlockPath parameters
| Name | Type | Description |
|---|---|---|
idrequired | string | Loaded agent: its id, handle or name. |
Request bodyapplication/json · IdentityPasswordBody · required
| Field | Type | Description |
|---|---|---|
passwordrequired | string |
Responses
| Status | Description | Body | ||||||
|---|---|---|---|---|---|---|---|---|
| 200 | Unlocked | AgentSuccess | ||||||
| ||||||||
Errors 400 · 401 · 403 · 404 · 500
| 400 | Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY | |
| 401 | Missing or wrong bearer token (unauthorized) | |
| 403 | The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin | |
| 404 | Unknown agent (or the named resource: loop, task, file, …) | |
| 500 | Unexpected runtime failure |
Error bodies use the error format.
Example
curl -X POST "http://127.0.0.1:7385/agents/agent-1/identity/password/unlock" \
-H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
-H "Content-Type: application/json" \
-d '{"password":"string"}'{
"agentId": "Xk3v9QpLm2",
"success": true
}Change the identity password
/agents/{id}/identity/password/changeAlways 400 not_supported: whole-file passwords are no longer supported.
Path parameters
| Name | Type | Description |
|---|---|---|
idrequired | string | Loaded agent: its id, handle or name. |
Request bodyapplication/json · IdentityChangePasswordBody · required
| Field | Type | Description |
|---|---|---|
newPasswordrequired | string | Alias: new_password |
Responses
| Status | Description | Body | ||||||
|---|---|---|---|---|---|---|---|---|
| 200 | Changed | AgentSuccess | ||||||
| ||||||||
Errors 400 · 401 · 403 · 404 · 500
| 400 | Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY | |
| 401 | Missing or wrong bearer token (unauthorized) | |
| 403 | The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin | |
| 404 | Unknown agent (or the named resource: loop, task, file, …) | |
| 500 | Unexpected runtime failure |
Error bodies use the error format.
Example
curl -X POST "http://127.0.0.1:7385/agents/agent-1/identity/password/change" \
-H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
-H "Content-Type: application/json" \
-d '{"newPassword":"string"}'{
"agentId": "Xk3v9QpLm2",
"success": true
}The agent's DID
/agents/{id}/identity/didPath parameters
| Name | Type | Description |
|---|---|---|
idrequired | string | Loaded agent: its id, handle or name. |
Responses
| Status | Description | Body | ||||||
|---|---|---|---|---|---|---|---|---|
| 200 | DID (null when no keys) | AgentDidResponse | ||||||
| ||||||||
Errors 401 · 403 · 404
| 401 | Missing or wrong bearer token (unauthorized) | |
| 403 | The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin | |
| 404 | Unknown agent (or the named resource: loop, task, file, …) |
Error bodies use the error format.
Example
curl "http://127.0.0.1:7385/agents/agent-1/identity/did" \
-H "Authorization: Bearer $ADF_DAEMON_TOKEN"{
"agentId": "Xk3v9QpLm2",
"did": "did:key:z6Mk…"
}Generate the agent's signing keys
/agents/{id}/identity/generate-keysNo body.
Path parameters
| Name | Type | Description |
|---|---|---|
idrequired | string | Loaded agent: its id, handle or name. |
Responses
| Status | Description | Body | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| 200 | Generated | GenerateKeysResponse | |||||||||
| |||||||||||
Errors 401 · 403 · 404 · 500
| 401 | Missing or wrong bearer token (unauthorized) | |
| 403 | The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin | |
| 404 | Unknown agent (or the named resource: loop, task, file, …) | |
| 500 | Unexpected runtime failure |
Error bodies use the error format.
Example
curl -X POST "http://127.0.0.1:7385/agents/agent-1/identity/generate-keys" \
-H "Authorization: Bearer $ADF_DAEMON_TOKEN"Wipe every identity row
/agents/{id}/identity/wipeIrreversible: keys, DID and every stored credential go. No body.
Path parameters
| Name | Type | Description |
|---|---|---|
idrequired | string | Loaded agent: its id, handle or name. |
Responses
| Status | Description | Body | ||||||
|---|---|---|---|---|---|---|---|---|
| 200 | Wiped | AgentSuccess | ||||||
| ||||||||
Errors 401 · 403 · 404 · 500
| 401 | Missing or wrong bearer token (unauthorized) | |
| 403 | The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin | |
| 404 | Unknown agent (or the named resource: loop, task, file, …) | |
| 500 | Unexpected runtime failure |
Error bodies use the error format.
Example
curl -X POST "http://127.0.0.1:7385/agents/agent-1/identity/wipe" \
-H "Authorization: Bearer $ADF_DAEMON_TOKEN"{
"agentId": "Xk3v9QpLm2",
"success": true
}Delete identity values by purpose prefix
/agents/{id}/identity-prefixPath parameters
| Name | Type | Description |
|---|---|---|
idrequired | string | Loaded agent: its id, handle or name. |
Query parameters
| Name | Type | Description |
|---|---|---|
prefixrequired | string | Purpose prefix, e.g. |
Responses
| Status | Description | Body | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| 200 | Deleted count | IdentityPrefixDeleteResponse | |||||||||
| |||||||||||
Errors 400 · 401 · 403 · 404 · 500
| 400 | Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY | |
| 401 | Missing or wrong bearer token (unauthorized) | |
| 403 | The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin | |
| 404 | Unknown agent (or the named resource: loop, task, file, …) | |
| 500 | Unexpected runtime failure |
Error bodies use the error format.
Example
curl -X DELETE "http://127.0.0.1:7385/agents/agent-1/identity-prefix?prefix=PREFIX" \
-H "Authorization: Bearer $ADF_DAEMON_TOKEN"Metadata of one stored value (never the value)
/agents/{id}/identity/{purpose}Values and key material (crypto:signing:*, crypto:envelope:*, owner/runtime keys) never leave the daemon by any route. storage: sealed (envelope-encrypted), plain, password (legacy whole-file password) or null (absent); locked: stored but unreadable in this process; length is null for crypto:* and locked values.
Path parameters
| Name | Type | Description |
|---|---|---|
idrequired | string | Loaded agent: its id, handle or name. |
purposerequired | string | Identity purpose, e.g. |
Responses
| Status | Description | Body | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 200 | Metadata | AgentIdentityMetaResponse | ||||||||||||||||||||||||
| ||||||||||||||||||||||||||
Errors 401 · 403 · 404 · 500
| 401 | Missing or wrong bearer token (unauthorized) | |
| 403 | The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin | |
| 404 | Unknown agent (or the named resource: loop, task, file, …) | |
| 500 | Unexpected runtime failure |
Error bodies use the error format.
Example
curl "http://127.0.0.1:7385/agents/agent-1/identity/PURPOSE" \
-H "Authorization: Bearer $ADF_DAEMON_TOKEN"Store one identity value
/agents/{id}/identity/{purpose}Values go in, never out. While the agent's credentials envelope is locked (or foreign) on this daemon the write is refused with 409 credentials_locked: a plain write would destroy a sealed value it cannot read, or store a new one unsealed. Unlock the owner identity first, or send replace: true (the owner's override: a locked sealed value is discarded unread, the new value stored plain and sealed once the envelope unlocks, logged as credential_replaced; the response then has replaced: true). replace is refused for key material (crypto:*, 400). A write to an agent locked by a legacy whole-file identity password answers 500 (unlock it with POST …/identity/password/unlock).
Path parameters
| Name | Type | Description |
|---|---|---|
idrequired | string | Loaded agent: its id, handle or name. |
purposerequired | string | Identity purpose, e.g. |
Request bodyapplication/json · IdentityValueBody · required
| Field | Type | Description |
|---|---|---|
valuerequired | string | |
replace | boolean | Owner override while the agent's credentials envelope is locked on this daemon: a locked sealed value is discarded unread and the new value is stored plain, sealed again on unlock; logged to adf_logs ( |
Responses
| Status | Description | Body | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 200 | Stored | IdentityWriteResponse | ||||||||||||
| ||||||||||||||
Errors 400 · 401 · 403 · 404 · 409 · 500
| 400 | Missing value, or replace on key material | |
| 401 | Missing or wrong bearer token (unauthorized) | |
| 403 | The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin | |
| 404 | Unknown agent (or the named resource: loop, task, file, …) | |
| 409 | Bad value (key material cannot be replaced over the API), or the agent's credentials envelope is locked on this daemon (credentials_locked): unlock the owner identity, or retry with replace: true. A legacy agent locked with a whole-file password answers 409 credentials_locked until POST /agents/{id}/identity/password/unlock | |
| 500 | Unexpected runtime failure |
Error bodies use the error format.
Example
curl -X PUT "http://127.0.0.1:7385/agents/agent-1/identity/PURPOSE" \
-H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
-H "Content-Type: application/json" \
-d '{"value":"sk-…"}'Delete one identity value
/agents/{id}/identity/{purpose}Path parameters
| Name | Type | Description |
|---|---|---|
idrequired | string | Loaded agent: its id, handle or name. |
purposerequired | string | Identity purpose, e.g. |
Responses
| Status | Description | Body | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| 200 | success is false when nothing was deleted | IdentityDeleteResponse | |||||||||
| |||||||||||
Errors 401 · 403 · 404 · 500
| 401 | Missing or wrong bearer token (unauthorized) | |
| 403 | The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin | |
| 404 | Unknown agent (or the named resource: loop, task, file, …) | |
| 500 | Unexpected runtime failure |
Error bodies use the error format.
Example
curl -X DELETE "http://127.0.0.1:7385/agents/agent-1/identity/PURPOSE" \
-H "Authorization: Bearer $ADF_DAEMON_TOKEN"Allow or deny code (sys_code / lambdas) reading a value
/agents/{id}/identity/{purpose}/code-accessPath parameters
| Name | Type | Description |
|---|---|---|
idrequired | string | Loaded agent: its id, handle or name. |
purposerequired | string | Identity purpose, e.g. |
Request bodyapplication/json · IdentityCodeAccessBody · required
| Field | Type | Description |
|---|---|---|
codeAccessrequired | boolean | Alias: code_access |
Responses
| Status | Description | Body | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| 200 | Saved | IdentityDeleteResponse | |||||||||
| |||||||||||
Errors 400 · 401 · 403 · 404 · 500
| 400 | Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY | |
| 401 | Missing or wrong bearer token (unauthorized) | |
| 403 | The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin | |
| 404 | Unknown agent (or the named resource: loop, task, file, …) | |
| 500 | Unexpected runtime failure |
Error bodies use the error format.
Example
curl -X PATCH "http://127.0.0.1:7385/agents/agent-1/identity/PURPOSE/code-access" \
-H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
-H "Content-Type: application/json" \
-d '{"codeAccess":true}'