Skip to main content
Baselayer’s Know Your Agent (KYA) enables agent builders and platforms to verify real-world people and business identities, and securely delegate those identities to agents. Carrying a verified identity enables agents to access more of the web, and grants more control to agent builders to manage and revoke access to user credentials. Merchants, platforms, and payment processors can verify trusted agents and recognize returning customers, before granting access to a service or accepting payment.

Why KYA matters

  1. Access more. Access more of the web with recognized identity and trust signals that expand account access, increase transaction success rates, and bypass bot detection.
  2. Recognize returning customers. Merchants and platforms can recognize returning customers, applying the appropriate loyalty status, purchasing history, and existing payment credentials.
  3. Enable secure access controls. Securely delegate identity rather than sharing reusable credentials and passwords that can be stolen or abused, and revoke access on demand.

How Baselayer’s KYA works

Baselayer’s KYA API lets an organization verify a person or business once, then mint short-lived, cryptographically signed credentials on demand for their agents to present to counterparties. A counterparty reads exactly the fields it needs and can verify the credential’s integrity and the issuer’s signature without ever calling Baselayer directly.
  1. Verify once. Verify a consumer or business once to create an identity. Either use Baselayer’s API; submit an identity you already collected; or embed Baselayer’s hosted, white-labelable onboarding flow so users enter their details themselves and you never touch the raw PII. Either way, you get back a durable principal_ref / business_ref. See Verifying an Identity.
  2. Mint credentials on demand. For every counterparty an agent visits, mint a fresh, short-lived credential scoped to that audience and bound to that agent’s key. See Minting Credentials.
  3. Present & verify. The agent presents the credential; the counterparty verifies the signature, checks revocation status, and enforces its disclosure scope before reading a single claim. See Presenting & Verifying a Credential.
  4. After the fact. Check a counterparty’s own standing in the Agentic Commerce Directory, or read back what happened in the Audit Log.
Step 1 happens once per consumer or business identity; step 2 repeats every time that consumer or business’s agent needs to act somewhere new; step 3 happens on every request. For the exact request and response shapes behind each step, see the API Reference; for how the credential is actually signed and verified on the wire, see the Credential Format Reference.

API details

Organizations and applications

Every identity, credential, and audit log read is scoped to your organization, inferred entirely from your X-API-Key — never from anything in the request body. A principal_ref or business_ref that belongs to another organization, or one that was never issued, resolves as an indistinguishable 404; there is no cross-org existence oracle.

Support

Questions or issues? Email support@baselayer.com or check status.baselayer.com.