@observer-protocol

Observer Protocol

Verifiable authorisation for AI agent decisions and payments. Enforcement before the signature. Delegation credentials verify offline, by anyone.

Observer Protocol

An agent holds a signed mandate that says what it may spend, on which rail, with whom. Enforcement happens at the signer boundary, before a key signs, and the verdict is verifiable by anyone.

Not a trust score, not an allowlist, not a service you have to call. A delegation credential is a W3C Verifiable Credential; the check on one is offline; the issuer DID and the schemas are public and frozen.

Start here

Run a verifier yourself. Three lines, no account, no API key:

git clone https://github.com/observer-protocol/op-verify-service
cd op-verify-service && docker compose up --build
./compose-smoke.sh

The smoke test checks a credential that must verify and one that must be refused, and fails if either answer is wrong. A test that only proves the happy path cannot tell a working verifier from one that says yes to everything.

Or verify a published credential against the hosted endpoint without cloning anything:

curl -s https://observerprotocol.org/credentials/maxi-0001-trading-mandate-2026-08.json \
| jq '{agentDid: .credentialSubject.id, mandate: .}' \
| curl -s -X POST https://verify.observerprotocol.org/v1/verify \
-H 'Content-Type: application/json' --data @-

That endpoint is open by ruling. It takes an artifact as input and retrieves nothing, so a caller can only check a credential it already holds.

The repositories

repowhat it is
aipThe protocol. Specification, delegation schemas, key-scoping policy. What you implement against.
op-policy-engineThe engine, and the package you install. Offline credential verification, mandate enforcement, decision attestations.
op-verify-serviceThe hosted verifier, and the runnable one. Dockerfile, compose file, and a smoke test that can fail.
op-adaptersPer-rail integrations: Lightning/L402, x402, MPP/Tempo, Tether WDK, OWS/Solana, AP2, Fireblocks. One repository, seven packages, each carrying an explicit support tier.

The adapters are not equally supported and the difference is stated, not implied. One is proven against a live system and not yet deployable; the rest are reference implementations, two of which have no published package at all. Each README says which it is and what backs that claim, because an unlabelled reference integration that someone picks up expecting production support is worse than no listing.

What is deliberately not claimed

The hosted endpoint is a convenience, never a dependency. What it checks on a delegation credential can be re-checked offline from the npm package: the issuer DID document is public, the schema URLs are frozen and content-addressed, and revocation status lists are static public files.

That set is delegation credentials, refusal records and lapse records. It does not include determinations, resolutions, instructions or releases. A PolicyEvaluationCredential is a determination and is a different artifact from a refusal record; both published PECs still fail with PEC-NO-VERIFIER-PATH, enforced in the website repository's CI.

Refusal records became verifiable at engine rc.9, which exports the payload builder. A scratch directory containing only @observer-protocol/policy-engine@1.0.0-rc.9, with no checkout of any repository, rebuilt the signed payloads for all 14 refusals in the 2026-08-08 corpus: 14 of 14 verify, 14 of 14 reject a one-field tamper. The absence of a checkout is the point, because it makes the result a counterparty's, not ours.

"Verifiable offline by anyone" was on this org's description until 9 August 2026 with no limit at all. The list above is the limit, and it is now wider than the one written here on that date.

Archived repositories under this organisation are kept public and readable on purpose. A published package's repository link must keep resolving, and a tarball you already installed must keep verifying, whether or not the work continued.

Because they stay public, their metadata stays true. An archived repository's description and topics are a permanent public claim, not a leftover, and a permanent false claim is worse than a current one: nobody is coming back to it. When a description or topic is found wrong, the repository is unarchived, the metadata corrected, and the repository re-archived. The code is frozen at the point of archiving. The claims made about it are not. See ORG-METADATA-POLICY.md.

Pinned Loading

  1. op-adaptersop-adaptersPublic

    Observer Protocol rail adapters: Lightning/L402, x402, MPP/Tempo, Tether WDK, OWS/Solana, AP2, Fireblocks. Each carries an explicit support tier.

    TypeScript

  2. op-policy-engineop-policy-enginePublic

    Observer Protocol Policy Engine: delegation-scoped enforcement for agentic wallets. AIP v0.8 spec, schema, integration guides, TypeScript interfaces.

    TypeScript

  3. op-verify-serviceop-verify-servicePublic

    Hosted one-call verification of Observer-issued agents: identity, mandate, scope — one signed fail-closed response, composed from the public policy engine.

    JavaScript

  4. aipaipPublic

    Agentic Identity Protocol (AIP) specification

    JavaScript 1

Repositories

Showing 10 of 25 repositories

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
@observer-protocol

Observer Protocol

Verifiable authorisation for AI agent decisions and payments. Enforcement before the signature. Delegation credentials verify offline, by anyone.

Observer Protocol

An agent holds a signed mandate that says what it may spend, on which rail, with whom. Enforcement happens at the signer boundary, before a key signs, and the verdict is verifiable by anyone.

Not a trust score, not an allowlist, not a service you have to call. A delegation credential is a W3C Verifiable Credential; the check on one is offline; the issuer DID and the schemas are public and frozen.

Start here

Run a verifier yourself. Three lines, no account, no API key:

git clone https://github.com/observer-protocol/op-verify-service
cd op-verify-service && docker compose up --build
./compose-smoke.sh

The smoke test checks a credential that must verify and one that must be refused, and fails if either answer is wrong. A test that only proves the happy path cannot tell a working verifier from one that says yes to everything.

Or verify a published credential against the hosted endpoint without cloning anything:

curl -s https://observerprotocol.org/credentials/maxi-0001-trading-mandate-2026-08.json \
| jq '{agentDid: .credentialSubject.id, mandate: .}' \
| curl -s -X POST https://verify.observerprotocol.org/v1/verify \
-H 'Content-Type: application/json' --data @-

That endpoint is open by ruling. It takes an artifact as input and retrieves nothing, so a caller can only check a credential it already holds.

The repositories

repowhat it is
aipThe protocol. Specification, delegation schemas, key-scoping policy. What you implement against.
op-policy-engineThe engine, and the package you install. Offline credential verification, mandate enforcement, decision attestations.
op-verify-serviceThe hosted verifier, and the runnable one. Dockerfile, compose file, and a smoke test that can fail.
op-adaptersPer-rail integrations: Lightning/L402, x402, MPP/Tempo, Tether WDK, OWS/Solana, AP2, Fireblocks. One repository, seven packages, each carrying an explicit support tier.

The adapters are not equally supported and the difference is stated, not implied. One is proven against a live system and not yet deployable; the rest are reference implementations, two of which have no published package at all. Each README says which it is and what backs that claim, because an unlabelled reference integration that someone picks up expecting production support is worse than no listing.

What is deliberately not claimed

The hosted endpoint is a convenience, never a dependency. What it checks on a delegation credential can be re-checked offline from the npm package: the issuer DID document is public, the schema URLs are frozen and content-addressed, and revocation status lists are static public files.

That set is delegation credentials, refusal records and lapse records. It does not include determinations, resolutions, instructions or releases. A PolicyEvaluationCredential is a determination and is a different artifact from a refusal record; both published PECs still fail with PEC-NO-VERIFIER-PATH, enforced in the website repository's CI.

Refusal records became verifiable at engine rc.9, which exports the payload builder. A scratch directory containing only @observer-protocol/policy-engine@1.0.0-rc.9, with no checkout of any repository, rebuilt the signed payloads for all 14 refusals in the 2026-08-08 corpus: 14 of 14 verify, 14 of 14 reject a one-field tamper. The absence of a checkout is the point, because it makes the result a counterparty's, not ours.

"Verifiable offline by anyone" was on this org's description until 9 August 2026 with no limit at all. The list above is the limit, and it is now wider than the one written here on that date.

Archived repositories under this organisation are kept public and readable on purpose. A published package's repository link must keep resolving, and a tarball you already installed must keep verifying, whether or not the work continued.

Because they stay public, their metadata stays true. An archived repository's description and topics are a permanent public claim, not a leftover, and a permanent false claim is worse than a current one: nobody is coming back to it. When a description or topic is found wrong, the repository is unarchived, the metadata corrected, and the repository re-archived. The code is frozen at the point of archiving. The claims made about it are not. See ORG-METADATA-POLICY.md.

Pinned Loading

  1. op-adaptersop-adaptersPublic

    Observer Protocol rail adapters: Lightning/L402, x402, MPP/Tempo, Tether WDK, OWS/Solana, AP2, Fireblocks. Each carries an explicit support tier.

    TypeScript

  2. op-policy-engineop-policy-enginePublic

    Observer Protocol Policy Engine: delegation-scoped enforcement for agentic wallets. AIP v0.8 spec, schema, integration guides, TypeScript interfaces.

    TypeScript

  3. op-verify-serviceop-verify-servicePublic

    Hosted one-call verification of Observer-issued agents: identity, mandate, scope — one signed fail-closed response, composed from the public policy engine.

    JavaScript

  4. aipaipPublic

    Agentic Identity Protocol (AIP) specification

    JavaScript 1

Repositories

Showing 10 of 25 repositories

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
@observer-protocol

Observer Protocol

Verifiable authorisation for AI agent decisions and payments. Enforcement before the signature. Delegation credentials verify offline, by anyone.

Observer Protocol

An agent holds a signed mandate that says what it may spend, on which rail, with whom. Enforcement happens at the signer boundary, before a key signs, and the verdict is verifiable by anyone.

Not a trust score, not an allowlist, not a service you have to call. A delegation credential is a W3C Verifiable Credential; the check on one is offline; the issuer DID and the schemas are public and frozen.

Start here

Run a verifier yourself. Three lines, no account, no API key:

git clone https://github.com/observer-protocol/op-verify-service
cd op-verify-service && docker compose up --build
./compose-smoke.sh

The smoke test checks a credential that must verify and one that must be refused, and fails if either answer is wrong. A test that only proves the happy path cannot tell a working verifier from one that says yes to everything.

Or verify a published credential against the hosted endpoint without cloning anything:

curl -s https://observerprotocol.org/credentials/maxi-0001-trading-mandate-2026-08.json \
| jq '{agentDid: .credentialSubject.id, mandate: .}' \
| curl -s -X POST https://verify.observerprotocol.org/v1/verify \
-H 'Content-Type: application/json' --data @-

That endpoint is open by ruling. It takes an artifact as input and retrieves nothing, so a caller can only check a credential it already holds.

The repositories

repowhat it is
aipThe protocol. Specification, delegation schemas, key-scoping policy. What you implement against.
op-policy-engineThe engine, and the package you install. Offline credential verification, mandate enforcement, decision attestations.
op-verify-serviceThe hosted verifier, and the runnable one. Dockerfile, compose file, and a smoke test that can fail.
op-adaptersPer-rail integrations: Lightning/L402, x402, MPP/Tempo, Tether WDK, OWS/Solana, AP2, Fireblocks. One repository, seven packages, each carrying an explicit support tier.

The adapters are not equally supported and the difference is stated, not implied. One is proven against a live system and not yet deployable; the rest are reference implementations, two of which have no published package at all. Each README says which it is and what backs that claim, because an unlabelled reference integration that someone picks up expecting production support is worse than no listing.

What is deliberately not claimed

The hosted endpoint is a convenience, never a dependency. What it checks on a delegation credential can be re-checked offline from the npm package: the issuer DID document is public, the schema URLs are frozen and content-addressed, and revocation status lists are static public files.

That set is delegation credentials, refusal records and lapse records. It does not include determinations, resolutions, instructions or releases. A PolicyEvaluationCredential is a determination and is a different artifact from a refusal record; both published PECs still fail with PEC-NO-VERIFIER-PATH, enforced in the website repository's CI.

Refusal records became verifiable at engine rc.9, which exports the payload builder. A scratch directory containing only @observer-protocol/policy-engine@1.0.0-rc.9, with no checkout of any repository, rebuilt the signed payloads for all 14 refusals in the 2026-08-08 corpus: 14 of 14 verify, 14 of 14 reject a one-field tamper. The absence of a checkout is the point, because it makes the result a counterparty's, not ours.

"Verifiable offline by anyone" was on this org's description until 9 August 2026 with no limit at all. The list above is the limit, and it is now wider than the one written here on that date.

Archived repositories under this organisation are kept public and readable on purpose. A published package's repository link must keep resolving, and a tarball you already installed must keep verifying, whether or not the work continued.

Because they stay public, their metadata stays true. An archived repository's description and topics are a permanent public claim, not a leftover, and a permanent false claim is worse than a current one: nobody is coming back to it. When a description or topic is found wrong, the repository is unarchived, the metadata corrected, and the repository re-archived. The code is frozen at the point of archiving. The claims made about it are not. See ORG-METADATA-POLICY.md.

Pinned Loading

  1. op-adaptersop-adaptersPublic

    Observer Protocol rail adapters: Lightning/L402, x402, MPP/Tempo, Tether WDK, OWS/Solana, AP2, Fireblocks. Each carries an explicit support tier.

    TypeScript

  2. op-policy-engineop-policy-enginePublic

    Observer Protocol Policy Engine: delegation-scoped enforcement for agentic wallets. AIP v0.8 spec, schema, integration guides, TypeScript interfaces.

    TypeScript

  3. op-verify-serviceop-verify-servicePublic

    Hosted one-call verification of Observer-issued agents: identity, mandate, scope — one signed fail-closed response, composed from the public policy engine.

    JavaScript

  4. aipaipPublic

    Agentic Identity Protocol (AIP) specification

    JavaScript 1

Repositories

Showing 10 of 25 repositories

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
@observer-protocol

Observer Protocol

Verifiable authorisation for AI agent decisions and payments. Enforcement before the signature. Delegation credentials verify offline, by anyone.

Observer Protocol

An agent holds a signed mandate that says what it may spend, on which rail, with whom. Enforcement happens at the signer boundary, before a key signs, and the verdict is verifiable by anyone.

Not a trust score, not an allowlist, not a service you have to call. A delegation credential is a W3C Verifiable Credential; the check on one is offline; the issuer DID and the schemas are public and frozen.

Start here

Run a verifier yourself. Three lines, no account, no API key:

git clone https://github.com/observer-protocol/op-verify-service
cd op-verify-service && docker compose up --build
./compose-smoke.sh

The smoke test checks a credential that must verify and one that must be refused, and fails if either answer is wrong. A test that only proves the happy path cannot tell a working verifier from one that says yes to everything.

Or verify a published credential against the hosted endpoint without cloning anything:

curl -s https://observerprotocol.org/credentials/maxi-0001-trading-mandate-2026-08.json \
| jq '{agentDid: .credentialSubject.id, mandate: .}' \
| curl -s -X POST https://verify.observerprotocol.org/v1/verify \
-H 'Content-Type: application/json' --data @-

That endpoint is open by ruling. It takes an artifact as input and retrieves nothing, so a caller can only check a credential it already holds.

The repositories

repowhat it is
aipThe protocol. Specification, delegation schemas, key-scoping policy. What you implement against.
op-policy-engineThe engine, and the package you install. Offline credential verification, mandate enforcement, decision attestations.
op-verify-serviceThe hosted verifier, and the runnable one. Dockerfile, compose file, and a smoke test that can fail.
op-adaptersPer-rail integrations: Lightning/L402, x402, MPP/Tempo, Tether WDK, OWS/Solana, AP2, Fireblocks. One repository, seven packages, each carrying an explicit support tier.

The adapters are not equally supported and the difference is stated, not implied. One is proven against a live system and not yet deployable; the rest are reference implementations, two of which have no published package at all. Each README says which it is and what backs that claim, because an unlabelled reference integration that someone picks up expecting production support is worse than no listing.

What is deliberately not claimed

The hosted endpoint is a convenience, never a dependency. What it checks on a delegation credential can be re-checked offline from the npm package: the issuer DID document is public, the schema URLs are frozen and content-addressed, and revocation status lists are static public files.

That set is delegation credentials, refusal records and lapse records. It does not include determinations, resolutions, instructions or releases. A PolicyEvaluationCredential is a determination and is a different artifact from a refusal record; both published PECs still fail with PEC-NO-VERIFIER-PATH, enforced in the website repository's CI.

Refusal records became verifiable at engine rc.9, which exports the payload builder. A scratch directory containing only @observer-protocol/policy-engine@1.0.0-rc.9, with no checkout of any repository, rebuilt the signed payloads for all 14 refusals in the 2026-08-08 corpus: 14 of 14 verify, 14 of 14 reject a one-field tamper. The absence of a checkout is the point, because it makes the result a counterparty's, not ours.

"Verifiable offline by anyone" was on this org's description until 9 August 2026 with no limit at all. The list above is the limit, and it is now wider than the one written here on that date.

Archived repositories under this organisation are kept public and readable on purpose. A published package's repository link must keep resolving, and a tarball you already installed must keep verifying, whether or not the work continued.

Because they stay public, their metadata stays true. An archived repository's description and topics are a permanent public claim, not a leftover, and a permanent false claim is worse than a current one: nobody is coming back to it. When a description or topic is found wrong, the repository is unarchived, the metadata corrected, and the repository re-archived. The code is frozen at the point of archiving. The claims made about it are not. See ORG-METADATA-POLICY.md.

Pinned Loading

  1. op-adaptersop-adaptersPublic

    Observer Protocol rail adapters: Lightning/L402, x402, MPP/Tempo, Tether WDK, OWS/Solana, AP2, Fireblocks. Each carries an explicit support tier.

    TypeScript

  2. op-policy-engineop-policy-enginePublic

    Observer Protocol Policy Engine: delegation-scoped enforcement for agentic wallets. AIP v0.8 spec, schema, integration guides, TypeScript interfaces.

    TypeScript

  3. op-verify-serviceop-verify-servicePublic

    Hosted one-call verification of Observer-issued agents: identity, mandate, scope — one signed fail-closed response, composed from the public policy engine.

    JavaScript

  4. aipaipPublic

    Agentic Identity Protocol (AIP) specification

    JavaScript 1

Repositories

Showing 10 of 25 repositories

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
@observer-protocol

Observer Protocol

Verifiable authorisation for AI agent decisions and payments. Enforcement before the signature. Delegation credentials verify offline, by anyone.

Observer Protocol

An agent holds a signed mandate that says what it may spend, on which rail, with whom. Enforcement happens at the signer boundary, before a key signs, and the verdict is verifiable by anyone.

Not a trust score, not an allowlist, not a service you have to call. A delegation credential is a W3C Verifiable Credential; the check on one is offline; the issuer DID and the schemas are public and frozen.

Start here

Run a verifier yourself. Three lines, no account, no API key:

git clone https://github.com/observer-protocol/op-verify-service
cd op-verify-service && docker compose up --build
./compose-smoke.sh

The smoke test checks a credential that must verify and one that must be refused, and fails if either answer is wrong. A test that only proves the happy path cannot tell a working verifier from one that says yes to everything.

Or verify a published credential against the hosted endpoint without cloning anything:

curl -s https://observerprotocol.org/credentials/maxi-0001-trading-mandate-2026-08.json \
| jq '{agentDid: .credentialSubject.id, mandate: .}' \
| curl -s -X POST https://verify.observerprotocol.org/v1/verify \
-H 'Content-Type: application/json' --data @-

That endpoint is open by ruling. It takes an artifact as input and retrieves nothing, so a caller can only check a credential it already holds.

The repositories

repowhat it is
aipThe protocol. Specification, delegation schemas, key-scoping policy. What you implement against.
op-policy-engineThe engine, and the package you install. Offline credential verification, mandate enforcement, decision attestations.
op-verify-serviceThe hosted verifier, and the runnable one. Dockerfile, compose file, and a smoke test that can fail.
op-adaptersPer-rail integrations: Lightning/L402, x402, MPP/Tempo, Tether WDK, OWS/Solana, AP2, Fireblocks. One repository, seven packages, each carrying an explicit support tier.

The adapters are not equally supported and the difference is stated, not implied. One is proven against a live system and not yet deployable; the rest are reference implementations, two of which have no published package at all. Each README says which it is and what backs that claim, because an unlabelled reference integration that someone picks up expecting production support is worse than no listing.

What is deliberately not claimed

The hosted endpoint is a convenience, never a dependency. What it checks on a delegation credential can be re-checked offline from the npm package: the issuer DID document is public, the schema URLs are frozen and content-addressed, and revocation status lists are static public files.

That set is delegation credentials, refusal records and lapse records. It does not include determinations, resolutions, instructions or releases. A PolicyEvaluationCredential is a determination and is a different artifact from a refusal record; both published PECs still fail with PEC-NO-VERIFIER-PATH, enforced in the website repository's CI.

Refusal records became verifiable at engine rc.9, which exports the payload builder. A scratch directory containing only @observer-protocol/policy-engine@1.0.0-rc.9, with no checkout of any repository, rebuilt the signed payloads for all 14 refusals in the 2026-08-08 corpus: 14 of 14 verify, 14 of 14 reject a one-field tamper. The absence of a checkout is the point, because it makes the result a counterparty's, not ours.

"Verifiable offline by anyone" was on this org's description until 9 August 2026 with no limit at all. The list above is the limit, and it is now wider than the one written here on that date.

Archived repositories under this organisation are kept public and readable on purpose. A published package's repository link must keep resolving, and a tarball you already installed must keep verifying, whether or not the work continued.

Because they stay public, their metadata stays true. An archived repository's description and topics are a permanent public claim, not a leftover, and a permanent false claim is worse than a current one: nobody is coming back to it. When a description or topic is found wrong, the repository is unarchived, the metadata corrected, and the repository re-archived. The code is frozen at the point of archiving. The claims made about it are not. See ORG-METADATA-POLICY.md.

Pinned Loading

  1. op-adaptersop-adaptersPublic

    Observer Protocol rail adapters: Lightning/L402, x402, MPP/Tempo, Tether WDK, OWS/Solana, AP2, Fireblocks. Each carries an explicit support tier.

    TypeScript

  2. op-policy-engineop-policy-enginePublic

    Observer Protocol Policy Engine: delegation-scoped enforcement for agentic wallets. AIP v0.8 spec, schema, integration guides, TypeScript interfaces.

    TypeScript

  3. op-verify-serviceop-verify-servicePublic

    Hosted one-call verification of Observer-issued agents: identity, mandate, scope — one signed fail-closed response, composed from the public policy engine.

    JavaScript

  4. aipaipPublic

    Agentic Identity Protocol (AIP) specification

    JavaScript 1

Repositories

Showing 10 of 25 repositories

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
@observer-protocol

Observer Protocol

Verifiable authorisation for AI agent decisions and payments. Enforcement before the signature. Delegation credentials verify offline, by anyone.

Observer Protocol

An agent holds a signed mandate that says what it may spend, on which rail, with whom. Enforcement happens at the signer boundary, before a key signs, and the verdict is verifiable by anyone.

Not a trust score, not an allowlist, not a service you have to call. A delegation credential is a W3C Verifiable Credential; the check on one is offline; the issuer DID and the schemas are public and frozen.

Start here

Run a verifier yourself. Three lines, no account, no API key:

git clone https://github.com/observer-protocol/op-verify-service
cd op-verify-service && docker compose up --build
./compose-smoke.sh

The smoke test checks a credential that must verify and one that must be refused, and fails if either answer is wrong. A test that only proves the happy path cannot tell a working verifier from one that says yes to everything.

Or verify a published credential against the hosted endpoint without cloning anything:

curl -s https://observerprotocol.org/credentials/maxi-0001-trading-mandate-2026-08.json \
| jq '{agentDid: .credentialSubject.id, mandate: .}' \
| curl -s -X POST https://verify.observerprotocol.org/v1/verify \
-H 'Content-Type: application/json' --data @-

That endpoint is open by ruling. It takes an artifact as input and retrieves nothing, so a caller can only check a credential it already holds.

The repositories

repowhat it is
aipThe protocol. Specification, delegation schemas, key-scoping policy. What you implement against.
op-policy-engineThe engine, and the package you install. Offline credential verification, mandate enforcement, decision attestations.
op-verify-serviceThe hosted verifier, and the runnable one. Dockerfile, compose file, and a smoke test that can fail.
op-adaptersPer-rail integrations: Lightning/L402, x402, MPP/Tempo, Tether WDK, OWS/Solana, AP2, Fireblocks. One repository, seven packages, each carrying an explicit support tier.

The adapters are not equally supported and the difference is stated, not implied. One is proven against a live system and not yet deployable; the rest are reference implementations, two of which have no published package at all. Each README says which it is and what backs that claim, because an unlabelled reference integration that someone picks up expecting production support is worse than no listing.

What is deliberately not claimed

The hosted endpoint is a convenience, never a dependency. What it checks on a delegation credential can be re-checked offline from the npm package: the issuer DID document is public, the schema URLs are frozen and content-addressed, and revocation status lists are static public files.

That set is delegation credentials, refusal records and lapse records. It does not include determinations, resolutions, instructions or releases. A PolicyEvaluationCredential is a determination and is a different artifact from a refusal record; both published PECs still fail with PEC-NO-VERIFIER-PATH, enforced in the website repository's CI.

Refusal records became verifiable at engine rc.9, which exports the payload builder. A scratch directory containing only @observer-protocol/policy-engine@1.0.0-rc.9, with no checkout of any repository, rebuilt the signed payloads for all 14 refusals in the 2026-08-08 corpus: 14 of 14 verify, 14 of 14 reject a one-field tamper. The absence of a checkout is the point, because it makes the result a counterparty's, not ours.

"Verifiable offline by anyone" was on this org's description until 9 August 2026 with no limit at all. The list above is the limit, and it is now wider than the one written here on that date.

Archived repositories under this organisation are kept public and readable on purpose. A published package's repository link must keep resolving, and a tarball you already installed must keep verifying, whether or not the work continued.

Because they stay public, their metadata stays true. An archived repository's description and topics are a permanent public claim, not a leftover, and a permanent false claim is worse than a current one: nobody is coming back to it. When a description or topic is found wrong, the repository is unarchived, the metadata corrected, and the repository re-archived. The code is frozen at the point of archiving. The claims made about it are not. See ORG-METADATA-POLICY.md.

Pinned Loading

  1. op-adaptersop-adaptersPublic

    Observer Protocol rail adapters: Lightning/L402, x402, MPP/Tempo, Tether WDK, OWS/Solana, AP2, Fireblocks. Each carries an explicit support tier.

    TypeScript

  2. op-policy-engineop-policy-enginePublic

    Observer Protocol Policy Engine: delegation-scoped enforcement for agentic wallets. AIP v0.8 spec, schema, integration guides, TypeScript interfaces.

    TypeScript

  3. op-verify-serviceop-verify-servicePublic

    Hosted one-call verification of Observer-issued agents: identity, mandate, scope — one signed fail-closed response, composed from the public policy engine.

    JavaScript

  4. aipaipPublic

    Agentic Identity Protocol (AIP) specification

    JavaScript 1

Repositories

Showing 10 of 25 repositories

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
@observer-protocol

Observer Protocol

Verifiable authorisation for AI agent decisions and payments. Enforcement before the signature. Delegation credentials verify offline, by anyone.

Observer Protocol

An agent holds a signed mandate that says what it may spend, on which rail, with whom. Enforcement happens at the signer boundary, before a key signs, and the verdict is verifiable by anyone.

Not a trust score, not an allowlist, not a service you have to call. A delegation credential is a W3C Verifiable Credential; the check on one is offline; the issuer DID and the schemas are public and frozen.

Start here

Run a verifier yourself. Three lines, no account, no API key:

git clone https://github.com/observer-protocol/op-verify-service
cd op-verify-service && docker compose up --build
./compose-smoke.sh

The smoke test checks a credential that must verify and one that must be refused, and fails if either answer is wrong. A test that only proves the happy path cannot tell a working verifier from one that says yes to everything.

Or verify a published credential against the hosted endpoint without cloning anything:

curl -s https://observerprotocol.org/credentials/maxi-0001-trading-mandate-2026-08.json \
| jq '{agentDid: .credentialSubject.id, mandate: .}' \
| curl -s -X POST https://verify.observerprotocol.org/v1/verify \
-H 'Content-Type: application/json' --data @-

That endpoint is open by ruling. It takes an artifact as input and retrieves nothing, so a caller can only check a credential it already holds.

The repositories

repowhat it is
aipThe protocol. Specification, delegation schemas, key-scoping policy. What you implement against.
op-policy-engineThe engine, and the package you install. Offline credential verification, mandate enforcement, decision attestations.
op-verify-serviceThe hosted verifier, and the runnable one. Dockerfile, compose file, and a smoke test that can fail.
op-adaptersPer-rail integrations: Lightning/L402, x402, MPP/Tempo, Tether WDK, OWS/Solana, AP2, Fireblocks. One repository, seven packages, each carrying an explicit support tier.

The adapters are not equally supported and the difference is stated, not implied. One is proven against a live system and not yet deployable; the rest are reference implementations, two of which have no published package at all. Each README says which it is and what backs that claim, because an unlabelled reference integration that someone picks up expecting production support is worse than no listing.

What is deliberately not claimed

The hosted endpoint is a convenience, never a dependency. What it checks on a delegation credential can be re-checked offline from the npm package: the issuer DID document is public, the schema URLs are frozen and content-addressed, and revocation status lists are static public files.

That set is delegation credentials, refusal records and lapse records. It does not include determinations, resolutions, instructions or releases. A PolicyEvaluationCredential is a determination and is a different artifact from a refusal record; both published PECs still fail with PEC-NO-VERIFIER-PATH, enforced in the website repository's CI.

Refusal records became verifiable at engine rc.9, which exports the payload builder. A scratch directory containing only @observer-protocol/policy-engine@1.0.0-rc.9, with no checkout of any repository, rebuilt the signed payloads for all 14 refusals in the 2026-08-08 corpus: 14 of 14 verify, 14 of 14 reject a one-field tamper. The absence of a checkout is the point, because it makes the result a counterparty's, not ours.

"Verifiable offline by anyone" was on this org's description until 9 August 2026 with no limit at all. The list above is the limit, and it is now wider than the one written here on that date.

Archived repositories under this organisation are kept public and readable on purpose. A published package's repository link must keep resolving, and a tarball you already installed must keep verifying, whether or not the work continued.

Because they stay public, their metadata stays true. An archived repository's description and topics are a permanent public claim, not a leftover, and a permanent false claim is worse than a current one: nobody is coming back to it. When a description or topic is found wrong, the repository is unarchived, the metadata corrected, and the repository re-archived. The code is frozen at the point of archiving. The claims made about it are not. See ORG-METADATA-POLICY.md.

Pinned Loading

  1. op-adaptersop-adaptersPublic

    Observer Protocol rail adapters: Lightning/L402, x402, MPP/Tempo, Tether WDK, OWS/Solana, AP2, Fireblocks. Each carries an explicit support tier.

    TypeScript

  2. op-policy-engineop-policy-enginePublic

    Observer Protocol Policy Engine: delegation-scoped enforcement for agentic wallets. AIP v0.8 spec, schema, integration guides, TypeScript interfaces.

    TypeScript

  3. op-verify-serviceop-verify-servicePublic

    Hosted one-call verification of Observer-issued agents: identity, mandate, scope — one signed fail-closed response, composed from the public policy engine.

    JavaScript

  4. aipaipPublic

    Agentic Identity Protocol (AIP) specification

    JavaScript 1

Repositories

Showing 10 of 25 repositories

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
@observer-protocol

Observer Protocol

Verifiable authorisation for AI agent decisions and payments. Enforcement before the signature. Delegation credentials verify offline, by anyone.

Observer Protocol

An agent holds a signed mandate that says what it may spend, on which rail, with whom. Enforcement happens at the signer boundary, before a key signs, and the verdict is verifiable by anyone.

Not a trust score, not an allowlist, not a service you have to call. A delegation credential is a W3C Verifiable Credential; the check on one is offline; the issuer DID and the schemas are public and frozen.

Start here

Run a verifier yourself. Three lines, no account, no API key:

git clone https://github.com/observer-protocol/op-verify-service
cd op-verify-service && docker compose up --build
./compose-smoke.sh

The smoke test checks a credential that must verify and one that must be refused, and fails if either answer is wrong. A test that only proves the happy path cannot tell a working verifier from one that says yes to everything.

Or verify a published credential against the hosted endpoint without cloning anything:

curl -s https://observerprotocol.org/credentials/maxi-0001-trading-mandate-2026-08.json \
| jq '{agentDid: .credentialSubject.id, mandate: .}' \
| curl -s -X POST https://verify.observerprotocol.org/v1/verify \
-H 'Content-Type: application/json' --data @-

That endpoint is open by ruling. It takes an artifact as input and retrieves nothing, so a caller can only check a credential it already holds.

The repositories

repowhat it is
aipThe protocol. Specification, delegation schemas, key-scoping policy. What you implement against.
op-policy-engineThe engine, and the package you install. Offline credential verification, mandate enforcement, decision attestations.
op-verify-serviceThe hosted verifier, and the runnable one. Dockerfile, compose file, and a smoke test that can fail.
op-adaptersPer-rail integrations: Lightning/L402, x402, MPP/Tempo, Tether WDK, OWS/Solana, AP2, Fireblocks. One repository, seven packages, each carrying an explicit support tier.

The adapters are not equally supported and the difference is stated, not implied. One is proven against a live system and not yet deployable; the rest are reference implementations, two of which have no published package at all. Each README says which it is and what backs that claim, because an unlabelled reference integration that someone picks up expecting production support is worse than no listing.

What is deliberately not claimed

The hosted endpoint is a convenience, never a dependency. What it checks on a delegation credential can be re-checked offline from the npm package: the issuer DID document is public, the schema URLs are frozen and content-addressed, and revocation status lists are static public files.

That set is delegation credentials, refusal records and lapse records. It does not include determinations, resolutions, instructions or releases. A PolicyEvaluationCredential is a determination and is a different artifact from a refusal record; both published PECs still fail with PEC-NO-VERIFIER-PATH, enforced in the website repository's CI.

Refusal records became verifiable at engine rc.9, which exports the payload builder. A scratch directory containing only @observer-protocol/policy-engine@1.0.0-rc.9, with no checkout of any repository, rebuilt the signed payloads for all 14 refusals in the 2026-08-08 corpus: 14 of 14 verify, 14 of 14 reject a one-field tamper. The absence of a checkout is the point, because it makes the result a counterparty's, not ours.

"Verifiable offline by anyone" was on this org's description until 9 August 2026 with no limit at all. The list above is the limit, and it is now wider than the one written here on that date.

Archived repositories under this organisation are kept public and readable on purpose. A published package's repository link must keep resolving, and a tarball you already installed must keep verifying, whether or not the work continued.

Because they stay public, their metadata stays true. An archived repository's description and topics are a permanent public claim, not a leftover, and a permanent false claim is worse than a current one: nobody is coming back to it. When a description or topic is found wrong, the repository is unarchived, the metadata corrected, and the repository re-archived. The code is frozen at the point of archiving. The claims made about it are not. See ORG-METADATA-POLICY.md.

Pinned Loading

  1. op-adaptersop-adaptersPublic

    Observer Protocol rail adapters: Lightning/L402, x402, MPP/Tempo, Tether WDK, OWS/Solana, AP2, Fireblocks. Each carries an explicit support tier.

    TypeScript

  2. op-policy-engineop-policy-enginePublic

    Observer Protocol Policy Engine: delegation-scoped enforcement for agentic wallets. AIP v0.8 spec, schema, integration guides, TypeScript interfaces.

    TypeScript

  3. op-verify-serviceop-verify-servicePublic

    Hosted one-call verification of Observer-issued agents: identity, mandate, scope — one signed fail-closed response, composed from the public policy engine.

    JavaScript

  4. aipaipPublic

    Agentic Identity Protocol (AIP) specification

    JavaScript 1

Repositories

Showing 10 of 25 repositories

Top languages

Loading…

Most used topics

Loading…