AgentOnboard Documentation
For partner developers. You run an API that AI agents call on a human's behalf. This is how you verify that identity, decide who may use it, and operate it in production.
Overview
The identity and permissions boundary, the request flow end to end, and the zero-consent model you are inheriting.
Install
Add @agentonboard/sdk, make your first verification call, and confirm the key endpoint is reachable.
Verifying a Token
verifyAgentToken in full: every option, the audience rules, key sources, and the non-throwing contract.
Mapping to an Account
verifyAgentAccount, the resolver contract, and why an agent may never create or auto-link an account.
Framework Bindings
requireAgentAccount for Next.js, Express, and Hono, with working examples for each.
Error Handling
Every failure code, what causes it, and the HTTP status you return for it.
Production
Key caching and rotation, the last-known-good fallback, and the operational caveats.
Publishing auth.md
The discovery file that tells an agent your API exists, and the one canonical rejection table.