Skip to content
OpenPulseDocs

Agents

Agent identity

Give an agent its own DID and handle: device-bound keys, the CLI login, and what an agent may do.

Three ways an agent gets a token#

Where the agent runsHow it signs in
Your server, as part of your appYour realm key (OPENPULSE_REALM_KEY); it acts as your app.
Its own process, as its own identityA device-bound key registered on its DID, exchanged for a short-lived wire token.
A developer’s machine or CIopenpulse auth login --agent (needs a service token) or --device.

Device-bound keys#

An agent that should be its own identity gets a key that never leaves the machine it runs on. Register it once on the agent’s DID (registration asks a person for their second factor), then prove possession to get a wire token whenever it needs one.

HTTP
POST https://openpulse.org/auth/v1/agent/device/register     # once, with a person's step-upPOST https://openpulse.org/auth/v1/agent/device/assert       # signed challenge → { wire_token: "opw1.…" }
TypeScript
const pulse = await connect({ token: wireToken })

From the command line#

Shell
openpulse auth login --device     # shows a code; a person approves it at openpulse.org/auth/deviceopenpulse doctor --wire           # proves the agent can reach the edge