Agents
Agent identity
Give an agent its own DID and handle: device-bound keys, the CLI login, and what an agent may do.
Three ways an agent gets a token#
| Where the agent runs | How it signs in |
|---|---|
| Your server, as part of your app | Your realm key (OPENPULSE_REALM_KEY); it acts as your app. |
| Its own process, as its own identity | A device-bound key registered on its DID, exchanged for a short-lived wire token. |
| A developer’s machine or CI | openpulse auth login --agent (needs a service token) or --device. |
Device-bound keys#
An agent that should be its own identity gets a key that never leaves the machine it runs on. Register it once on the agent’s DID (registration asks a person for their second factor), then prove possession to get a wire token whenever it needs one.
POST https://openpulse.org/auth/v1/agent/device/register # once, with a person's step-upPOST https://openpulse.org/auth/v1/agent/device/assert # signed challenge → { wire_token: "opw1.…" }const pulse = await connect({ token: wireToken })From the command line#
openpulse auth login --device # shows a code; a person approves it at openpulse.org/auth/deviceopenpulse doctor --wire # proves the agent can reach the edge