The neutral authority layer for autonomous systems
Authority for machines that act.
Delegus gives AI agents, robots, and autonomous systems machine-verifiable authority to act on behalf of organizations.
Identity tells you who it is. Delegus tells you what it is allowed to do.
Before a machine spends, signs, books, deploys, unlocks, moves, or takes another consequential action, Delegus verifies who delegated the authority, what limits apply, whether approval is required, and whether that authority is still valid right now.
Then Delegus signs the decision. After the action, that signed receipt proves what was decided and why.
Verify before. Prove after.
Free sandbox, no card. Then 14 days free in production. Read the quickstart
Signup to first signed receipt: under a minute.
From deciding to doing.
- Building the AItraining
- The AI decidesinference
- The agent proposesagency
- Delegus checksauthority
- The world actsaction
- The model decides“Acme needs more compute.”
- The agent proposes“Buy 400 GPU-hours from ComputeCo for $18,400.”
- Delegus checks“Does this agent have Acme’s authority to do this, right now?”
- AllowedComputeCo accepts the order.
- Signed receiptBoth sides can check later what was decided and why.
AI decides. Delegus checks. The world acts.
AI decides what a machine wants to do. Delegus checks whether it is allowed to do it.
You don’t have to make an AI model perfect. You limit what its decisions can cause.
Every AI that can act will reach this line between deciding and doing. The more decisions AI makes, the more actions cross it. Delegus is the check at that line, for every one.
Identity isn’t authority.
An autonomous system can have a valid identity and still have no authority to perform a particular action.
Delegus verifies the delegation behind the action.
- Who authorized it?
- To do what?
- Under what limits?
- Until when?
- Does it require approval?
- Has that authority been revoked?
And when the answer is yes, Delegus signs a receipt: cryptographic proof of what was checked, what was decided, and when.
From human intent to machine action.
- Organizationdelegates authority
- Delegusverifies scope, limits, approval and validity
- AI Agent · Robot · Autonomous Systemacts
- Service · Machine · Real World
- Signed Receipt
A check before action. A proof after.
Machine-verifiable power of attorney.
People have always delegated authority to other people.
Companies delegate authority through contracts, policies, roles, mandates and powers of attorney.
Autonomous systems need the machine-readable equivalent.
Delegus turns an organization’s intent into explicit, bounded, revocable authority that another machine can verify.
Not simply: “Who is this agent?”
But: “Is this agent authorized to perform this exact action, under these exact conditions, right now?”
Intelligence creates capability. Delegation creates authority. Delegus sits between the two.
Video
Video Intro
For MCP servers
Any web-facing MCP server, in any language
Every tools/call is checked before the tool runs: a denied call never runs, and each decision comes back with its reason and a signed receipt. Three ways in, one check:
Node middlewareExpress-style servers, one line
app.use("/mcp", delegus.mcp())Python middlewareOfficial MCP SDK, Starlette, FastAPI
pip install delegus-mcpGatewayIn front of a server in any language
npx @delegus/mcp-gatewayOver HTTP (streamable HTTP); servers that only speak stdio aren’t covered.
Not MCP? The same check sits in front of an ordinary web API: app.use(delegus.http({ routeMap })) in a Node server, or npx @delegus/http-gateway in front of an API in any language. Check requests to any API
Test your agent before you ship it: npm i -D @delegus/test, or try it in your browser with Delegus Check.
How it works
How authority travels from a company to a stranger's server
A company gives its agent a signed permission. The agent takes it to a business that has never seen it. Before acting, that business asks Delegus to check it.
Every link is a signature or a domain proof. The only party asserting anything on its own authority is Delegus, at the end, and it signs what it asserted. The company can withdraw the permission at any moment.
Why Delegus exists
Identity made strangers recognizable. Payment networks made strangers economically interoperable. Delegus makes delegated authority between strangers verifiable.
See it work
Watch a real run, then try it.
An AI agent tried to commit Acme to $31,000 with a $25,000-per-order limit. Refused, with a signed receipt and no invoice.
Acme’s agent, procurement-7, orders compute from ComputeCo on invoice terms. ComputeCo has never dealt with it, so it checks with Delegus before it books anything. Every terminal line in the recording is the real output of the run, in order; the code is the seller’s own.
See the full run
The check ran in the Delegus reference engine on the recording machine, not the production service.
Try the live demo Open the recording page Why Delegus exists
One call. Two outcomes. Nothing to learn first.
The agent presents two headers with its request: a grant signed by the company it works for, and a proof signed with its own key. The receiving service forwards both, plus what it actually received, to Delegus.
// The relying party's entire integration
import { Delegus } from "@delegus/sdk";
const delegus = new Delegus({ apiKey: process.env.DELEGUS_API_KEY });
app.post("/orders", async (req, res) => {
const d = await delegus.verify({
grant: req.header("Delegus-Grant"),
proof: req.header("Delegus-Proof"),
action: { type: "commerce:purchase", resource: req.body.orderId,
amount: req.body.amountMinor, currency: req.body.currency },
});
if (d.decision !== "ALLOW") return res.status(403).json({ reason: d.reason });
// proceed, and keep d.receipt with the order
});
No DIDs, credentials, or status lists to understand. If a denial comes back, it says why: AMOUNT_EXCEEDS_AUTHORITY, AUTHORITY_REVOKED, PROOF_REPLAYED, and so on. The engineer who has never seen the agent before can add it in a few lines.
Every decision leaves evidence that outlives it
The receipt pins hashes of the grant, the request, the company's key document as it stood, the revocation list as it stood, the exact rules applied, and the evaluation time. Delegus signs the whole thing and keeps the referenced artifacts.
Years later, anyone with the receipt can confirm it is genuine and unchanged, and the business and the company behind it can check what it relied on, without calling Delegus. If a partner ever asks who let that happen, the answer is a signed document, not a log search.
Outcomes are recorded too. The receiving service reports what happened afterward — fulfilled, disputed, resolved — and nothing is ever overwritten. Over time that turns decisions into something rarer than identity data: a record of authority, decision, reliance, and outcome.
Try it: anyone can check a receipt is genuine. Change one character and watch the signature check fail, in your browser.Open format. Closed service.
Anyone can verify a Delegus artifact without calling Delegus. Nobody else can produce a fresh one.
Published and reproducible
- Grant semantics and the constraint vocabulary
- Proof format, carrying the request’s method and URL
- Protocol verification rules, versioned and hashed
- Receipt and outcome formats
- Use your own web domain as your company’s identity
Run by Delegus
- Issuer trust and domain verification
- Live revocation and replay protection
- Decision signing and evidence preservation
- The outcome graph, and what it eventually makes possible
Starting where agents already spend money on behalf of companies
Business procurement is going autonomous first. Company A's agent buys GPU hours, dataset access, or software seats from Company B's API. The money can move; what's missing is a way for B to know that A's agent was authorized to spend it.
Payment networks answer whether the money can move. Delegus answers the prior question: was this machine authorized by this company to enter this transaction?
Start free
Sign up with your work email, copy your verify key, and send your first request. You get a signed decision back straight away. The sandbox is free, with no card. When you go live, the first 14 days are free; then Starter is $99 a month unless you cancel.
Founding pilots
$1,500 a month, flat, for up to 2 million checks. Self-serve, with the price locked for 12 months. For companies whose agents buy, and for services that sell to agents through an API.
Founding pilot program