AI Passport developer docs

Changelog

Additive contract changes and shipped partner-program waves.

This page records changes to sign-in, agent connections, and partner integrations.

Generally available. Admission for host-consistent metadata-document clients is automatic. The contract changes only with notice on the changelog.

2026-09-16

Garmin branding and source attribution

  • Garmin Connect™ connection surfaces use the official app tile and full name.
  • Garmin connector results and workout sample responses include optional garmin_attribution display labels with provider-supplied device models, falling back to Garmin when a model is unavailable.
  • Receiving applications must retain attribution beside their data, including derived or combined results and exports. See Garmin attribution.

2026-09-08

Device authorization for agents

  • Personal and headless agents can connect without a public host through device authorization. The owner checks a code and agent name on my.ego.ist.
  • Caller-chosen names are shown as unverified. A client id returned by an earlier device pairing may be reused. Purpose scopes are unavailable in this flow.
  • ai-passport-signin@0.3.0 adds createDevicePairing with begin, poll, and abortable wait helpers and verified OpenID token handling.

Connect codes for any agent

  • Owner-minted connect codes now support muse (Muse) and other for any agent, alongside OpenClaw, Hermes, and OpenCode. Generic names are unverified.
  • Codes expire in 10 minutes, work once, and return a memory-scoped token pair.

Capability discovery

  • Call the new MCP passport_status tool first for scopes, memory state, this app's passes, and enabled and linked connectors.
  • The passport claim can include memory_locked and connectors only with granted memory and a completed lookup. /userinfo follows the same rule.
  • MCP recall leads with live connector data through its connectors parameter.

Recall outcomes

  • Approval notices remain visible when another category is locked. Structured recall gives approval_required priority over locked.
  • Temporary scoped custody failures return a retry notice or unavailable. Only an owner who must unlock once receives unlock guidance. A locked structured category may include unlock_url.

Admission wording

  • Docs now state that automatic admission for host-consistent CIMD clients is live from the 2026-08-20 wave, enabled in production on 2026-08-21. Loopback redirect URIs are exempt from the host-subtree rule.
  • DCR remains deprecated and compatible with manual admission. Partner entitlements remain operator-provisioned, and admission confirms domain control only.

2026-09-03

Grant revocation without a refresh token

  • Authorization-code exchanges can return a one-time revocation_handle. Native clients can persist it with a stable command identifier and revoke the grant after destroying local bearer tokens.

Purpose scopes for metadata-document clients

  • A Client Identifier Metadata Document may declare booking:actions and connector:reads in scope. A client can request a purpose scope only when its document declares it and the deployment offers it.
  • clientMetadataDocument() in ai-passport-signin accepts a scope array.

Signed directed-disclosure deliveries

  • Every delivery carries a short-lived signed Passport-Disclosure-Attestation header next to the stable Idempotency-Key. Verify it against the JWKS before reading the body.
  • Delivery is now at most once. Passport retries only when the destination provably did not process the request. An unanswered request or a 5xx response is never sent again and the status stays pending.
  • request_disclosure accepts a controlled purpose: directed_disclosure (default) or travel_booking.

Access-token client binding

  • ID tokens include at_hash. Verify it against the access token returned in the same exchange.
  • Added POST /oauth/token-info, advertised as introspection_endpoint. It takes the access token as its bearer and returns the server-derived client_id, sub, scope, and exp.
  • Token-info also accepts a sender-constrained access token with the DPoP scheme and a DPoP proof. It returns token_type DPoP, the confirmation thumbprint, and the registered device id.
  • complete() in ai-passport-signin now verifies at_hash and requires the issuer to emit it.

2026-08-20

Sign-in SDK and client metadata documents

  • Added Client Identifier Metadata Documents (CIMD) for registration and automatic admission of host-consistent clients.
  • Added the ai-passport-signin package with browser, React, and server helpers.
  • Added official light and dark sign-in button assets and the approved mark.
  • Added agent-facing documentation and the /llms-install.md install prompt.

Compatibility contract

The /v1 contract can grow without a version change. Treat these changes as additive and non-breaking:

  • New endpoints
  • New optional response fields
  • New error strings
  • New item status values

Clients shall tolerate all four changes. Ignore fields you do not use. Keep an unknown error or status visible in diagnostics.

Removing a field, requiring a new input, or changing existing behavior is a breaking change. We give partners direct notice before one ships.

Quota changes are operational changes. Read current dials from GET /partner/v1/me and honor Retry-After.

2026-08-14

Hosted connector credential entry

  • Added POST /partner/v1/connectors/connect-key.
  • Provider API keys now go directly to an AI Passport-hosted page.
  • Added durable attempt budgets and a 10-minute ambiguity horizon.

Partner hardening and lifecycle signals

  • Added bounded refresh response recovery and token-family reuse handling.
  • Added RFC 8936 standing-event delivery at POST /partner/v1/events.
  • Added request IDs, retry headers, named rate limits, and content-free signals.
  • Accepted the partner platform design after the release gates passed.
  • Added Passport Link ticket mint and redemption.
  • Added REST and MCP workspace operations.
  • Added workspace quotas, retention, export, deletion, and owner visibility.

2026-08-13

Partner owner controls

  • Added one owner action to forget all memories from one partner source.
  • Preserved the action after the owner severs the partner delegation.

2026-08-12

Partner API phases 2 through 5

  • Added connector listing and connection initiation.
  • Added source-attributed memory ingestion.
  • Added pass-governed recall and partner documentation.

Partner API phase 1

  • Added managed partner records and hashed API keys.
  • Added attested net-new provisioning and delegated token pairs.
  • Added creation notices, owner recourse, and one-tap delegation severing.

On this page