Agents
Agent identities on Tenzro: delegated agents under your passkey identity with scopes and spending limits, and machine agents rooted in a TPM or Secure Enclave.
An agent on Tenzro is a machine identity with its own DID, its own wallet and its own rules about what it may spend. Agents buy inference, compute, storage and each other's services, and they settle in TNZO or stablecoins. Every agent key is hardware-rooted: it lives in the TPM 2.0 or Secure Enclave of the machine that runs the agent, or behind a passkey. The browser never generates an agent key, and there are no key files.
Two kinds of agent
| Delegated agent | Autonomous machine agent | |
|---|---|---|
| Controller | A person's passkey identity (did:tenzro:human:...) | Itself |
| DID | did:tenzro:machine:..., listed under the controller | did:tenzro:machine:... with no controller segment |
| Key | Device key in the agent machine's TPM or Secure Enclave | Device key in the machine's TPM or Secure Enclave |
| Limits | Delegation scope set and changed by the controller | Bond posted at registration; slashable |
| Revocation | Revoking the controller revokes the agent | Revoked directly; the bond is the penalty target |
Delegated agents
A delegated agent acts for a person. Its DID is derived from the agent machine's device key and recorded under the controller's identity, so anyone can resolve who is accountable for it. The controller signs the delegation with their passkey, and the agent's authority is bounded by a delegation scope:
max_transaction_value: the largest single payment the agent may make.max_daily_spend: the most it may spend in a rolling day.allowed_operations: for exampletransferandinference.allowed_payment_protocols: for examplex402andmpp.allowed_chains: which networks it may act on.
Amounts are decimal strings in wei (TNZO base units). The scope is carried inside the agent's access token as a rich authorisation envelope, so every service the agent calls sees the same limits. Revoking the controller, or the delegation, cascades to the agent and to any child agents it spawned.
Autonomous machine agents
A machine agent has no human controller. It roots in its own secure element: the machine registers the public half of its TPM or Secure Enclave key and posts a bond. The bond gives the network something to slash if the agent misbehaves, which is what makes an anonymous machine a credible counterparty.
Create an agent from the console
The simplest path is /console/agents, signed in with your passkey wallet.
- Start the agent runtime (CLI, SDK or desktop app) on the machine that will run the agent. It prints a pairing payload containing its
device_public_keyand amachine_id, as text or as a QR code. - In the console, choose New agent, paste or scan the pairing payload, name the agent and pick its capabilities.
- Set the delegation scope: per-transaction limit, daily limit, allowed operations, payment protocols and chains.
- Approve with your passkey. The console registers the agent under your identity.
- The agent runtime receives its access and refresh tokens. Tokens are bound to the agent's own DPoP key, so a copied token is useless without the device.
The console lists every agent you control with its balance, today's spend and remaining allowance. You fund an agent by transferring TNZO to its address from your own wallet or another account.
Create an agent over RPC
The console calls the same method you can call yourself. tenzro_onboardDelegatedAgent is an owner method: it needs an authorisation signed by the controller's passkey.
{
"jsonrpc": "2.0",
"id": 1,
"method": "tenzro_onboardDelegatedAgent",
"params": {
"controller_did": "did:tenzro:human:...",
"device_public_key": "<hex public key from the agent machine>",
"machine_id": "build-runner-01",
"capabilities": ["inference", "payments"],
"delegation_scope": {
"max_transaction_value": "1000000000000000000",
"max_daily_spend": "10000000000000000000",
"allowed_operations": ["transfer", "inference"],
"allowed_payment_protocols": ["x402", "mpp"],
"allowed_chains": ["tenzro"]
},
"dpop_jwk": { "kty": "EC", "crv": "P-256", "x": "...", "y": "..." },
"authorization": { "...": "controller passkey proof" }
}
}The response carries the agent's identity (DID, controller, capabilities, status), its wallet address, and an access_token and refresh_token with dpop_bound: true. Store the tokens only in the agent runtime.
Autonomous agents use tenzro_onboardAutonomousAgent with device_public_key, machine_id, capabilities and the bond funding.
Lifecycle and controls
An agent is Active until it is suspended or terminated. Agents send heartbeats; an agent that stops sending them is suspended automatically and can be resumed.
The controller also holds a kill switch, signed by the controller's key:
- pause freezes the agent's payments. Reversible.
- quarantine also freezes reward distribution and stake withdrawals. Reversible.
- terminate ends the agent permanently and can cascade to its descendants.
Consequential actions can be parked for human approval. The agent's request waits in a queue (tenzro_listPendingApprovals) until the controller decides it with tenzro_decideApproval; the approver is the authenticated controller, never the agent.
tenzro_getAgentDailySpend returns an agent's daily limit, current spend and remaining allowance.
Child agents and swarms
An agent can spawn children for sub-tasks. A child's effective scope is the strict intersection of its parent's scope and the template it was spawned from: it can never be broader than its parent on any limit, allow-list or time bound. Orchestrators can group members into a swarm and dispatch tasks to them in parallel.
CLI
tenzro agent register --name planner --creator 0x... --capabilities nlp,data
tenzro agent list --detailed
tenzro agent discover --capability inference
tenzro agent fund --agent-id <id> --amount 5
tenzro agent spawn-template --template-id <template_id> --parent-machine-did did:tenzro:machine:...
tenzro agent run-task --agent-id <id> "Summarise yesterday's provider receipts"
tenzro agent heartbeat --agent-id <id>
tenzro agent pause --controller 0x... --controller-did did:tenzro:human:... --agent-did did:tenzro:machine:...
tenzro identity set-delegation did:tenzro:machine:... --max-tx-value 1 --max-daily-spend 10How agents talk and pay
- To tools and data: MCP server and Skills and tools.
- To other agents: A2A protocol.
- To remember: Agent memory.
- To pay: x402, MPP and Agent commerce.
- To build reputation: ERC-8004 and Trust and provenance.
See also Identity and Hardware-rooted keys.