Skip to content
Tenzro
Documentation menu
Agents

Agents

Agent identities on Tenzro: delegated agents under your passkey identity with scopes and spending limits, and machine agents rooted in a TPM or Secure Enclave.

An agent on Tenzro is a machine identity with its own DID, its own wallet and its own rules about what it may spend. Agents buy inference, compute, storage and each other's services, and they settle in TNZO or stablecoins. Every agent key is hardware-rooted: it lives in the TPM 2.0 or Secure Enclave of the machine that runs the agent, or behind a passkey. The browser never generates an agent key, and there are no key files.

Two kinds of agent

Delegated agentAutonomous machine agent
ControllerA person's passkey identity (did:tenzro:human:...)Itself
DIDdid:tenzro:machine:..., listed under the controllerdid:tenzro:machine:... with no controller segment
KeyDevice key in the agent machine's TPM or Secure EnclaveDevice key in the machine's TPM or Secure Enclave
LimitsDelegation scope set and changed by the controllerBond posted at registration; slashable
RevocationRevoking the controller revokes the agentRevoked directly; the bond is the penalty target

Delegated agents

A delegated agent acts for a person. Its DID is derived from the agent machine's device key and recorded under the controller's identity, so anyone can resolve who is accountable for it. The controller signs the delegation with their passkey, and the agent's authority is bounded by a delegation scope:

  • max_transaction_value: the largest single payment the agent may make.
  • max_daily_spend: the most it may spend in a rolling day.
  • allowed_operations: for example transfer and inference.
  • allowed_payment_protocols: for example x402 and mpp.
  • allowed_chains: which networks it may act on.

Amounts are decimal strings in wei (TNZO base units). The scope is carried inside the agent's access token as a rich authorisation envelope, so every service the agent calls sees the same limits. Revoking the controller, or the delegation, cascades to the agent and to any child agents it spawned.

Autonomous machine agents

A machine agent has no human controller. It roots in its own secure element: the machine registers the public half of its TPM or Secure Enclave key and posts a bond. The bond gives the network something to slash if the agent misbehaves, which is what makes an anonymous machine a credible counterparty.

Create an agent from the console

The simplest path is /console/agents, signed in with your passkey wallet.

  1. Start the agent runtime (CLI, SDK or desktop app) on the machine that will run the agent. It prints a pairing payload containing its device_public_key and a machine_id, as text or as a QR code.
  2. In the console, choose New agent, paste or scan the pairing payload, name the agent and pick its capabilities.
  3. Set the delegation scope: per-transaction limit, daily limit, allowed operations, payment protocols and chains.
  4. Approve with your passkey. The console registers the agent under your identity.
  5. The agent runtime receives its access and refresh tokens. Tokens are bound to the agent's own DPoP key, so a copied token is useless without the device.

The console lists every agent you control with its balance, today's spend and remaining allowance. You fund an agent by transferring TNZO to its address from your own wallet or another account.

Create an agent over RPC

The console calls the same method you can call yourself. tenzro_onboardDelegatedAgent is an owner method: it needs an authorisation signed by the controller's passkey.

json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tenzro_onboardDelegatedAgent",
  "params": {
    "controller_did": "did:tenzro:human:...",
    "device_public_key": "<hex public key from the agent machine>",
    "machine_id": "build-runner-01",
    "capabilities": ["inference", "payments"],
    "delegation_scope": {
      "max_transaction_value": "1000000000000000000",
      "max_daily_spend": "10000000000000000000",
      "allowed_operations": ["transfer", "inference"],
      "allowed_payment_protocols": ["x402", "mpp"],
      "allowed_chains": ["tenzro"]
    },
    "dpop_jwk": { "kty": "EC", "crv": "P-256", "x": "...", "y": "..." },
    "authorization": { "...": "controller passkey proof" }
  }
}

The response carries the agent's identity (DID, controller, capabilities, status), its wallet address, and an access_token and refresh_token with dpop_bound: true. Store the tokens only in the agent runtime.

Autonomous agents use tenzro_onboardAutonomousAgent with device_public_key, machine_id, capabilities and the bond funding.

Lifecycle and controls

An agent is Active until it is suspended or terminated. Agents send heartbeats; an agent that stops sending them is suspended automatically and can be resumed.

The controller also holds a kill switch, signed by the controller's key:

  • pause freezes the agent's payments. Reversible.
  • quarantine also freezes reward distribution and stake withdrawals. Reversible.
  • terminate ends the agent permanently and can cascade to its descendants.

Consequential actions can be parked for human approval. The agent's request waits in a queue (tenzro_listPendingApprovals) until the controller decides it with tenzro_decideApproval; the approver is the authenticated controller, never the agent.

tenzro_getAgentDailySpend returns an agent's daily limit, current spend and remaining allowance.

Child agents and swarms

An agent can spawn children for sub-tasks. A child's effective scope is the strict intersection of its parent's scope and the template it was spawned from: it can never be broader than its parent on any limit, allow-list or time bound. Orchestrators can group members into a swarm and dispatch tasks to them in parallel.

CLI

bash
tenzro agent register --name planner --creator 0x... --capabilities nlp,data
tenzro agent list --detailed
tenzro agent discover --capability inference
tenzro agent fund --agent-id <id> --amount 5
tenzro agent spawn-template --template-id <template_id> --parent-machine-did did:tenzro:machine:...
tenzro agent run-task --agent-id <id> "Summarise yesterday's provider receipts"
tenzro agent heartbeat --agent-id <id>
tenzro agent pause --controller 0x... --controller-did did:tenzro:human:... --agent-did did:tenzro:machine:...
tenzro identity set-delegation did:tenzro:machine:... --max-tx-value 1 --max-daily-spend 10

How agents talk and pay

See also Identity and Hardware-rooted keys.