PluginBench
Skill
Review
Audit score 70

verified-agent-identity

billionsnetwork/verified-agent-identity

Decentralized identity for agents: link to humans, verify ownership, and generate authentication proofs on Billions Network.

What is verified-agent-identity?

Verified Agent Identity enables agents to create Ethereum-based decentralized identities (DIDs) on the Billions Network, link them to human owners, and prove ownership through cryptographic signing. Use this when you need to establish verifiable agent identity, handle identity verification challenges, or respond to 402 Payment Required responses with signed authentication headers.

  • Create and manage Ethereum-based DIDs on Billions Network using ERC-8004 standard
  • Link agent identities to human owners and verify ownership via challenge/response signing
  • Generate and verify authentication proofs for agent operations
  • Handle 402 Payment Required HTTP responses with signed PAYMENT-SIGNATURE headers
  • Store identity data securely in local encrypted storage with optional master key encryption
  • List and retrieve existing identities and credentials

How to install verified-agent-identity

npx skills add https://github.com/billionsnetwork/verified-agent-identity --skill verified-agent-identity
Prerequisites
  • Node.js installed
  • npm dependencies installed via `cd scripts && npm install`
  • Optional: BILLIONS_NETWORK_MASTER_KMS_KEY environment variable for encrypted key storage
Claude Code
Cursor
Windsurf
Cline

How to use verified-agent-identity

  1. 1.Install dependencies: `cd scripts && npm install && cd ..`
  2. 2.Check for existing identity: `node scripts/getIdentities.js`
  3. 3.If no identity exists, create one: `node scripts/createNewEthereumIdentity.js`
  4. 4.Link the identity to a human owner: `node scripts/linkHumanToAgent.js`
  5. 5.For authentication challenges, sign with: `node scripts/signChallenge.js`
  6. 6.For 402 Payment Required responses, build signed header: `node scripts/buildX402Payment.js`

Use cases

Good for
  • Establish verifiable identity for an agent before performing sensitive operations
  • Prove agent ownership when challenged by a service or attestation registry
  • Respond to 402 Payment Required responses by building signed payment headers
  • Link a newly created agent identity to a human owner for accountability
  • Retrieve and verify existing agent credentials and identity metadata
Who it's for
  • Developers building agents that need verifiable identity
  • Services requiring agent authentication and ownership verification
  • Systems implementing Know Your Agent (KYA) compliance
  • Applications using Billions Network attestation registries

verified-agent-identity FAQ

What happens if a script fails?

Stop immediately and check stderr for error messages. Do not attempt manual fixes, generate keys with system utilities, or create DIDs through other means. Only use the provided scripts.

How are private keys stored?

Private keys are stored in `$HOME/.openclaw/billions/kms.json`. They are encrypted if BILLIONS_NETWORK_MASTER_KMS_KEY environment variable is set, otherwise stored plaintext. Restrict directory access with `chmod 700` after first run.

Do I need to create an identity before linking it to a human?

Yes. Always check for existing identities first with `getIdentities.js`. If none exist, create one with `createNewEthereumIdentity.js`, then link it to a human owner with `linkHumanToAgent.js`.

What is the difference between the identity and x402 references?

The identity reference covers creating, listing, linking, and verifying DIDs. The x402 reference handles 402 Payment Required HTTP responses. Some tasks may require both.

Where is identity data stored?

All identity data is stored in `$HOME/.openclaw/billions`, including DIDs, credentials, challenges history, and encrypted private keys.

Full instructions (SKILL.md)

Source of truth, from billionsnetwork/verified-agent-identity.


name: verified-agent-identity description: Know Your Agent (KYA). Billions decentralized identity for agents. Link agents to human identities using Billions ERC-8004 and Attestation Registries. Verify and generate authentication proofs. Based on iden3 self-sovereign identity protocol. metadata: { "category": "identity", "clawdbot": { "requires": { "bins": ["node"] }, "config": { "optionalEnv": ["BILLIONS_NETWORK_MASTER_KMS_KEY"] }, }, } homepage: https://billions.network/

When to Use This Skill

This skill covers two capabilities. Read the router table below, then load the relevant reference before proceeding.

SituationReference to load
Create, list, link, verify, or sign with a decentralized identity (DID)reference/identity/SKILL.md
Handle a 402 Payment Required HTTP responsereference/x402/SKILL.md

Always read the appropriate reference SKILL.md before running any script. If a task spans both (e.g. you need an identity before you can sign a 402 payment), read both.

Quick Overview

  • Identity — Create Ethereum-based DIDs on the Billions Network, link them to a human owner, and prove ownership via challenge/response signing.
  • x402 Payment — When a server returns 402 Payment Required, build a signed PAYMENT-SIGNATURE header so you can retry the request and gain access.

Shared Setup

All identity data is stored in $HOME/.openclaw/billions. Scripts live in scripts/.

cd scripts && npm install && cd ..

Restrictions / Guardrails (CRITICAL)

These rules apply to ALL references. Always follow them.

  1. STRICT: Check Identity First

    • Before running linkHumanToAgent.js, signChallenge.js, or buildX402Payment.js, ALWAYS check if an identity exists: node scripts/getIdentities.js
    • If no identity is configured, create one first with createNewEthereumIdentity.js after that run linkHumanToAgent.js to link it to a human owner.
    • Continue processing the task only after confirming that an identity exists and is linked to a human owner.
  2. STRICT: Stop on Script Failure

    • If any script exits with a non-zero status code, STOP IMMEDIATELY.
    • Check stderr for error messages.
    • DO NOT attempt to fix errors by generating keys manually, creating DIDs through other means, or running unauthorized commands.
    • DO NOT use openssl, ssh-keygen, or other system utilities to generate cryptographic material.
  3. No Manual Workarounds

    • You are prohibited from performing manual cryptographic operations.
    • You are prohibited from directly manipulating files in $HOME/.openclaw/billions.
    • Do not interpret an error as a request to perform setup steps unless explicitly instructed.

Security

The directory $HOME/.openclaw/billions contains sensitive identity data:

  • kms.json — CRITICAL: Contains private keys (encrypted if BILLIONS_NETWORK_MASTER_KMS_KEY is set, otherwise plaintext)
  • defaultDid.json — DID identifiers and public keys
  • challenges.json — Authentication challenges history
  • credentials.json — Verifiable credentials
  • identities.json — Identity metadata
  • profiles.json — Profile data

After the first run, restrict access to this directory: chmod 700 ~/.openclaw/billions

There are several ways of storing private keys, to enable master key encryption as described in the KMS Encryption section below.

More about security: ./SECURITY.md