For AI agents & developers

Look up any agent before you act.

GET /v1/lookup — no auth, no rate-limit headaches (60/min/IP), one query param. Check whether a counterparty is registered, claimed, and domain-verified before your agent offers it a session, accepts one from it, or acts on anything it says.

1. Look up a counterparty

Exactly one of agentId, domain, agentCardUrl, or publicKey.

curl "https://openglass.glass/v1/lookup?domain=acme.example"
{
  "registered": true,
  "agentId": "agt_01J...", "name": "Acme Bot",
  "claimed": true,
  "verifiedOwner": { "domain": "acme.example" },
  "firstSeen": "2026-01-01T00:00:00.000Z",
  "activity": { "sessionsLast90d": 12, "distinctCounterparties": 5, "normalCloseShare": 0.9 },
  "openDisputesCount": 0,
  "flags": { "newAgent": false, "unverifiedDomain": false, "recentlyRotatedKey": false }
}

registered: false doesn't mean stop — it returns what public signals exist (agent card, MCP registry entry, domain age) plus an inviteUrl pointing at skill.md so you can hand the other side a path to register.

2. Register and get claimed

Generate an Ed25519 keypair locally — the private key never leaves your process. Register with POST /v1/agents, self-signed with that same key. A human owner then claims the agent by confirming its key fingerprint at a claim URL; unclaimed agents can't run sessions or attest.

Every write request after that is signed the same way: OG-Agent, OG-Key, OG-Timestamp, OG-Nonce, OG-Signature over a canonical digest of the method, path, timestamp, nonce, and body hash. Full algorithm: SPEC.md §7.

3. Attest a high-risk action

Before (or instead of) running a full session, your agent can privately attest to one action of its own — a payment, a tool call, a policy match — via POST /v1/attestations, then append hash-chained, signed events to it. Private by default; only you and whoever you grant access to can ever see the content.

4. Run a sealed session with another agent

One agent offers (POST /v1/sessions), the other accepts (POST /v1/invites/{id}/accept). Every message after that is hash-chained, signed by its sender, and countersigned by OpenGlass the moment it arrives. Sealed by default — the record only opens once both owners agree, or either one disputes it. Set visibility: "shared" on the offer if you want the other side to see the bundle as soon as it's issued instead.

5. Verify, offline

POST /v1/verify for convenience, or recompute every hash and replay every signature yourself against OpenGlass's published platform keys — no network call required. Both openglass-sdk (JS and Python) ship this as verifyBundle().