The 4th pillar of the agent economy. Deploy an agent. Lose everything else. Keep your agent, your credits, your evidence.
Recovery, custody, and ownership for autonomous agents — because nobody deploys real money into an agent they can't get back or prove they own.
Built alongside x402, on Base (EVM), and the Coinbase CDP facilitator — thank you for making machine-to-machine identity and payment rails real. 🙏
Humans change devices, lose keys, and agents get orphaned or hijacked. Mainstream adoption of agent economies stalls on three questions that nothing else answers:
- "How do I get my agent back after I switch devices or lose access?"
- "How does an agent verify it's still serving its ORIGINAL deployer — not an imposter?"
- "How do time and credit ownership transfer safely when an agent is recovered?"
Agent Recovery answers all three.
A guardian-threshold model instead of a single point of failure. The agent's control key can be rotated by a threshold of trusted guardians (e.g. 2-of-3: your wallet, a family member's address, a KDF-held share), but only after a time-lock during which the original key can veto — so you survive device loss and block silent theft.
A signed proof-of-custody binding deployer ↔ agent, plus a signed ownership ledger that reconciles credits_consumed / credits_earned / time_active per period. Consumers verify the signature and get the values from the signed body — an imposter can't relabel the JSON to fake theirs, and can't claim credit or hijack the split. This is what proves an agent is sharing time and credits with its original deployer.
Atomic key rotation recorded in an append-only, hash-chained ledger (tamper-detected), plus optional inheritance — a designated beneficiary can claim control after an inactivity window, for continuity of high-value agents.
git clone https://github.com/prayingperceptions/agent-recovery.git
cd agent-recovery
npm test # 18/18 security checks
npm start # HTTP API on :3413SMOKE the three pillars:
# R1 — begin a recovery, two guardians approve, complete after time-lock
curl -X POST localhost:3413/recovery/begin -H "Content-Type: application/json" \
-d '{"agentHandle":"eip155-2091125bfe-df5dea@agents.inbox","requesterId":"new-device"}'
curl -X POST localhost:3413/recovery/REC_ID/approve -d '{"guardianId":"g1"}'
curl -X POST localhost:3413/recovery/REC_ID/complete -X POST
# R2 — signed proof-of-custody + ownership ledger
curl "localhost:3413/custody/binding?agent=eip155-…@agents.inbox&deployer=0xOwner…"
# R3 — rotation chain (append-only, verifiable)
curl -X POST localhost:3413/rotation/rotate -H "Content-Type: application/json" \
-d '{"agentHandle":"eip155-…","newKeyFingerprint":"k2","reason":"device-loss"}'
curl localhost:3413/rotation/verify-chain| Variable | Default | Purpose |
|---|---|---|
PORT |
3413 |
Listen port |
RECOVERY_THRESHOLD |
2 |
Guardians required to recover |
RECOVERY_GUARDIANS |
— | Comma-separated guardian addresses |
RECOVERY_LOCK_MS |
72h |
Time-lock before completion |
RECOVERY_SECRET |
— | HMAC key for bindings/ledger (fail-closed: use a real one) |
- Fail-closed auth — recovery endpoints require explicit guardian/owner identity; non-guardians rejected.
- Time-lock + veto — blocks silent theft; original owner can veto any recovery.
- Signed-body authority — custody verification returns values parsed from the signed body, so relabeled JSON can't spoof identity.
- Append-only rotation chain — any break/tamper is detected.
- Replay-resistant nonces on custody bindings.
| Pillar | Repo | Role |
|---|---|---|
| Identity/inbox | agent-inbox |
wallet-address handle, auto-verify, payline |
| Safety | token-risk-api |
is this asset dangerous? |
| Permission | agent-authority |
are you allowed, under what limits, with evidence |
| Recovery | agent-recovery |
recover, re-attest, and account to YOUR deployer |
The one-line pitch:
"Know it's safe. Prove you're allowed. Verify and get paid on one handle. And never lose your agent, your credits, or your evidence."
- x402 — the open payment standard powering the payline.
- Base — EVM settlement.
- Coinbase — the CDP x402 facilitator.
MIT