An AI agent asks to spend EUR 49. Limiq decides whether it can - before money moves.
Limiq is a reference identity and permission layer for autonomous agents. It turns a signed action, a short-lived capability and the current policy into one deterministic answer: ALLOW or DENY.
It is intentionally a focused v0.x system, not an IAM suite.
The reference stack boots PostgreSQL, Redis, the API and a purchase target, then runs one allowed purchase and one denied purchase:
docker compose -f examples/reference-implementation/docker-compose.yml \
up --build --abort-on-container-exit agent-demoExpected business result:
ALLOW EUR 49 -> purchase executed
DENY EUR 149 -> SPEND_LIMIT_EXCEEDED
sequenceDiagram
participant A as Agent
participant L as Limiq
participant T as Target service
A->>L: Request scoped capability
L-->>A: Signed, short-lived JWT
A->>T: Signed action + capability
T->>L: Verify action
L->>L: Identity + scope + spend + rate + revocation
L-->>T: ALLOW / DENY + audit event
The security boundary is deliberately small:
| Concern | Implementation |
|---|---|
| Tenant access | Workspace ID + HMAC-derived workspace key |
| Agent identity | Ed25519 public keys and signed canonical envelopes |
| Delegation | Short-lived EdDSA capability JWTs bound to agent, workspace and target |
| Money | Exact Decimal comparisons, currency binding, policy and token limits |
| Revocation | Agent and capability revocation with fail-closed Redis rate limiting |
| Evidence | Append-only audit events linked by a per-workspace hash chain |
Prerequisites: Python 3.12+, Docker and make.
cp apps/api/.env.example apps/api/.env
make generate-dev-keypair # paste the two printed values into apps/api/.env
# set LIMIQ_WORKSPACE_BOOTSTRAP_TOKEN and LIMIQ_WORKSPACE_AUTH_SECRET in apps/api/.env
docker compose up -d
make install
make migrate-up
make devThen open Swagger UI. POST /workspaces returns the workspace API key once; send it as X-Workspace-Key with X-Workspace-Id on tenant routes.
apps/api- FastAPI verification core, policies, capabilities, revocation and audit integrity.packages/sdk-jsandpackages/sdk-python- cross-language canonical signing and API clients.apps/playgroundandexamples- an operator playground plus runnable Express/FastAPI integrations.
Useful checks:
make lint
make test
make verify-all
pnpm --filter @limiq/sdk-js test
pnpm --filter playground buildThe same canonical JSON vectors are exercised in Python and TypeScript so signatures do not depend on language-specific serialization.
The core flow is intentionally linear:
- Bootstrap a workspace.
- Register an agent public key.
- Create and bind a policy.
- Issue a scoped capability.
- Verify the signed action.
- Query or export the audit trail.
{
"decision": "DENY",
"reason_code": "SPEND_LIMIT_EXCEEDED",
"audit_event_id": "b9f..."
}Docs: API guide · architecture · threat model · why Limiq
Limiq is a production-minded reference implementation, not a hosted identity provider. It does not include human SSO, RBAC administration, key rotation workflows or multi-region deployment. The current workspace key model is suitable for controlled service-to-service environments; a public multi-user product should put an IdP and managed secret rotation in front of it.
Apache-2.0 - see LICENSE.