{"$schema":"https://intyga.com/.well-known/intyga-agent.json","version":"1","name":"INTYGA","category":"Privileged runtime authorization","summary":"Holds an irreversible action until a named human approves those exact parameters with a hardware-backed signature, and gives the executing code a receipt it verifies offline.","integration":{"mcp":{"transport":"Streamable HTTP","endpoint":"https://api.intyga.com/mcp","description":"Agents connect here. A tool call that maps to a gated action is held until a human approves it; the agent receives a verifiable receipt, not a boolean."},"rest":{"endpoint":"/authorize","auth":"Human API key, subject type humanDid","description":"For humans, CLIs, CI jobs, and backend services. The same primitive as the agent path — the MCP surface is one adapter over it."},"verification":{"description":"Verification is the part that must not require us. Re-derive the canonical payload from the parameters you are about to execute and check the signature against the approver's public key. No INTYGA secret, no network call, no account.","packages":["@intyga/verify (TypeScript)","intyga-sdk (Python)","Go","Rust","Java"]}},"behaviour":{"failClosed":true,"failClosedNote":"If INTYGA is unreachable, the SDK surfaces an error or an expired status and never an approval. An outage delays a gated action; it does not release it.","offlineApproval":{"supported":true,"note":"The relying party builds the challenge itself, approvers sign it on a disconnected device, and the relying party verifies the result with the ordinary procedure. Validity windows are capped at 60 minutes."},"preSignedApprovals":{"supported":false,"note":"Deliberately not offered. A proof at rest is a bearer capability that cannot be revoked and attests to a judgment about a hypothetical rather than the incident in progress."},"autoApprovedReceipts":{"note":"Receipts with sigAlg AUTO_APPROVED carry no human signature. Verifiers refuse them by default. Do not treat one as an approval."}},"evaluation":{"name":"14-Day Runtime Assessment","url":"https://www.intyga.com/assessment","blocksAnything":false,"note":"Observes every privileged action for 14 days without gating any of it, then reports the control gaps. Observations are not approvals."},"specifications":{"div":"Deterministic Intent Verification — signed intent, proof envelope, offline verification procedure.","dewp":"Deterministic Evidence & Witness Protocol — domain-separated Merkle hashing, gapless per-tenant sequencing, offline inclusion proofs.","published":false,"url":null,"note":"The normative specifications are written but withheld until production launch. The whitepaper and developer reference describe the same mechanisms without normative language."},"endpoints":{"site":"https://www.intyga.com","console":"https://app.intyga.com","docs":"https://www.intyga.com/docs","pricingData":"https://www.intyga.com/pricing-data.json","citations":"https://www.intyga.com/citations.json","llmsTxt":"https://www.intyga.com/llms.txt","agentSetup":"https://www.intyga.com/agent-setup.txt"},"contact":{"general":"hello@intyga.com","security":"security@intyga.com"}}