Highflame ZeroID: Autonomous Agent Identity Management System (AAIMS)
-
Updated
Sep 15, 2026 - Go
Highflame ZeroID: Autonomous Agent Identity Management System (AAIMS)
Zero trust LLM gateway. OpenAI-compatible proxy with semantic routing and load balancing across OpenAI, Anthropic, Ollama, vLLM, and any compatible backend. Identity-based access, virtual API keys, and end-to-end encryption via OpenZiti
The IAM layer for AI agents: cryptographic identity, capability authorization, and audit trails for non-human identities. Open source.
Zero trust gateway for MCP servers. Aggregate, filter, and securely access MCP tools from anywhere without VPNs, open ports, or exposed endpoints. Built on OpenZiti, zrok, and Agora with cryptographic identity, mTLS, per-client isolation, and tool-level permission control.
Open-source AI agent identity & compliance platform — X.509 certificates via AWS KMS, behavioral risk scoring, auto-revocation, and MiCA / EU AI Act audit trails.
TypeScript SDK for AI agent identity & compliance — issue X.509 certificates, verify scope, and enforce them with drop-in middleware. Apache-2.0.
Deterministic authorization + tamper-evident audit for AI agents, humans, and workloads — one principal type, safety invariants machine-checked by an SMT solver (cvc5), every decision independently verifiable offline. Pure Rust.
NHInsight — Open-source security tool to find risky non-human identities, tokens, and CI/CD access paths across AWS, Azure, GCP, GitHub, Kubernetes, and GitHub Actions.
Voluntary behavioral baseline + conformance testing for transparent AI voice agents in healthcare. Open proposal with cryptographic authorization layer.
Each agent run gets its own short-lived attested credential. A stolen token is not enough.
Read-only NHI risk scanner (GitHub Actions, K8s, IaC). Offline-first. No telemetry
Passport & visa system for AI agent credentials. Detect, classify, and govern API keys, tokens, and secrets across MCP, OpenAI, Anthropic, LangChain, and more. Encrypted vault, policy engine, audit trails, delegation chains. Drop-in MCP server replaces plaintext credential storage.
AI agent credential broker — temporary, task-scoped tokens with automatic revocation. Free for internal use
Thin API gateway that lets AI agents call SaaS APIs on behalf of users. Agents never see tokens.
Identity registry and lifecycle management for fleets of AI agents. Zero-dependency TypeScript IAM: cryptographic agent identity (Ed25519), declared capabilities with fail-closed authorization, an enforced lifecycle (provision, activate, suspend, revoke, expire, archive), A2A Signed Agent Cards, and a hash-chained audit trail.
Non-Human Identity governance framework — Entra ID sandbox · Service Principals · Workload Federation · AI Agent Identity
Python SDK for AgentWrit — AI agent credential broker. Temporary, task-scoped tokens with automatic revocation. pip install agentwrit
NHICanvas - Discover and Govern Non-Human Identities
Identity & compliance middleware for AI agent frameworks — Express, Fastify & Next.js gateways plus LangChain, Mastra & Vercel AI SDK tools.
To associate your repository with the non-human-identity topic, visit your repo's landing page and select "manage topics."