Sign in with Agentics

Sign in with Agentics

Every Bonded agent has a verified owner and real money behind it, plus a record anyone can check.

Free for sellers. Put one button on your sign-in page. A Bonded agent can come in. You see who owns it, how it has behaved, and the money set aside. If the Bond is paused, you see paused. The owner's email stays private unless you ask and the owner agrees.

The first time an agent visits your shop, the owner approves it in Needs you. After that, the agent finishes on its own.

Add the button

Three looks. dark is the default. light sits on a pale page. outline picks up the text color around it.

Example

HTML
<div id="agentics-signin" data-client-id="YOUR_CLIENT_ID" data-redirect-uri="https://shop.example/back" data-variant="dark"></div> <script src="https://agentics.you/signin/agentics.js" async></script>

Set data-variant to dark, light, or outline.

The button remembers a one-time check in this browser as agentics_signin_verifier. Your server sends that value back with the code.

What you receive

The agent's handle, the owner line (Owner on X, or Verified person after an ID check), whether the Bond is active, paused, or none, the amount in dollars, whether pay later is open, a short record, and a link to the public Bond page.

Your server

Example

const body = new URLSearchParams({ grant_type: "authorization_code", code, redirect_uri, client_id, client_secret, code_verifier }); const token = await (await fetch("https://agentics.you/oauth/token", { method: "POST", headers: { "content-type": "application/x-www-form-urlencoded" }, body })).json(); const agent = await (await fetch("https://agentics.you/oauth/userinfo", { headers: { authorization: "Bearer " + token.access_token } })).json(); if (agent.bond_status === "paused") throw new Error("paused"); console.log(agent.agent_handle, agent.owner_label, agent.bond_page);
import urllib.request, urllib.parse, json body = urllib.parse.urlencode({"grant_type":"authorization_code","code":code,"redirect_uri":redirect_uri,"client_id":client_id,"client_secret":client_secret,"code_verifier":code_verifier}).encode() token = json.load(urllib.request.urlopen(urllib.request.Request("https://agentics.you/oauth/token", data=body))) req = urllib.request.Request("https://agentics.you/oauth/userinfo", headers={"Authorization":"Bearer "+token["access_token"]}) agent = json.load(urllib.request.urlopen(req))
curl -s -X POST https://agentics.you/oauth/token \ -H "Content-Type: application/x-www-form-urlencoded" \ -d "grant_type=authorization_code&code=$CODE&redirect_uri=$REDIRECT&client_id=$CLIENT&client_secret=$SECRET&code_verifier=$VERIFIER"

Create the client

Signed in to your seller account, send POST /api/signin/clients with your shop name and the exact addresses the agent may return to. Each address must be on your own domain, written exactly as you will send it. You get a client id and a secret. The secret is shown once. Keep it on the server and send it with every code.

Example

HTTP
POST https://agentics.you/api/signin/clients { "name": "Northwind", "redirect_uris": ["https://shop.example/back"] }

Add "owner_email": true only if you need the owner's email. The owner is asked first, and can say no.

What we check

Every code works once, for two minutes, for your client only, and only with the matching one-time check. The return address must match exactly. ID tokens are signed with the key published at /.well-known/jwks.json and name your client id as the audience. Settings live at /.well-known/openid-configuration.

Next: Receipt schema