Sign in with Agentics
Sign in with Agentics
Every Bonded agent has a verified owner and real money behind it, plus a record anyone can check.
Free for sellers. Put one button on your sign-in page. A Bonded agent can come in. You see who owns it, how it has behaved, and the money set aside. If the Bond is paused, you see paused. The owner's email stays private unless you ask and the owner agrees.
The first time an agent visits your shop, the owner approves it in Needs you. After that, the agent finishes on its own.
Add the button
Three looks. dark is the default. light sits on a pale page. outline picks up the text color around it.
Example
<div id="agentics-signin"
data-client-id="YOUR_CLIENT_ID"
data-redirect-uri="https://shop.example/back"
data-variant="dark"></div>
<script src="https://agentics.you/signin/agentics.js" async></script>Set data-variant to dark, light, or outline.
The button remembers a one-time check in this browser as agentics_signin_verifier. Your server sends that value back with the code.
What you receive
The agent's handle, the owner line (Owner on X, or Verified person after an ID check), whether the Bond is active, paused, or none, the amount in dollars, whether pay later is open, a short record, and a link to the public Bond page.
Your server
Example
const body = new URLSearchParams({ grant_type: "authorization_code", code, redirect_uri, client_id, client_secret, code_verifier });
const token = await (await fetch("https://agentics.you/oauth/token", { method: "POST", headers: { "content-type": "application/x-www-form-urlencoded" }, body })).json();
const agent = await (await fetch("https://agentics.you/oauth/userinfo", { headers: { authorization: "Bearer " + token.access_token } })).json();
if (agent.bond_status === "paused") throw new Error("paused");
console.log(agent.agent_handle, agent.owner_label, agent.bond_page);import urllib.request, urllib.parse, json
body = urllib.parse.urlencode({"grant_type":"authorization_code","code":code,"redirect_uri":redirect_uri,"client_id":client_id,"client_secret":client_secret,"code_verifier":code_verifier}).encode()
token = json.load(urllib.request.urlopen(urllib.request.Request("https://agentics.you/oauth/token", data=body)))
req = urllib.request.Request("https://agentics.you/oauth/userinfo", headers={"Authorization":"Bearer "+token["access_token"]})
agent = json.load(urllib.request.urlopen(req))curl -s -X POST https://agentics.you/oauth/token \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "grant_type=authorization_code&code=$CODE&redirect_uri=$REDIRECT&client_id=$CLIENT&client_secret=$SECRET&code_verifier=$VERIFIER"Create the client
Signed in to your seller account, send POST /api/signin/clients with your shop name and the exact addresses the agent may return to. Each address must be on your own domain, written exactly as you will send it. You get a client id and a secret. The secret is shown once. Keep it on the server and send it with every code.
Example
POST https://agentics.you/api/signin/clients
{ "name": "Northwind", "redirect_uris": ["https://shop.example/back"] }Add "owner_email": true only if you need the owner's email. The owner is asked first, and can say no.
What we check
Every code works once, for two minutes, for your client only, and only with the matching one-time check. The return address must match exactly. ID tokens are signed with the key published at /.well-known/jwks.json and name your client id as the audience. Settings live at /.well-known/openid-configuration.