OpenAGP is an open, vendor-neutral protocol designed to standardize governance and auditing for AI agents across multiple vendors. It addresses the challenge enterprises face when managing hundreds of AI agents from different providers, each with their own audit formats, policy enforcement mechanisms, and identity models. By defining a unified approach, OpenAGP enables organizations to enforce a single policy and maintain a verifiable audit trail regardless of the agent vendor, much like how SAML standardized identity management.
At its core, OpenAGP specifies a set of signed, schema-defined messages exchanged between a customer's governance plane and an agent vendor. These messages allow for consistent policy enforcement and the creation of a tamper-evident, hash-chained ledger of agent actions. Events and policies are signed using Ed25519 and canonicalized with RFC 8785 (JCS), ensuring that they are independently verifiable. The protocol supports three main flows—events, policy, and decision—corresponding to different levels of vendor conformance (L1, L2, L3). At the basic level, vendors emit signed canonical events for passive observability. Higher levels add support for accepting and applying customer policies and real-time decision callbacks, enabling human-in-the-loop governance for high-stakes actions.
OpenAGP is intended for a range of stakeholders. Vendors can quickly implement the protocol using reference SDKs and prove conformance with a dedicated suite. Customers benefit from authoring governance policies once and having them enforced across all conformant vendors. Auditors gain access to standardized, signed artifacts that can be verified independently, without having to trust any intermediary. Contributors are invited to participate in shaping the standard through an open RFC process, with free SDKs and no contributor license agreement required.
The protocol is available as an open specification, with reference implementations in Python, TypeScript, and Go. 0 for SDKs, and CC0 for registry data. OpenAGP is maintained by its community and aims for multi-stakeholder governance as it matures.
OpenAGP is a Frameworks & SDKs project. It focuses on standardizing governance, policy enforcement, and auditability for AI agents across multiple vendors. OpenAGP is an open-source project aimed at AI infrastructure developers. The project is open source (Apache-2.0). OpenAGP is available on the web, the command line, and API, and it can be self-hosted.
Behind OpenAGP is OpenAGP community, and it first shipped in 2026. Development happens publicly on GitHub with 9 commits in the last 90 days. Key capabilities include open specification, agent policy enforcement, and audit trail.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Closest matches by what these projects do