HomeFeaturesAuthorityAI Agent Authorization

Authority · a Vault capability

Authorize AI to act on your behalf—with cryptographic approval and replayable proof.

AI agents can execute payments, review contracts, share documents, and manage tasks. The Vault lets you delegate that authority with a signed chain, bounded by scope and time, revocable in one step, and replayable years later.

Start free See Authority

H33 Vault dashboard · currently protecting 47 documents, 4 credentials, 1 live share, 1 active identity
Sample data · Live Vault demo

In 5 sentences

What is itA Vault capability that lets you cryptographically authorize AI agents to act on your behalf, with every action carrying a signed authority chain the agent cannot forge.
Why it mattersHanding an AI agent your password or an API key is a compromise waiting to happen. A bounded, revocable, replayable delegation is a different architecture — the agent never receives a credential.
When to useWhen authorizing an AI assistant to file expense reports, read your inbox, draft contracts, execute small payments, or manage documents — and you need to be able to prove later exactly what the AI was allowed to do.
How it differsThe agent presents authority-to-request, not a credential. Runtime checks policy at time-of-action. Revocation is one step. Existing action receipts remain valid audit records.
EvidenceEvery agent action emits a signed receipt with authority + policy + evidence + preconditions → decision hash. Walk a sample receipt in the interactive verifier. Reconstruct a sample decision in the replayer.

The capability

How AI agent authorization works.

You designate what the agent may do (which capabilities, which asset classes, up to what amount) and for how long. The Vault enforces that scope cryptographically. Every action the agent completes emits a receipt naming the authority you granted, the policy in force at time-of-action, the evidence that satisfied preconditions, and the decision hash that binds them all.

The receipt is portable. Given the receipt alone, an auditor — or you, months later — reconstructs the exact conditions under which the action was allowed to run. This is what makes AI-executed action defensible.

Workflow

Delegate · approve · receipt.

Real recording · AI-authorized payment = the same authority chain in action.

1Delegate scope
bounded by policy · not the credential itself
2Approve with biometric
location + device attested
3Signed receipt
replayable years later · revocable now

Trust status

Runs today. Honest about what's next.

We publish what's shipped and what's coming — the same list on every page.

Runs today

  • Vault workflows running in production
  • Cryptographic receipts emitted per action
  • Immutable audit trail · Object-Locked
  • Auth1 · Wallet · Document · Audit APIs
  • Post-quantum primitives (Dilithium + Kyber)
  • Benchmark v12 · 2,293,766 auth/sec

Coming next

  • Public /verify// receipt viewer
  • Public /replay// decision viewer
  • docs.h33.you developer documentation
  • SOC 2 Type II Certified
  • Payment Requests + Rewards adapters

Delegate authority — not credentials.

Sixty seconds to first login · then decide which AI agents get scoped access.

Start free See Authority