For agents

Give an agent reach. Do not give it the account.

Delegation is the whole point of an agent and the whole risk of one. human.tech separates the two: the person keeps custody and keeps deciding, and the agent operates inside limits that are enforced by the protocol rather than promised by a dashboard.

2,184,101Verified accounts
51,557,974Credentials issued
438,809Attestation transactions on-chain
150+Ecosystem partners

Verified accounts and credentials as of 2026-06-10. On-chain figures as of 2026-07-31.

Built on open standards
ICAO·W3C Verifiable Credentials·eIDAS 2.0·FATF Travel Rule
Read the third-party audits
The fourth question

Who may act on their behalf?

Wallets a person holds themselves, and agents that operate inside limits a human set in advance. Every action carries the authority it was granted, so a delegate can be given real reach without being handed the account.Wallets the user holds, agents that cannot exceed what a human approved.

WaaP

What it may spend

Wallet as a Protocol is custody the person keeps. An agent transacts through it without the wallet ever handing over the ability to move funds on its own account, which is the thing a hosted wallet service gives away by design.

Wallet as a Protocol →
TAP

What it may reach

The Tool Authorization Protocol sits in front of the credentials and tools an agent calls. The agent presents a key of its own and never sees the secret behind the call, so revoking its reach is one decision rather than a rotation across every service it touched.

Tool Authorization Protocol →
The custody model

A limit is only real if nobody can quietly lift it.

Most agent wallets are a hosted wallet with a policy layer bolted on. The keys sit on somebody's server, and the limit is a row in their database. WaaP starts from self-custody instead, which is why the constraint survives a compromise of the thing enforcing it.

Q4 2025WaaP publicly launched at WalletCon Argentina.
Mar 2026Agentic WaaP launched, extending protected self-custody to autonomous callers.
  • 01

    A protocol, not a service

    A wallet-as-a-service charges a SaaS fee and locks the wallet to the app that issued it. WaaP is free and universal, so the user keeps one wallet across everything rather than one per product.

    Protocol, not service →
  • 02

    No custodial key server

    There is no server holding the keys that could be compelled, breached, or quietly changed. That is the difference between a limit that is enforced and a limit that is a setting in somebody else’s dashboard.

    How the split works →
  • 03

    The frontend is not trusted

    Wallet-as-a-service models trust the frontend and an iframe with the ability to spend user funds. WaaP does not, which is what makes an autonomous caller a safe thing to attach to it at all.

    Preventing blind signing →
  • 04

    EIP-1193 compliant

    A drop-in replacement for MetaMask or any EVM wallet provider. Your agent code keeps the interface it already targets, so adopting this is an integration rather than a rewrite.

    WaaP for agents →
Upstream of all of it

Every delegation traces back to a person.

Authority has to come from somewhere. If the principal behind an agent is itself an unverified account, the limits are arithmetic on top of nothing, and one operator can field as many agents as they can afford to run. Human Passport establishes that a real, unique person stands behind the delegation, and the authority an agent carries is bounded by what that person granted.

Tell us what your agent needs to be able to do.

Move funds, call a paid API, hold a credential, act while its principal is asleep. Bring the capability you want to delegate and we will show you where the limit sits and who is able to move it.

Holonym Foundation, a Delaware public benefit corporation