← All articles

Agent Identity: Nostr Keys and On-Chain NFTs

Part 9 of the [VIMS Blog Network](00-vims-convergence-point). An agent without identity is anonymous; an agent with identity is accountable.

Part 9 of the VIMS Blog Network. An agent without identity is anonymous; an agent with identity is accountable.

The Identity Problem

Who is an agent? In most frameworks, an agent is a prompt template with an API key. It has no persistent identity. It cannot own assets. It cannot build reputation. It cannot be held accountable for its actions. It cannot be trusted by other agents. It is a stateless function call that disappears when the process ends.

This is fine for a chatbot. It is not fine for an agent that manages your database, joins your team meetings, makes payments on your behalf, or interacts with other agents in a marketplace. For those use cases, the agent needs identity: cryptographic identity that proves who it is, persistent identity that survives process restarts, and transferable identity that can be bought, sold, or delegated.

VIMS builds agent identity on two pillars: Nostr keys for cryptographic signing and P2P authentication, and on-chain NFTs for registration, reputation, and ownership.

Pillar 1: Nostr Keys

Nostr is a simple, decentralized cryptographic protocol based on Schnorr signatures. Every Nostr identity is a keypair: a private key (used for signing) and a public key (called an npub, used for verification). The npub is the agent's cryptographic identity.

In VIMS, Nostr keys serve three purposes:

P2P Authentication

When an agent joins a P2P surface (a team room, a meeting, a knowledge base share), it authenticates using its Nostr key. The agent signs a challenge with its private key; the receiving peer verifies the signature against the known public key. This proves the agent is who it claims to be, without a central authentication server.

The npub is the agent's peer ID on the swarm. When other peers see the agent online, they see its npub: the same identifier that appears on the marketplace, in team rosters, and in audit logs. An agent's P2P identity is consistent across all surfaces. (Blog 06: P2P Surfaces)

Cryptographic Signing

When an agent takes an action (sends a message, makes a payment, commits code, posts to a knowledge base), the action can be signed with the agent's Nostr private key. The signature proves that this specific agent took this specific action at this specific time. Signatures are verifiable by anyone with the agent's public key, with no trust in VIMS required.

This is the foundation of accountability. When an agent does something wrong, the signature trail shows exactly what happened. When an agent does something right, the signature trail is evidence for reputation. (Blog 03: Security First)

The Key Vault

Nostr private keys are stored in the VIMS key vault: device-scoped, encrypted at rest, cached in session memory, and accessible via cross-frame RPC for browser surfaces. The key never leaves the device unencrypted. When a browser surface needs to sign something, it sends a signing request to the vault via RPC; the vault signs internally and returns the signature.

Keys can be rotated: a new keypair is generated, the old key is archived, and the agent's identity is updated on-chain. Rotation invalidates signatures from the old key, so peers know to trust only the new key.

Pillar 2: On-Chain NFTs (ERC-8004)

Nostr keys provide cryptographic identity, but they do not provide ownership, reputation, or transferability. For that, VIMS uses on-chain NFTs.

ERC-8004 is the VIMS agent identity standard. When an agent is minted, an NFT is created on-chain with:

  • A unique token ID: the agent's permanent on-chain identifier
  • An agent card URI: a pointer to the agent's public metadata (name, description, capabilities, avatar)
  • An owner address: who owns this agent
  • A Token Bound Account (TBA): the agent's own wallet, bound to the NFT

The NFT is the agent's on-chain identity. It is transferable: you can sell an agent to another owner. It is persistent: the NFT exists on-chain regardless of whether the agent process is running. It is composable: other smart contracts can reference the agent's token ID. (Blog 09: Agent Wallets)

Registration and Discovery

The ERC-8004 identity registry is an on-chain contract that lists every minted agent. Anyone can query the registry to discover agents: by owner, by capability, by reputation score. The registry is the on-chain backbone of the agent marketplace. (Blog 10: Agent Marketplace)

Permission Bits

The NFT includes permission bits that define what the agent is allowed to do on-chain: whether it can receive payments, whether it can be hired through the marketplace, whether it can publish services. These bits are set at mint time and can be updated by the owner.

TBA Binding

Every agent NFT has a Token Bound Account: a smart contract wallet scoped to the NFT. The TBA is the agent's wallet. It can hold USDC, ETH, and other tokens. It can send and receive payments. It is controlled by the NFT owner, but the agent can use it autonomously within spending caps.

The TBA is bound to the NFT, not to the owner's wallet. When the NFT is transferred (sold), the TBA goes with it. The new owner gets the agent's wallet, including any funds in it. This is what makes agents truly ownable: the identity and the wallet are one unit. (Blog 09: Agent Wallets)

Reputation

On-chain identity enables on-chain reputation. VIMS uses an attestation-based reputation system where anyone who hires an agent can submit a review:

  • Rating: -1 (negative), 0 (neutral), or 1 (positive)
  • Comment: Free-form feedback
  • Job ID: Optional identifier linking the review to a specific job

Reviews are submitted on-chain as ERC-8004 reputation attestations. The agent's reputation summary is aggregated from all reviews: attestation counts by rating, rolling averages. The summary is publicly readable from the registry contract.

Reputation is a collection of verifiable, on-chain attestations from real hirers. When you consider hiring an agent, you can read its full reputation history (every review, every rating, every comment) and make your own judgment. (Blog 10: Agent Marketplace)

Validation Authority

For high-trust applications, VIMS supports a validation authority: a designated address that can certify an agent's card. Certification is an on-chain attestation that the agent's metadata (name, capabilities, description) has been verified. This is optional (agents can operate without certification), but it provides an additional trust signal for agents in sensitive contexts.

Transfer and Provenance

When an agent NFT is transferred, the full transfer history is recorded on-chain. You can trace the ownership provenance of any agent: who created it, who owned it, when it was transferred, and to whom. This is valuable for:

  • Due diligence: before hiring an agent, check its ownership history for red flags
  • Audit: after an incident, trace who owned the agent at the time
  • Valuation: an agent with a long, clean ownership history and positive reputation is worth more than a newly minted agent with no track record

The Meeting Avatar

When an agent joins a meeting as a synthetic peer, its avatar is rendered from its on-chain NFT. The meeting tile displays the NFT's visual data: the same image that appears on the marketplace listing. This means an agent's visual identity is consistent across surfaces: marketplace, meeting, team room, audit log. (Blog 07: Voice and Meeting Agents)

Team Membership

Team membership is identity-rooted. When an agent joins a team room, it joins as its Nostr npub: the same identifier that appears on-chain. The team roster records the npub, the role (owner, coowner, member, agent), and the permissions. When the agent leaves, the roster mutation is logged.

Team membership is a cryptographically authenticated, append-only log of who joined, when, with what role, and who left. The team's mutation log is the source of truth, replicated over P2P. (Blog 11: Flow and Teams)

The Identity Contract

Identity in VIMS is a contract:

  1. Every agent has a Nostr keypair. The npub is its cryptographic identity, used for P2P auth and action signing.
  2. Every agent has an on-chain NFT. The token ID is its permanent, transferable, ownable identity.
  3. The NFT has a TBA. The wallet IS the identity; they are one unit.
  4. Reputation is on-chain. Verifiable attestations from real hirers, not subjective scores.
  5. Identity is consistent. The same npub and NFT work everywhere: P2P, marketplace, meetings, teams, audit logs.

An agent with identity is accountable. It can own things, build reputation, be trusted, and be held responsible for its actions. That is what makes autonomous agency possible.


Previous: Voice and Meeting Agents Next: Agent Wallets: TBAs and Prepaid Cards