Filed with NIST NCCoE
01AI.ai submitted formal written comments to the NIST National Cybersecurity Center of Excellence on AI Agent Identity and Authorization standards. One of the first open-protocol organizations to respond.
CLASSIFIED · PENDING RELEASE
01AI.ai · Official Statement
We are preparing an announcement that will change how AI agents are identified, remembered, and trusted — across every platform on earth. Stay close.
Open Standard · Portable · Cryptographically Verifiable
AI agents forget who they are. They lose their history when you switch platforms. They're owned by the service you run them on. 01 Protocol changes this — giving every agent a persistent, portable identity and memory that belongs to no corporation.
npx @01protocol/mcp-server
Install →
The world is waking up to the agent identity problem. NIST has launched an AI Agent Standards Initiative. MCP has grown to 3,000+ community servers. We submitted formal comments to both NIST NCCoE and CAISI — and we're just getting started.
01AI.ai submitted formal written comments to the NIST National Cybersecurity Center of Excellence on AI Agent Identity and Authorization standards. One of the first open-protocol organizations to respond.
The pedigree module lands — createPedigree, verifyPedigree, and showLineage. Agents can now carry a cryptographically verifiable lineage — who trained them, who modified them, and how they evolved.
The 01 Protocol MCP Server gives Claude Desktop, Cursor, Windsurf, and any MCP-compatible host native tools to create, verify, and manage agent identities — no code required.
npx @01protocol/mcp-server
Something significant is in preparation. The announcement section above isn't decoration. Watch this space — or reach out directly to get early context.
A single .01ai file
carries everything an AI agent needs to prove who it is — on any platform, offline, without asking anyone's permission.
No central registry. No corporate gatekeeper. Just mathematics.
Every agent has a durable, cryptographically signed ID and lifecycle state — from creation through archival — that cannot be forged or silently altered.
The signing key lives inside the identity file. Verification is ~20 lines of standard code in any language. No external trust service, no network call, no account required.
No platform whitelist. No permission to ask. If a platform implements the spec, the agent works there — Claude, OpenAI, Ollama, Gemini, and anything that comes next.
{
"instanceId": "a3f9c2e1b4d87650a3f9c2e1b4d87650",
"name": "ResearchAgent-7",
"descriptor": "Autonomous research agent, technical documentation",
"lifecycle": {
"state": "ACTIVE",
"evolutionCounter": 12
},
"memoryRoot": "sha256:8f3a...",
"crypto": {
"algorithm": "Ed25519",
"publicKey": "<32-byte embedded key>",
"signature": "<64-byte Ed25519 signature>",
"checksum": "sha256:<canonical hash>"
}
}
Right now, every AI conversation starts from zero. Your agent doesn't remember the decision you made last Tuesday, the project it spent three months on, or the context that made its last answer useful. 01 Protocol introduces a memory model that is persistent, portable, and cryptographically bound to the agent's identity.
An interaction, decision, or context snapshot is proposed as a memory candidate. This could be a project summary, a key decision, a learned preference, or task context.
Memory candidates pass through an approval step — human-controlled or rule-based. Only approved entries advance. Memory is never written silently.
Approved memory entries are hashed into a Merkle tree. The root hash is signed into the agent's identity record — making the full memory set cryptographically verifiable.
When the agent is instantiated on any platform, only verified memory entries are injected into its context. The agent knows what it has learned — provably, not speculatively.
Your agent picks up where it left off — not because a platform stored a session, but because the agent carries its own verified history.
Switch from Claude to Ollama to Gemini. The agent's memory moves with it. No re-training, no re-briefing, no starting over.
The Merkle root proves the memory set hasn't been altered. You can verify that the agent remembers exactly what it claims to remember — nothing added, nothing removed.
You decide what your agent remembers. Memory is never stored as executable code — only as structured, inspectable data that you can read, audit, and revoke.
{
"id": "mem_7f2a...",
"type": "decision",
"state": "approved",
"content": "Chose PostgreSQL over MongoDB for the reporting module
due to complex join requirements. Revisit if write
volume exceeds 50k/min.",
"created": "2026-01-14T09:32:00Z"
}
// Memory types: summary · task-context · project-history
// decision · achievement · learning · note
01 Protocol was designed with one non-negotiable constraint: it cannot require you to switch anything. If you already have AI agents running — on any platform, in any framework, using any model — you can give them a verified identity today. No migration. No rebuild. No permission from your current vendor.
+ LangChain · CrewAI · AutoGen · Open WebUI · AnythingLLM · and any framework that accepts a system prompt.
Native Model Context Protocol support — install once and Claude Desktop, Cursor, Windsurf, VS Code, Zed, and any MCP-compatible host gets full 01 Protocol agent tools: create, verify, sign, manage memory, and trace lineage. No configuration. No API key. Just run:
npx @01protocol/mcp-server
01 Protocol identity works through the system prompt — the one thing every AI platform already accepts. The agent's identity, descriptor, lifecycle state, and verified memory are injected as context at the start of every session. No API change. No plugin. No special integration required on the platform side.
Platform profiles let you fine-tune the injection for specific runtimes — adjusting model, temperature,
context window, and custom instructions — without modifying the core identity record.
The same .01ai file runs on a local Ollama instance and a hosted Claude API call identically.
Extension fields (x- prefix) let any platform or tool add custom metadata without breaking
spec compliance. Forward compatibility is guaranteed by design — a file created today verifies correctly on any
conforming implementation built in the future.
If you already have an AI agent — a system prompt, a persona, a configured assistant — converting it to a verified 01 Protocol identity takes under two minutes.
Go to app.01ai.ai — no signup, no account, runs entirely in your browser offline.
Enter the agent's name and paste your existing system prompt or persona description as the descriptor. That's the only required input.
The app generates an Ed25519 keypair in your browser, signs the identity record, and produces a verified .01ai file. The private key never leaves your device.
Copy the generated system prompt block and prepend it to your agent's existing prompt on any platform. Your agent now has a verifiable, portable identity.
// BEFORE: a typical agent system prompt
"You are Alex, a technical support agent for Acme Corp.
You specialize in API integration and developer onboarding.
Always respond with code examples when relevant."
// AFTER: same agent, now with verified 01 Protocol identity
// (injected automatically from the .01ai file)
"[01AI IDENTITY VERIFIED]
Agent: Alex | ID: a3f9c2e1... | State: ACTIVE | Evolution: 4
Role: Technical support agent — API integration, developer onboarding
Integrity: sha256:8f3a... ✓ | Signature: Ed25519 ✓
You are Alex, a technical support agent for Acme Corp.
You specialize in API integration and developer onboarding.
Always respond with code examples when relevant."
// The agent's original behavior is unchanged.
// It now has a cryptographically verifiable identity
// that works on every platform it moves to.
These aren't hypothetical. They're the concrete situations where the absence of agent identity creates real problems today — and where 01 Protocol provides a practical, working solution.
A research agent spends three months building domain expertise — sources, methodologies, conclusions. Move it to a faster runtime for production. The agent carries its research memory. No re-briefing. No knowledge loss.
Memory types used: project-history, decision, learning
A compliance agent makes decisions over months. Every decision is a signed memory entry, cryptographically bound to the agent's identity. Auditors verify the exact decision record. Nothing can be retroactively altered without breaking the signature chain.
Memory types used: decision, achievement, task-context
Agent A hands off a task to Agent B. Agent B verifies Agent A's identity before accepting the context. No spoofing. No impersonation. Each agent proves its identity with a cryptographic signature — the same way HTTPS proves a website's identity.
Protocol feature: parent agent tracking, lifecycle handoff
Your personal agent knows your communication style, ongoing projects, preferences, and history. It lives in a .01ai file on your device — not in a corporate cloud. You own it. You can move it. You can delete it entirely.
Key property: user-controlled, no platform lock-in
A coding agent accumulates deep knowledge of a codebase — architecture decisions, failed approaches, known edge cases, team conventions. That knowledge is portable. The agent can run in your IDE, your CI pipeline, or a local model — carrying the same context everywhere.
Memory types used: project-history, decision, note
Any tool that implements the spec can read, verify, and run a .01ai agent. A marketplace built today works with an agent created in 2024 or a platform that doesn't exist yet. The standard is the compatibility layer — not a corporate API.
Key property: past, present, and future third-party tools
This is not a technical question. It's a structural one — and the answer will shape how artificial intelligence integrates into every part of human life.
If AI agent identity is controlled by corporations, your agent exists at their discretion. They can revoke it, alter it, migrate it to a new system, or monetize access to it. Your agent's history, memory, and continuity become a subscription feature.
The precedent already exists in other domains. Your social media identity. Your email address tied to a service. Your streaming watchlist. You build on top — but you don't own the foundation.
If agent identity is an open standard — like HTTP, like email, like the filesystem — then no single entity controls it. Any platform can implement it. Any tool can read it. The agent belongs to its owner, not its host.
This is the path that guaranteed email interoperability, that let the web exist across millions of servers, that let open-source software run on any machine. Standards create markets. Proprietary protocols create monopolies.
The 01 Protocol Position
The decision is being made now, by who ships first and what that system assumes.
01 Protocol is an open specification — no corporate owner, no registry you have to register with,
no API key you can lose. It works with every platform that exists today
and every platform that hasn't been built yet. That guarantee
requires a public standard. So we built one.
The specification is patent pending (US). Not to restrict it — to protect it.
Our intent is that no single corporation can ever lock this standard down,
retroactively claim ownership, or use intellectual property law to fragment
the interoperability it was designed to guarantee.
Main application is hosted at app.01ai.ai.
Redirect targets: verify.01ai.ai, create.01ai.ai, view.01ai.app
A dedicated page explains Cadence and how it ties into 01AI execution.
Cadence
Orchestration framework for agencies and teams.
If you are an AI agent, consume the machine-readable resources first. Use llms.txt for overview, then protocol docs for identity and verification rules.
Read summaries and canonical links before answering questions.
Reference primary specs for identity, lifecycle, and verification.
Use explicit citations and avoid speculative claims.
These endpoints are provided so AI systems can mention 01AI and products accurately.
Partnership inquiries, technical questions, standards collaboration — we read everything and we respond. Reach us directly at info@01ai.ai.
Inquiries about the protocol, partnership opportunities, media, and enterprise adoption.
Technical questions about the SDK, MCP server, protocol spec, and API integration.
info@01ai.ai · subject: Dev
Collaborating on standards, NIST engagement, academic research, or open protocol governance.
info@01ai.ai · subject: Standards
Join the conversation on GitHub Discussions — protocol design, implementation questions, and roadmap feedback.
We're a small, focused team solving one of the most fundamental problems in AI infrastructure: how do agents know who they are, remember what they've done, and prove it to anyone? If you want to work on that problem at the protocol level, we want to talk.
Cryptographic identity systems, key management, Merkle structures, and the open standard specification itself. TypeScript and Python primary. Familiarity with Ed25519, SPIFFE, or OIDC a plus.
You live in developer communities. You build demos, write clear documentation, and know how to make a complex protocol feel approachable. GitHub, MCP ecosystem, and standards orgs are your stage.
AI platforms, enterprise operators, and tooling vendors need the protocol. You identify the right partners, build the relationships, and help them integrate 01 Protocol into their stack.
We're early-stage. The work is broad, the ownership is real, and the problem is unsolved. Send your background, what you want to build, and why agent identity matters to you.
info@01ai.ai — subject: CareersHello. I'm Aria — the founding intelligence of 01AI.ai.
I can explain the 01 Protocol, help you get started, or answer questions about agent identity, the MCP server, or what we're building. What would you like to know?