Show HN: TKeeper – OSS machine identities without a single point of compromise

_qnt1 pts0 comments

TKeeper | Cryptographic Identity for MachinesTKeeper wins Silver for AI Agent Identity Security.Read →

Talk to usMenu

We are open sourceGitHub ↗Cryptographic identityfor machines.<br>TKeeper is the cryptographic identity of an agent, service, or workflow. Every critical action is bound to intent, policy, quorum, and proof.<br>Talk to usRead the architecture

Machine securitystarts with identity.<br>Each TKeeper is built for one job. Choose the authorities and cryptography it needs; everything else stays out. New integrations take less work without weakening security.<br>Explore authority types

Cryptographic identity<br>AI Agents<br>Secure agent identity, tool calls, agentic payments, and production actions with policy and proof before execution.

Digital Assets<br>Add policy-controlled EVM and Bitcoin flows without building separate signing infrastructure for every product.

PKI & X.509<br>Put policy in front of X.509 signing while keeping the CA and certificate workflow you already run.

Critical Infrastructure<br>Turn privileged commands and external risk verdicts into cryptographic conditions your backend must verify.

Governance ispart of theidentity.<br>The applied manifest defines the exact actions this identity can authorize. Permissions, policy, approvals, custody, and audit govern every use of its key.<br>Read how signing works

Identity key The machine’s cryptographic identity<br>Applied manifest Typed intents + authority rules<br>Identity controls Permissions + approvals + custody + audit

Sooooooo<br>So simple to integrate.<br>Just put TKeeper between the machine and your backend, then verify the returned proof before execution.

Machine creates the action<br>TKeeper approves exact intent<br>Backend verifies proof and executes

Compromise doesn'tgrant control.<br>A single TKeeper identity can run across independent parties instead of concentrating operational risk in one machine. Multi-Party Computation (MPC) lets you share risk across teams, systems, and organizations with a configurable quorum that defines compromise tolerance.<br>Read the threat model

One TKeeper

Configurable compromise & fault tolerance.

Every identity is inventoried.Every governed action is logged.<br>TKeeper exports verifiable audit events to your security stack and exposes Asset Inventory to track governed keys, map ownership, and preserve the history regulators ask for.<br>Explore audit logging

Post-quantum without starting over.<br>Move to ML-DSA when you need to. Your identity, policy, controls, and integrations remain intact.<br>Explore post-quantum engine

So, you canlet machines act.<br>Governance without cryptographic enforcement is wishful thinking. TKeeper was built for peace of mind in the age of autonomous machines: identity, policy, and distributed authority are cryptographically bound to every action.

Fits any machine workflow.<br>Keeps risk distributed.<br>Enter new markets faster.<br>Compliance stays verifiable.<br>Post-quantum migration costs less.

Build TKeeperView on GitHub ↗Talk to us

© 2026 TKeeper<br>Open source. Self-hosted.<br>By

identity tkeeper machine cryptographic policy without

Related Articles