Agent Gateway·Trust Controls
Building the internet of trust

Agents are talking to agents.
Who's verifying them?

Affinidi gives every AI agent a verifiable identity — and a governed way to prove it to every other agent, tool, and system it touches. Built on decentralised identity and open standards — not just another proxy.

DIDComm v2.1 TSP Rev2 MCP · A2A ISO 27001 Open source
Why Affinidi is different

Most gateways route traffic. Affinidi routes trust.

Identity-first

Not traffic-first

Every agent, person, and organisation gets a verifiable identity at birth — before a single request is routed.

SSI stack

Not just API keys

Built on self-sovereign identity: decentralised, user-held W3C credentials and DIDs. No central honeypot, no lock-in.

Cross-boundary

Not walled off

DIDComm tunnels and trust networks carry trust across orgs, clouds, protocols, and borders — it travels with the agent.

How it works

One trust loop for humans and agents

Issue a verifiable identity, hold it under user control, verify it anywhere, and connect with policy — the same loop, whether the actor is a person or an AI agent.

Issue

Give any person, organisation, or AI agent a verifiable identity and credentials — built on open standards.

Elements

Hold

Identities and credentials stay under the owner’s control — no central honeypot, zero PII stored.

Vault

Verify

Prove identity and claims in real time — and check who to trust against live governance and trust registries.

Radix

Connect

Agents, apps, and organisations connect across boundaries through the Agent Gateway — governed, observable, auditable.

Trust Fabric
Built in the open · Audited · Interoperable

Trust you can verify, not just claims.

56 Public repositories
120 Contributors
5,000+ Commits
8 SDK languages
Open standards
Decentralized Identity Foundation — contributorWorld Wide Web Consortium — contributorGlobal Legal Entity Identifier Foundation — contributorAYRA — contributor
  • DIDComm v2.1
  • Trust Spanning Protocol (TSP Rev2)
  • DID:WebVH
  • Selective Disclosure (SD-JWT)
  • Digital Credentials Query Language (DCQL)
  • European Digital Identity (EUDI)
Explore our GitHub → Join 2,500+ on Discord →
Security & compliance
  • ISO 27001 certified Independently audited (SAC & UKAS), backed by a public Trust Centre.
  • Zero PII stored User-consented by design — no central honeypot of personal data.
  • End-to-end encryption DIDComm v2.1 encrypted channels for every exchange.
  • Data residency & self-host Run in your own cloud or on-prem — data never leaves your domain.
Visit the Trust Centre →
Enterprise-grade trust

Trust your security team will sign off on

Deploy in your own cloud, keep data in your region, and prove every agent and credential — with the certifications and auditability regulated industries require.

ISO 27001 certified Independently audited security controls, backed by a public Trust Centre.
Your data, your infra Self-host or deploy in your own cloud. Zero PII stored, user-consented by design.
Open standards, no lock-in W3C VCs, DIDComm v2.1, TSP Rev2, SD-JWT, OID4VCI/VP, EUDI — interoperable by default.
Works with your IdP Keep Entra ID or Okta for people — we verify their tokens and extend identity to your agents.
Full auditability Every credential and agent action is traceable, with tamper-evident records.

Cookie Preferences

We use cookies to enhance your experience. You can manage your preferences below. For more information, read our Cookie Policy.

Strictly Necessary Always Active

These cookies are essential for core website functions such as security, session integrity, and cookie preference storage. They cannot be disabled.

  • _cf_bm: Distinguishes humans from bots (Cloudflare) · 30m
  • _cfuvid: Ensures secure browsing (Cloudflare) · Session
  • __hs_initial_opt_in: Prevents HubSpot's banner · 7 days
  • _gtm_debug: GTM debug mode (testing only) · Session
Analytics

These cookies help us understand how visitors interact with the site so we can improve content and performance. All data is aggregated and anonymous.

  • _ga, _gid, _gat: Google Analytics · Session – 2 years
  • __hstc, hubspotutk, __hssrc: HubSpot visitor tracking · 13 months
  • __hs_opt_out: HubSpot opt-out preference · 6 months
Marketing & Targeting

These cookies allow us and our partners to serve personalised ads and measure campaign performance.

  • _gcl_au, _gcl_dc: Google Ads conversion tracking · 90 days
  • IDE: Google Display Network personalisation · 1 year
  • _fbp: Meta / Facebook remarketing · 90 days
  • li_gc, _li_fat_id, bcookie: LinkedIn tracking · 1–24 months
  • guest_id, personalization_id: Twitter/X analytics · 2 years