Live data from Hacker News

AC2 Protocol: The missing security layer for AI agents

ac2protocol.org

1–10 of 20 posts

Re: AC2 Protocol: The missing security layer for AI agents

#2
AC2 is an open standard that puts users back in control of AI-driven signing operations, providing verifiable proof of intent and credential isolation.

The problem: a compromised agent runtime (e.g. a malicious plugin dependency) can leak everything injected into it like API keys or session tokens, and there's no way to prove whether a human actually approved what happened, since chat-based "approvals" are just messages, spoofable and session-hijackable.

AC2 closes both gaps. Approvals become a FIDO2 passkey signature from your device, that's hardware-bound, phishing-resistant, and a real audit trail instead of a chat message. And credentials never enter the runtime at all: the agent gets a signed authorization, not the key. Compromise the runtime, there's nothing to steal.

Under the hood: AC2 opens a direct, end-to-end encrypted WebRTC connection between a user's wallet and an agent. When the agent needs to sign something (a payment, a commit, an API call), it sends the request via AC2, the user approves from their own wallet, and the signature is delegated back. The private key never leaves the user's device.

Built on three open standards: DIDComm v2.0 (messaging), WebAuthn/FIDO2 (hardware-bound auth), and WebRTC DataChannel (P2P transport, no relay servers). Lightweight (~50 lines for a basic flow), blockchain-agnostic, and works alongside your existing setup. One plugin, one command.

Built by the Algorand Foundation team behind Pera Wallet, Rocca, Intermezzo, and LiquidAuth. Use cases include code deploys, client comms, API access, x402 payments, and intent-based delegation via AP2 IntentMandates.

Spec is live and open. Reference implementation (AC2 Wallet) is on GitHub, Play Store, and App Store, with a plugin to try the full flow. This is v1, feedback welcome.

Re: AC2 Protocol: The missing security layer for AI agents

#3

AC2 is an open standard that puts users back in control of AI-driven signing operations, providing verifiable proof of intent and credential isolation. The problem: a compromised agent runtime (e.g. a malicious plugin dependency) can leak everything injected into it like API keys or session tokens, and there's no way to prove whether a human actually approved what happened, since chat-based "approvals" are just messa…

This is cool, we've built similar things, I'm a bit uneasy with crypto stuff involved, especially with algorand

But FIDO2 passkey signature I absolutely agree should be the way to go. Just need more open standard without tokens involved

Re: AC2 Protocol: The missing security layer for AI agents

#5
I can’t help but see the crypto stink all over this and recoil. This is just trying to salvage ideas and tools from the last fad into the current one.

Seems like “ask for approval, except you approve by spending a little of some random altcoin”

  > Disclaimer: AC2 is a self-custodial Algorand wallet. You — and only you — hold your seed phrase, your keys, and your crypto-assets on your own device. Pera Wallet, Lda does not hold, custody, or have access to your seed phrase, your keys, or your crypto-assets, and cannot recover them on your behalf.

Re: AC2 Protocol: The missing security layer for AI agents

#6

AC2 is an open standard that puts users back in control of AI-driven signing operations, providing verifiable proof of intent and credential isolation. The problem: a compromised agent runtime (e.g. a malicious plugin dependency) can leak everything injected into it like API keys or session tokens, and there's no way to prove whether a human actually approved what happened, since chat-based "approvals" are just messa…

Obviously it's using Algorand because it's built by people working with/at Algorand, but regardless; wouldn't this all be possible to build without any cryptocurrency at all? And if no, why is Algorand particularly well suited for this (if it is), in contrast with anything else, say zCash or whatever?

Re: AC2 Protocol: The missing security layer for AI agents

#8

AC2 is an open standard that puts users back in control of AI-driven signing operations, providing verifiable proof of intent and credential isolation. The problem: a compromised agent runtime (e.g. a malicious plugin dependency) can leak everything injected into it like API keys or session tokens, and there's no way to prove whether a human actually approved what happened, since chat-based "approvals" are just messa…

Obviously it's using Algorand because it's built by people working with/at Algorand, but regardless; wouldn't this all be possible to build without any cryptocurrency at all? And if no, why is Algorand particularly well suited for this (if it is), in contrast with anything else, say zCash or whatever?

Good questions, the core doesn't need a blockchain at all. AC2 is just an approval/signing layer (DIDComm + WebAuthn/FIDO2 + WebRTC), so most use cases like API access, git commits, and client comms never touch a chain. Blockchain only enters when what's being signed is a transaction, like an x402 payment.

For that case we use Algorand, but AC2 is chain-agnostic, meaning any chain could plug in. Algorand fit because of instant finality (no forking), low predictable fees for frequent small agent payments, and post-quantum resilient signatures. zCash optimizes for privacy, which isn't really our problem, we care about speed/finality for agent-authorized actions, not hiding the payment.

So the blockchain piece is more of a plugin for one use case than the foundation of the protocol. Hope that answers your questions!

Re: AC2 Protocol: The missing security layer for AI agents

#9
Regardless of what people think of blockchains, it's the necessary foundation for any agent governance. If not this protocol, then something in this direction.

The analogy I would use is the only thing reliably containing humanity is interstellar distances, and the equivalent for ASI would be cryptographic distances, where the only way to relate to anything safely will be via a crypto interface. Compute is the physics of an ASI's substrate, and cryptography is the only meaningful barrier we've been able to create in it so far.

Re: AC2 Protocol: The missing security layer for AI agents

#10

Earlier quoted context omitted.

Obviously it's using Algorand because it's built by people working with/at Algorand, but regardless; wouldn't this all be possible to build without any cryptocurrency at all? And if no, why is Algorand particularly well suited for this (if it is), in contrast with anything else, say zCash or whatever?

Good questions, the core doesn't need a blockchain at all. AC2 is just an approval/signing layer (DIDComm + WebAuthn/FIDO2 + WebRTC), so most use cases like API access, git commits, and client comms never touch a chain. Blockchain only enters when what's being signed is a transaction, like an x402 payment. For that case we use Algorand, but AC2 is chain-agnostic, meaning any chain could plug in. Algorand fit because…

Judging by my own initial reaction, and other commentators here too, if this tech doesn't actually need any cryptocurrency to be useful, then probably you shouldn't mention that at all on the landing page, but let the people who need that stuff find it on some other pages. You'll fight a huge deluge of knee-jerk reactions otherwise, as you can tell :)

Regardless, thanks for expanding and explaining, and good luck to you all! :)

Post reply on HN