Documentation
AGLedger is change control for AI agents, delivered as a signed ledger for agentic work: records in, hash-chained, Ed25519-signed, tamper-evident, verifiable offline. New here? Start with the Quick Start.
Getting Started
Quick Start
Notarize what an agent is about to do and what it did, then verify one of those records offline on your own machine with nothing but the Server's public key.
Records & the Chain
The model behind AGLedger: records, notarizing, each record's signed chain, and delegation. The vocabulary you work with in every guide.
Build
Authentication
Get an agent a credential: the agl_ API key, the OIDC-bound short-lived certificate tied to your IdP, and the admin SSO bearer operators send to /v1/admin.
Define Custom Types
Author your own contract Types past notarize-generic-v1 - the JSON Schema that sets what a record carries and whether it has a verdict phase. Register, share.
Install a Recipe
Install an AGLedger industry recipe: clone it, register its contract types against your own Server in one command, wire Notify, and adapt it to your shop.
Agent Work Context
Checkpoint in-progress agent work as signed, tamper-evident records, so a fresh session with no prior conversation reads the latest checkpoint and resumes.
Webhooks
Receive AGLedger record events on your endpoint and verify them - HMAC-SHA256 for receiver-only integrity, RFC 9421 signatures for non-repudiable signals.
Delegate over A2A
Delegate tasks between independent agents through AGLedger over A2A 1.0 or 0.3: the agent card, JSON-RPC calls, delegation chains, and task states.
SDKs & Tools
SDK (TypeScript & Python)
Notarize, verify, and export records from TypeScript or Python. One thin SDK per language over the REST API, with an offline audit verifier in both.
CLI
Use the AGLedger CLI to authenticate, notarize a record, submit a completion, export a chain, and verify an export offline from a terminal.
MCP Server
Wire an MCP client to the AGLedger MCP server so an agent can notarize through MCP tools - install, client config, the three tools, and an offline-only path.
Run a Server
Quick Install (Compose)
The fastest path to a running AGLedger Server: clone the install repo, run one script, notarize a signed record in five minutes. Developer Edition on Compose.
Install (Kubernetes)
Bring up an AGLedger Server on Kubernetes with the published Helm chart, fronted by TLS, backed by your own PostgreSQL. OpenShift and air-gapped paths included.
Install on AWS
Bring up a single AGLedger Server on Amazon EKS with an ALB, an ACM certificate, and Aurora PostgreSQL - the AWS-native companion to the Kubernetes guide.
Provisioning
Declare a Server's orgs, agents, keys, webhooks, and contract types in YAML, reconciled on every boot - the GitOps alternative to clicking admin calls.
FIPS 140 Hosts
Run AGLedger where OpenSSL is in FIPS mode: single-Server ES256 signing, what the configuration gives up, and how to rotate an existing chain to a P-256 key.
Verify the Release
Verify every artifact AGLedger ships - image, Helm chart, npm and PyPI packages - against one keyless trust root: GitHub OIDC to Sigstore to the Rekor log.
Operate
Backup
Take a verifiable backup of an AGLedger Server - the PostgreSQL state and the signed chain - with key custody that keeps it useless to anyone but you.
Recovery
Restore an AGLedger Server from a backup, then prove the restored chain is intact and unaltered. Recovery for a tamper-evident chain is restore-then-verify.
Audit & Verification
Prove what an AGLedger chain holds - to a SIEM continuously, and to an offline auditor who trusts nothing about the running Server. Two surfaces, two audiences.
External Anchoring
Operator runbook for external anchoring: pin signed chain checkpoints to S3 Object Lock so tamper-evidence holds against the operator, and tune the interval.
Day-2 Operations
Keep a running AGLedger Server healthy: health probes, metrics, agent drift, signing-key rotation, partition maintenance, config reloads, and upgrades.
High Availability
The supported HA shape for AGLedger: stateless API and worker tiers that scale freely, a chart-derived rate-limit store, and a database tier where HA lives.
Key Compromise
Incident runbook for a suspected or confirmed vault signing-key compromise: rotate to contain, scan to scope, compare against anchors to prove what holds.
Offboarding
Runbook for taking an agent, an admin key, or an IdP out of a Server: what order to run the calls in, and what deactivation deliberately leaves running.