Originate Tokens - old

Originate kya, pay and kya-pay tokens to offer agentic access and agentic payments to your customers.

An originator is an organization that uses Skyfire to offer agentic identity and agentic wallets to its customers, typically agent platforms. Skyfire issues the kya, pay, and kya-pay tokens and hosts the identity and wallet infrastructure behind them.

As an originator, your customers rely on you to facilitate token creation for their agents. Skyfire issues each token, either to you or to your customer, depending on your access model. In both cases, your organization's URL is recorded in the ori claim, identifying you as the originator. The tokens represent your customers' agents and the end users those agents act for. The agents present them to merchants and services to prove their identity or complete a purchase.

This page assumes you have already onboarded as an enterprise organization. See Enterprise Guide for what onboarding gives you, how to onboard a customer, and the design decisions referenced throughout this page.

This guide describes the setup required to become an originator on Skyfire and originate tokens for your customers.

Skyfire enables you to

Originate tokens

Originate tokens that agents present as identity and payment credentials to websites and APIs.

Provide wallets

Give agents wallets and the ability to collect authorizations, so they can make purchases on behalf of their end users.

Roles

Several parties are involved in originating tokens and putting them to use. Here's who's responsible for what:

RoleDescription
End userThe person on whose behalf an agent acts, the human principal.
Agent / Agent platform (your customer)Runs the agents, which act on behalf of the end user and present tokens to merchants or services. Owns the relationship with its end users, and is responsible for KYC of its end users.
Originator (you)Provider of agentic identity and agentic wallets to its customers. Responsible for KYB of its customers.
SkyfireIssues the tokens and hosts the identity and wallet infrastructure behind them.
Skyfire's KYAPay Acceptance NetworkA network of security vendors that merchants use to help secure their websites and APIs, including bot managers, fraud managers, account takeover protectors, and CIAMs.
Merchant / serviceAccepts tokens from agents to grant access, complete a purchase, or both.

Skyfire has partnerships with a large and growing list of security vendors that natively accept kya/kya-pay tokens. If you are a security vendor who wants to enable agentic access and payments for your merchants and services, see kyapay.org for more information and reach out to [email protected].

What Skyfire configures for you

Skyfire configures your organization as an originator, which populates the ori claim in every token your organization users create. This requires no action from you.

The ori claim is what tells a merchant or service that your organization stands behind the token, distinct from the verifier claims, which record who performed verification. See Who verifies your organization users for that decision.

Onboarding a customer as an agent platform

Enterprise Guide covers creating a customer's organization user and setting their personal data, which every enterprise does. Origination adds two things on top.

  • Skyfire onboards the customer as an agent platform. This is what lets your customer run agents of its own, rather than only holding a wallet.
  • Skyfire sets up a designated administrator. A staff member at the customer's company, whose credentials Skyfire shares with you. Handle them per your access model. Tokens identify this administrator as the contact person in the apd claim.

Your customer then provisions its own agents, using the designated administrator's credentials. Once an end user's personal data is submitted, you can originate kya, pay, and kya-pay tokens for that user's agents.

Originating card-backed pay and kya-pay tokens is fully supported. Creating one involves Skyfire's Payments React SDK alongside Create Token, rather than an API call on its own. See Agentic Commerce with Payment Cards for how that works.

Next steps


Did this page help you?