Originate Tokens - old
Originate kya, pay and kya-pay tokens to offer agentic access and agentic payments to your customers.
An originator is an organization that uses Skyfire to offer agentic identity and agentic wallets to its customers, typically agent platforms. Skyfire issues the kya, pay, and kya-pay tokens and hosts the identity and wallet infrastructure behind them.
As an originator, your customers rely on you to facilitate token creation for their agents. Skyfire issues each token, either to you or to your customer, depending on your access model. In both cases, your organization's URL is recorded in the ori claim, identifying you as the originator. The tokens represent your customers' agents and the end users those agents act for. The agents present them to merchants and services to prove their identity or complete a purchase.
This page assumes you have already onboarded as an enterprise organization. See Enterprise Guide for what onboarding gives you, how to onboard a customer, and the design decisions referenced throughout this page.
This guide describes the setup required to become an originator on Skyfire and originate tokens for your customers.
Skyfire enables you to
Originate tokens that agents present as identity and payment credentials to websites and APIs.
Give agents wallets and the ability to collect authorizations, so they can make purchases on behalf of their end users.
Roles
Several parties are involved in originating tokens and putting them to use. Here's who's responsible for what:
| Role | Description |
|---|---|
| End user | The person on whose behalf an agent acts, the human principal. |
| Agent / Agent platform (your customer) | Runs the agents, which act on behalf of the end user and present tokens to merchants or services. Owns the relationship with its end users, and is responsible for KYC of its end users. |
| Originator (you) | Provider of agentic identity and agentic wallets to its customers. Responsible for KYB of its customers. |
| Skyfire | Issues the tokens and hosts the identity and wallet infrastructure behind them. |
| Skyfire's KYAPay Acceptance Network | A network of security vendors that merchants use to help secure their websites and APIs, including bot managers, fraud managers, account takeover protectors, and CIAMs. |
| Merchant / service | Accepts tokens from agents to grant access, complete a purchase, or both. |

Skyfire has partnerships with a large and growing list of security vendors that natively accept
kya/kya-paytokens. If you are a security vendor who wants to enable agentic access and payments for your merchants and services, see kyapay.org for more information and reach out to [email protected].
What Skyfire configures for you
Skyfire configures your organization as an originator, which populates the ori claim in every token your organization users create. This requires no action from you.
The ori claim is what tells a merchant or service that your organization stands behind the token, distinct from the verifier claims, which record who performed verification. See Who verifies your organization users for that decision.
Onboarding a customer as an agent platform
Enterprise Guide covers creating a customer's organization user and setting their personal data, which every enterprise does. Origination adds two things on top.
- Skyfire onboards the customer as an agent platform. This is what lets your customer run agents of its own, rather than only holding a wallet.
- Skyfire sets up a designated administrator. A staff member at the customer's company, whose credentials Skyfire shares with you. Handle them per your access model. Tokens identify this administrator as the contact person in the
apdclaim.
Your customer then provisions its own agents, using the designated administrator's credentials. Once an end user's personal data is submitted, you can originate kya, pay, and kya-pay tokens for that user's agents.
Originating card-backed
payandkya-paytokens is fully supported. Creating one involves Skyfire's Payments React SDK alongside Create Token, rather than an API call on its own. See Agentic Commerce with Payment Cards for how that works.
Next steps
- To see how the tokens you originate fit into an agentic purchase, see Agentic Commerce with Payment Cards.
- To see how this is built with Skyfire's Payments React SDK, see Building an Agentic Checkout.
- To bill your customers for usage of resources you host, rather than at third parties, see Meter Platform Usage.
Updated 7 days ago

