---
updatedAt: 2026-07-10T16:59:43.000Z
agentTools:
  projectIndex: https://docs.skyfire.xyz/llms.txt
---

# Security Brief for Sellers and Bot Managers

# Protocol Flow

<Image align="center" src="https://files.readme.io/b2949f66b6839f940fdb589da19c03d47cbf63dd5e9d0a5f36d94cb23433bc83-Screenshot_2025-11-08_at_10.24.48_AM.png" />

# KYA

* `kya` tokens present the verified identity credentials of the agent platform, agent, and the human principal behind the agent
* Skyfire conducts KYBs on the buy-side agent platforms that it onboards
  * This ensures that the buy-side agents are who they say they are
* Skyfire directly, or via the trusted agent platforms, verifies the identity of the human principals / businesses behind the agents
* The identity layer in `kya` tokens in extensible in case more intermediaries need to be verified on the buy-side e.g. in case of referral sales

# Tokens

* `kya` tokens are <Anchor label="RFC-7515" target="_blank" href="https://datatracker.ietf.org/doc/html/rfc7515">RFC-7515</Anchor> and <Anchor label="RFC-7519" target="_blank" href="https://datatracker.ietf.org/doc/html/rfc7519">RFC-7519</Anchor> compliant signed JWTs
  * Skyfire publishes its `JWKS` file at <Anchor label="<Anchor label=&#x22;[https://app.skyfire.xyz/.well-known/jwks.json](https://app.skyfire.xyz/.well-known/jwks.json)&#x22; target=&#x22;_blank&#x22; href=&#x22;https://app.skyfire.xyz/.well-known/jwks.json&#x22;>[https://app.skyfire.xyz/.well-known/jwks.json](https://app.skyfire.xyz/.well-known/jwks.json)</Anchor>" target="_blank" href="https://app.skyfire.xyz/.well-known/jwks.json"><Anchor label="[https://app.skyfire.xyz/.well-known/jwks.json](https://app.skyfire.xyz/.well-known/jwks.json)" target="_blank" href="https://app.skyfire.xyz/.well-known/jwks.json"><https://app.skyfire.xyz/.well-known/jwks.json></Anchor></Anchor>
  * Signing ensures that the JWTs are tamper-proof
  * e2e HTTPS encryption ensures that malicious intermediaries cannot extract tokens from the request headers

# Token Transport

* Tokens are sent directly from the buyer to the seller
  * There is no intermediary
  * Skyfire recommends end-to-end encryption for these connections e.g. `HTTPS`
* Tokens are typically contained in a custom `HTTP` header e.g. `skyfire-pay-id`
  * `HTTP` headers are encrypted by the `HTTPS` protocol

# Token Verification

Sellers and their Bot Managers verify the validity of the tokens - both signature and claims

See: <Anchor label="<Anchor label=&#x22;Verify and Extract Data from Tokens&#x22; target=&#x22;_blank&#x22; href=&#x22;https://docs.skyfire.xyz/reference/verify-and-optionally-extract-data-from-the-tokens#/&#x22;>Verify and Extract Data from Tokens</Anchor>" target="_blank" href="https://docs.skyfire.xyz/reference/verify-and-extract-data-from-tokens"><Anchor label="Verify and Extract Data from Tokens" target="_blank" href="https://docs.skyfire.xyz/reference/verify-and-optionally-extract-data-from-the-tokens#/">Verify and Extract Data from Tokens</Anchor></Anchor>

<br />

## Replay Attacks

### Audience and Seller Service Identifier

* The `aud`, `ssi`, `srl`, and `sdm` claims make it so that stolen / copied tokens are only valid at the specified seller

### Expiry

`exp` claim:

* Sellers can set the maximum expiry of tokens created for them
* Shorter expiry times lower the threat of replay attacks but also add friction for buyers
* Sellers can select what is optimal for them

### JTI

The `jti` claim can be used to de-duplicate tokens at the seller

* The seller can require the buyer to create a new token for each request
* This does add friction for buyers so instead the seller could use shorter expiry times.

### IP Addresses

* The IP address from which the agent created the token is included in the KYA token in the `aid.creation_ip` claim.
* The Agent Platform can further set IP address ranges from which it originates its traffic. This is carried in the `aid.source_ips claim`.
* The seller and/or their bot manager can independently verify whether the incoming traffic from the buyer matches one of these IP addresses. If it does not, then the seller can use that as a signal to decline / block the requests.

# Token Acceptance

`kya` tokens are not a free pass

* Sellers and their Bot Managers inspect them for validity and can then grant access selectively

# Token Creation

KYAPay is NOT meant as a requirement to identify each and every agent, bot, or crawler regardless of use case. It is meant to enable merchants, content publishers, and other sellers to conduct commerce with humans via their designated agents by making such transactions easy to identify and verify.