Refused
scope exceeded · signed
For API & identity teams
Built for a platform like yours. Your API gateway and identity server already broker tokens and scopes between clients, services and users — and now AI agents call those APIs on someone’s behalf. KYE Protocol™ checks the agent’s delegated scope at the moment of the call — and refuses any invocation beyond what its principal actually granted. Each refusal is sealed as a receipt your security team can replay, cutting an access-abuse investigation from days to minutes.
AI integration agent
call admin API · scope exceeded
KYE™delegated scope check
scope exceeded · signed
within scope · signed
Stopped before the call lands. The invocation is refused because it exceeds the scope the agent’s principal delegated — and the refusal is signed and verifiable, so you can prove to security and audit that least-privilege held at the moment of the act.
That refusal, sealed REFUSED · SCOPE_EXCEEDED kye:evidence:4a8c… Replay & verify →
1 · What KYE™ ™ governs in your stack
Your platform already issues tokens, enforces scopes and routes calls across services. KYE Protocol™ adds the one check an AI agent makes it urgent to enforce: at the moment of a consequential call, is this inside the authority the agent’s principal actually delegated — not just the token it happens to hold?
2 · The honest boundary
This is a governance layer, not an API gateway or IAM. KYE Protocol™ does not issue your tokens, terminate TLS, or route your traffic.
It checks the agent’s delegated authority at the action boundary, admits or refuses, and seals the proof. A call outside the agent’s scope is refused and routed to a human step-up — the refusal is itself evidence. See how the delegation chain is drawn on the authority diagram, then walk a sealed decision on the Evidence Pack™ demo.
3 · See it on your own flow
In a 20-minute walk-through we take one of your live flows — a privileged API call, a scope escalation, an agent-to-agent invocation — and show the AI action refused or admitted against the agent’s delegated authority, then hand you the sealed receipt to replay yourself. No credentials to share: the proof verifies against a public key set, the same runtime enforcement KYE Protocol™ uses to govern itself.
Canonical KYE™ surfaces referenced on this page: KYE Protocol™.