Privacy policy

Last updated: 2026-06-03

This policy covers what data the AgentPKI Chrome extension and the verify.agentpki.dev verifier service handle. The short version: as little as possible, and never sold.

1. What the AgentPKI extension does

The extension watches webpages you visit for signals that an AI agent is present — a <meta name="agentpki-passport"> tag, an AgentPKI-Token: response header, an RFC 9421 outbound signature, or known agent-framework JavaScript globals — and shows a coloured toolbar badge that tells you whether the agent is verified.

2. What we send across the network

The extension makes network requests to exactly one place: verify.agentpki.dev. The payload of each request is:

3. What we store on your device

All of these live in chrome.storage on your machine and never leave it:

Use the Clear all local data button on the Activity & Settings page to wipe these at any time.

4. What we store server-side

5. What we never collect

6. Third parties

The verifier runs on Cloudflare Workers. Cloudflare may retain edge logs as described above. We do not share data with anyone else.

7. Children

The extension is not directed at children under 13. We do not knowingly collect data from anyone.

8. Open source

Every line of the extension and verifier is MIT-licensed and visible:

9. Changes

We will date this page each time it changes. Material changes will be announced in the GitHub repository's CHANGELOG.md and on /why.

10. Contact

Privacy questions: [email protected].