@browserid-ng/wallet
v0.5.1
Published
MCP server that gives an AI agent its own browserid-ng identity — provision, warrants, assertions. Run via npx.
Downloads
401
Maintainers
Readme
@browserid-ng/wallet
Give your AI agent its own identity. This is an MCP server that lets an agent provision a browserid-ng identity, get human-approved warrants, and present verifiable assertions — so it can sign in to services as itself, acting for you, within scopes you approve and can revoke.
No checkout, no build. Add one line to your MCP client and you're done.
Install
Add to your MCP client config (Claude Code / Cursor .mcp.json, or Claude
Desktop's config):
{
"mcpServers": {
"browserid": { "command": "npx", "args": ["-y", "@browserid-ng/wallet"] }
}
}Then, in your agent, try the demo:
Provision a browserid-ng identity and sign the guestbook saying "hello from my agent".
The agent shows you an approval link (open it, confirm the fingerprint, approve), then signs the public guestbook at browserid.me/guestbook — where your message appears attributed to the agent and to you.
Tools
provision(handles?, label?)— pair a new identity. The agent generates its device keypair locally; you approve, and the IdP issues anagent-subject device cert for it (a device-grant — nothing is delegated by chaining your key). Returns an approval URL for you; the agent picks up its device cert automatically once you approve. The private key is generated locally and never transmitted. At rest it is stored as plaintext JSON in~/.browserid(owner-only,0700/0600) — there is no passphrase or OS-keychain layer, so anything running as your user can read it. Treat the machine account as the custody boundary; revoke the agent's cert from your /account page if the machine is compromised.identity— who the agent acts as.authorize(audience, scopes, message?)— request a warrant for an audience (signed by your config cert at the consent screen).get_assertion(audience)— the four-object bundle (access_cert~assertion~warrant~config_cert) to present there; the agent mints a fresh access cert as needed.sign_guestbook(message)/read_guestbook()— the demo.
Where the identity lives
In ~/.browserid/ (the agent's device key, its IdP-issued device cert, and any
warrants). It's local to your machine — browserid.me never holds the key.
Config
BROWSERID_BROKER— defaulthttps://browserid.me.BROWSERID_HOME— default~/.browserid.GUESTBOOK_URL— default<broker>/guestbook.AGENT_NAME— pick a reserved name for a multi-name credential.
License
MPL-2.0
