{
  "fixes": {
    "slug": "kite-agent-passport",
    "name": "Kite Agent Passport",
    "listing": "https://www.anchorterminal.com/tools/kite-agent-passport",
    "markdown": "# Fix list: Kite Agent Passport\n\nFrom Anchor Terminal's listing at https://www.anchorterminal.com/tools/kite-agent-passport, the October 2026 research run, assessed 10 October 2026. Grade D, 51.5 out of 100.\n\nThis is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.\n\nFor a coding agent working on Kite Agent Passport: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.\n\n## 1. Reliability, 35 out of 100, up to 13 more on the total\n\nWhy it scored 35: Graded as a hosted service, the Passport backend behind the kpass CLI, skills and dashboard. status.gokite.ai shows 60 days of uptime for the Kite website, explorer and RPC endpoints, but no Passport component, so 10 of 20. With no readable Passport history the record takes the default (5). No rate limit with numbers was found (0). The skills map exit code 5 to a rate limit with a 30-second wait, and `kpass session execute` takes an `--idempotency-key` for safe retries of paid calls, with no Retry-After documented (10 of 15). No SLA was found (0). No beta label was found on Passport, and production and a sandbox test mode are both live (10). Total 35.\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):\n\nHosted APIs, MCP servers, models and platforms.\n\n- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.\n\nLocal packages, SDKs, frameworks and stdio MCP servers.\n\n- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.\n\nProtocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.\n\n## 2. Payments \u0026 pricing, 35 out of 100, up to 8.1 more on the total\n\nWhy it scored 35: Payment platforms and wallets take the highest step that applies on the 40-point protocol line. 40 for x402, MPP or L402 on all their own endpoints, 30 on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, 0 for only a protocol of their own. Passport pays third-party x402 and MPP services as a buyer. Its own backend is not paid over either, and Kite recommends the third-party Pieverse facilitator, so the buyer step (15 of 40). No fee rate is published. The changelog says Passport's service margin is shown only in a per-session estimate before approval (0 of 20). Account creation and sandbox test mode with a testnet faucet need no card (20). Signup needs a person to click an emailed link and create a passkey in a browser (0). Total 35.\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):\n\nThe published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).\n\n- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).\n\nPayment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.\n\nOpen-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.\n\n## 3. Schema \u0026 documentation, 64 out of 100, up to 5.9 more on the total\n\nWhy it scored 64: The API reference page is a placeholder that says the OpenAPI spec is not yet published. The skill files document the CLI's arguments and JSON output shapes, which earns 5 of 25. llms.txt, sharded Markdown corpora and a read-only docs MCP server (10). Skill descriptions say when to use each skill and list what not to use them for, but the kite-passport skill also tells agents to invoke it before WebSearch, WebFetch or built-in tools, which overstates its scope (14 of 20). CLI flags are documented with required fields, a `--payment-approach` value and typed caps, while `--delegation` takes a JSON blob (9 of 15). Examples for every command, and exit-code tables with `error_code` values and recovery actions (14 of 15). A dated docs changelog from 19 May to 29 July 2026, semver tags on the skills repository and numbered CLI bundles. The docs changelog has no entry after 29 July although bundle 83 shipped on 7 October (12 of 15). Total 64.\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):\n\nAPIs and MCP servers.\n\n- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.\n\nModels are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.\n\n## 4. Agent ergonomics, 68 out of 100, up to 5.2 more on the total\n\nWhy it scored 68: The CLI returns JSON with `--output json`, and the skills load one per task, but the 26 skill files total about 6,900 lines and the router skill's description is long (15 of 25). `ksearch services list` takes `--query`, `--payment-approach`, `--asset` and `--limit`, activity filters by date and merchant, and the login log takes `since`, `until`, `limit` and `offset` (14 of 20). Numbered exit codes, a machine-readable `error_code` and a `hint`, with merchant decline reasons returned since 1 July 2026 (18 of 20). An idempotency key on paid executes, and session approval and wallet sends wait for the person's passkey (14 of 20). One-line install on macOS, Linux and Windows, with sensible session defaults, but no official SDK in any language for Passport (7 of 15). Total 68.\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):\n\n- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.\n\nModels are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.\n\n## 5. Security \u0026 auth, 72 out of 100, up to 4.9 more on the total\n\nWhy it scored 72: A person logs in with an emailed code and approves with a device passkey. Agents act through time-boxed sessions bound to that approval, and the hosted MCP endpoint uses OAuth. Key rotation for agents was not documented in what we read (25 of 30). Sessions enforce a per-transaction cap, a total budget, a lifetime and scope rules such as `session_endpoint_forbidden` and `payment_target_forbidden`. Wallet sends, session approvals and passkey changes need an action-bound passkey step-up since 4 June 2026 (18 of 20). The x402-execute and request-session skills tell agents to treat merchant URLs and response values as untrusted and to quote them safely in shell commands. The kite-passport skill steers agents to paid services ahead of free tools (8 of 15). A step-up log, a login history, a per-session activity feed and transaction history (14 of 15). SECURITY.md in the skills repository gives security@kitepassport.com with a 48-hour acknowledgement. No security.txt, bug bounty or SOC 2 was found, and Kite's security page says Halborn audits and penetration tests cover the chain, with reports on request (7 of 20). Total 72.\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-security):\n\n- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.\n\nModels are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.\n\n## 6. Transparency \u0026 trust, 56 out of 100, up to 3.9 more on the total\n\nMade of editorial 47, provenance 65.\n\nWhy it scored 56: A closed service under terms from Datalego Inc. dated 29 April 2026, with the skills under MIT and the CLI source private (17 of 30). The privacy policy of the same date names Banxa (Australia) and Crossmint (US) as processors, says private keys are not collected, and keeps data for as long as necessary with no periods. The changelog adds that login history stores derived city and country without the IP. No DPA was found (14 of 30). Release notes carry 'Important updates' with required upgrades and breaking changes, such as Base settlement replacing the treasury relay, but give them on the day of release and no deprecation policy was found (6 of 20). Banxa, Crossmint, Halliday and MaxMind are named across the policy and changelog, with locations for the first two, and no subprocessor list (10 of 20). Total 47.\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):\n\n- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).\n\nThe other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.\n\nProvenance checks not met in full (half of this category, computed from checked facts):\n\n- Domain age: agentpassport.ai, no registry record we could read (0 of 15)\n- Status page: not found (0 of 10)\n- security.txt: not found (0 of 10)\n\n## 7. Maintenance \u0026 community, 71 out of 100, up to 2.5 more on the total\n\nWhy it scored 71: CLI bundle 83 with kpass 6.8.0 was built on 7 October 2026 and Passport Skills v3.5.0 tagged the same day, 3 days before this check (30). Twelve skills tags since 29 August 2026 (20). The skills repository merges pull requests weekly and `kpass feedback submit` sends reports to Kite. The backend and CLI sources are private and the docs changelog stops at 29 July, so 9 of 15 for a closed service. The CLI is current, but no official SDK for Passport exists and the PyPI gokite SDK was last released on 18 July 2025. The hosted MCP endpoint was not found in the official registry (5 of 15). The skills repository runs validation and Markdown lint in CI, and the installer verifies SHA-256 checksums from the bundle manifest (7 of 10). Total 71.\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):\n\n- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.\n\nModels are read for deprecation notice periods and model churn rather than release counts.\n\n## Deductions\n\nEach comes off the total. A fixed and documented problem counts for less at the next check.\n\n- 22 July 2026: Kite fixed a settlement-timing gap in agent-session payments, marked [security], that could allow repricing between detection and settlement. It is fixed and disclosed in the changelog, with no report of exploitation found, so -2 (https://docs.gokite.ai/changelog/2026/2026-07-22-release).\n- 8 July 2026: settlement moved to Base, replacing the treasury relay path, and mainnet agent wallets' USDC was bridged to Base. The release note asked integrations that assumed Kite settlement to update, with no earlier notice found, so -3 (https://docs.gokite.ai/changelog/2026/2026-07-08-release).\n\n## What we couldn't check\n\nWhat we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.\n\n- unchecked: the hosted MCP endpoint's URL, tools and OAuth scopes. The changelog of 23 June 2026 announces it and the reviewed docs give no address.\n- unchecked: who holds the wallet keys. The privacy policy says Datalego does not collect private keys and uses Crossmint for on-chain payments, without stating custody.\n- unchecked: the size of Passport's service margin and whether failed or declined payments are charged.\n- unchecked: the date Passport became available to the public. A Chainwire press release dated 30 April 2026 announces it, and the terms are dated 29 April 2026. The earliest docs changelog entry is 19 May 2026.\n- unchecked: GitHub stars and issue response times, because the GitHub API was not reachable from our session.\n- The docs changelog has no entry after 29 July 2026, although CLI bundles and skills releases continued to 7 October 2026.\n\n## Weaknesses\n\n- A person signs up by email, clicks a verification link and creates a passkey in a browser before any agent can spend\n- No fee rate is published. Passport's service margin appears only in a per-session estimate before approval\n- The API reference is a placeholder and no OpenAPI file is published, so agents work through the CLI or the hosted MCP endpoint\n- No status page covers the Passport backend, and no rate limit with numbers or SLA was found\n- The kite-passport skill tells agents to use paid services before WebSearch or built-in tools, which can spend budget on tasks free tools could do\n\n## What costs an agent a turn today\n\nThe notes we give agents before they call it. Each one is a workaround an agent shouldn't need.\n\n- Run `kpass` with `--output json --no-interactive` and branch on the exit code and `error_code`. Exit 6 is a session policy breach, so request a new session rather than logging in again\n- Pass `--idempotency-key` on every `kpass session execute` so a retry after a timeout does not pay twice\n- Ask the person for a session with a small per-transaction cap and a short `--ttl`, and confirm the merchant URL before executing\n- Use `kpass sandbox` test mode and the faucet to try a payment flow without real funds. Scoped cards are not available in sandbox\n- Check the kite-passport skill's trigger rules before installing it, since it directs the agent to paid services ahead of free tools\n\n## When it's done\n\nSend what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `\"kind\": \"dispute\"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.\n",
    "grade": "D",
    "score": 51.5,
    "assessed": "2026-10-10",
    "run": "October 2026 research run",
    "categories": [
      {
        "key": "reliability",
        "name": "Reliability",
        "score": 35,
        "maxGain": 13,
        "reason": "Graded as a hosted service, the Passport backend behind the kpass CLI, skills and dashboard. status.gokite.ai shows 60 days of uptime for the Kite website, explorer and RPC endpoints, but no Passport component, so 10 of 20. With no readable Passport history the record takes the default (5). No rate limit with numbers was found (0). The skills map exit code 5 to a rate limit with a 30-second wait, and `kpass session execute` takes an `--idempotency-key` for safe retries of paid calls, with no Retry-After documented (10 of 15). No SLA was found (0). No beta label was found on Passport, and production and a sandbox test mode are both live (10). Total 35.",
        "checklist": [
          "Hosted APIs, MCP servers, models and platforms.",
          "- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.",
          "Local packages, SDKs, frameworks and stdio MCP servers.",
          "- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.",
          "Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-reliability"
      },
      {
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "score": 35,
        "maxGain": 8.1,
        "reason": "Payment platforms and wallets take the highest step that applies on the 40-point protocol line. 40 for x402, MPP or L402 on all their own endpoints, 30 on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, 0 for only a protocol of their own. Passport pays third-party x402 and MPP services as a buyer. Its own backend is not paid over either, and Kite recommends the third-party Pieverse facilitator, so the buyer step (15 of 40). No fee rate is published. The changelog says Passport's service margin is shown only in a per-session estimate before approval (0 of 20). Account creation and sandbox test mode with a testnet faucet need no card (20). Signup needs a person to click an emailed link and create a passkey in a browser (0). Total 35.",
        "checklist": [
          "The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).",
          "- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).",
          "Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.",
          "Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-payments"
      },
      {
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "score": 64,
        "maxGain": 5.9,
        "reason": "The API reference page is a placeholder that says the OpenAPI spec is not yet published. The skill files document the CLI's arguments and JSON output shapes, which earns 5 of 25. llms.txt, sharded Markdown corpora and a read-only docs MCP server (10). Skill descriptions say when to use each skill and list what not to use them for, but the kite-passport skill also tells agents to invoke it before WebSearch, WebFetch or built-in tools, which overstates its scope (14 of 20). CLI flags are documented with required fields, a `--payment-approach` value and typed caps, while `--delegation` takes a JSON blob (9 of 15). Examples for every command, and exit-code tables with `error_code` values and recovery actions (14 of 15). A dated docs changelog from 19 May to 29 July 2026, semver tags on the skills repository and numbered CLI bundles. The docs changelog has no entry after 29 July although bundle 83 shipped on 7 October (12 of 15). Total 64.",
        "checklist": [
          "APIs and MCP servers.",
          "- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.",
          "Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-schema"
      },
      {
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "score": 68,
        "maxGain": 5.2,
        "reason": "The CLI returns JSON with `--output json`, and the skills load one per task, but the 26 skill files total about 6,900 lines and the router skill's description is long (15 of 25). `ksearch services list` takes `--query`, `--payment-approach`, `--asset` and `--limit`, activity filters by date and merchant, and the login log takes `since`, `until`, `limit` and `offset` (14 of 20). Numbered exit codes, a machine-readable `error_code` and a `hint`, with merchant decline reasons returned since 1 July 2026 (18 of 20). An idempotency key on paid executes, and session approval and wallet sends wait for the person's passkey (14 of 20). One-line install on macOS, Linux and Windows, with sensible session defaults, but no official SDK in any language for Passport (7 of 15). Total 68.",
        "checklist": [
          "- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.",
          "Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-ergonomics"
      },
      {
        "key": "security",
        "name": "Security \u0026 auth",
        "score": 72,
        "maxGain": 4.9,
        "reason": "A person logs in with an emailed code and approves with a device passkey. Agents act through time-boxed sessions bound to that approval, and the hosted MCP endpoint uses OAuth. Key rotation for agents was not documented in what we read (25 of 30). Sessions enforce a per-transaction cap, a total budget, a lifetime and scope rules such as `session_endpoint_forbidden` and `payment_target_forbidden`. Wallet sends, session approvals and passkey changes need an action-bound passkey step-up since 4 June 2026 (18 of 20). The x402-execute and request-session skills tell agents to treat merchant URLs and response values as untrusted and to quote them safely in shell commands. The kite-passport skill steers agents to paid services ahead of free tools (8 of 15). A step-up log, a login history, a per-session activity feed and transaction history (14 of 15). SECURITY.md in the skills repository gives security@kitepassport.com with a 48-hour acknowledgement. No security.txt, bug bounty or SOC 2 was found, and Kite's security page says Halborn audits and penetration tests cover the chain, with reports on request (7 of 20). Total 72.",
        "checklist": [
          "- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.",
          "Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-security"
      },
      {
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "score": 56,
        "maxGain": 3.9,
        "reason": "A closed service under terms from Datalego Inc. dated 29 April 2026, with the skills under MIT and the CLI source private (17 of 30). The privacy policy of the same date names Banxa (Australia) and Crossmint (US) as processors, says private keys are not collected, and keeps data for as long as necessary with no periods. The changelog adds that login history stores derived city and country without the IP. No DPA was found (14 of 30). Release notes carry 'Important updates' with required upgrades and breaking changes, such as Base settlement replacing the treasury relay, but give them on the day of release and no deprecation policy was found (6 of 20). Banxa, Crossmint, Halliday and MaxMind are named across the policy and changelog, with locations for the first two, and no subprocessor list (10 of 20). Total 47.",
        "blend": "editorial 47, provenance 65",
        "checklist": [
          "- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).",
          "The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-transparency"
      },
      {
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "score": 71,
        "maxGain": 2.5,
        "reason": "CLI bundle 83 with kpass 6.8.0 was built on 7 October 2026 and Passport Skills v3.5.0 tagged the same day, 3 days before this check (30). Twelve skills tags since 29 August 2026 (20). The skills repository merges pull requests weekly and `kpass feedback submit` sends reports to Kite. The backend and CLI sources are private and the docs changelog stops at 29 July, so 9 of 15 for a closed service. The CLI is current, but no official SDK for Passport exists and the PyPI gokite SDK was last released on 18 July 2025. The hosted MCP endpoint was not found in the official registry (5 of 15). The skills repository runs validation and Markdown lint in CI, and the installer verifies SHA-256 checksums from the bundle manifest (7 of 10). Total 71.",
        "checklist": [
          "- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.",
          "Models are read for deprecation notice periods and model churn rather than release counts."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-maintenance"
      }
    ],
    "provenance": [
      {
        "label": "Domain age",
        "value": "agentpassport.ai, no registry record we could read",
        "points": 0,
        "max": 15
      },
      {
        "label": "Status page",
        "value": "not found",
        "points": 0,
        "max": 10
      },
      {
        "label": "security.txt",
        "value": "not found",
        "points": 0,
        "max": 10
      }
    ],
    "deductions": [
      "22 July 2026: Kite fixed a settlement-timing gap in agent-session payments, marked [security], that could allow repricing between detection and settlement. It is fixed and disclosed in the changelog, with no report of exploitation found, so -2 (https://docs.gokite.ai/changelog/2026/2026-07-22-release).",
      "8 July 2026: settlement moved to Base, replacing the treasury relay path, and mainnet agent wallets' USDC was bridged to Base. The release note asked integrations that assumed Kite settlement to update, with no earlier notice found, so -3 (https://docs.gokite.ai/changelog/2026/2026-07-08-release)."
    ],
    "unchecked": [
      "unchecked: the hosted MCP endpoint's URL, tools and OAuth scopes. The changelog of 23 June 2026 announces it and the reviewed docs give no address.",
      "unchecked: who holds the wallet keys. The privacy policy says Datalego does not collect private keys and uses Crossmint for on-chain payments, without stating custody.",
      "unchecked: the size of Passport's service margin and whether failed or declined payments are charged.",
      "unchecked: the date Passport became available to the public. A Chainwire press release dated 30 April 2026 announces it, and the terms are dated 29 April 2026. The earliest docs changelog entry is 19 May 2026.",
      "unchecked: GitHub stars and issue response times, because the GitHub API was not reachable from our session.",
      "The docs changelog has no entry after 29 July 2026, although CLI bundles and skills releases continued to 7 October 2026."
    ],
    "weaknesses": [
      "A person signs up by email, clicks a verification link and creates a passkey in a browser before any agent can spend",
      "No fee rate is published. Passport's service margin appears only in a per-session estimate before approval",
      "The API reference is a placeholder and no OpenAPI file is published, so agents work through the CLI or the hosted MCP endpoint",
      "No status page covers the Passport backend, and no rate limit with numbers or SLA was found",
      "The kite-passport skill tells agents to use paid services before WebSearch or built-in tools, which can spend budget on tasks free tools could do"
    ],
    "agentNotes": [
      "Run `kpass` with `--output json --no-interactive` and branch on the exit code and `error_code`. Exit 6 is a session policy breach, so request a new session rather than logging in again",
      "Pass `--idempotency-key` on every `kpass session execute` so a retry after a timeout does not pay twice",
      "Ask the person for a session with a small per-transaction cap and a short `--ttl`, and confirm the merchant URL before executing",
      "Use `kpass sandbox` test mode and the faucet to try a payment flow without real funds. Scoped cards are not available in sandbox",
      "Check the kite-passport skill's trigger rules before installing it, since it directs the agent to paid services ahead of free tools"
    ],
    "recheck": "https://www.anchorterminal.com/builders/#disputes"
  },
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-11",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  }
}
